Live Stream VOD: Clipboard Hijacking Detection (Patreon)
Published:
2022-09-22 16:56:05
Imported:
2022-12
Content
In this Twitch stream we take a look at a simple malware (great for practicing RE) that is used to steal crypto by substituting wallet addresses that are copy pasted from the clipboard.
We analyze the malware functionality and build some static detection with a Yara rule so we can generically identify this behaviour.
Sample
8d7f0e6b6877bdfb9f4531afafd0451f7d17f0ac24e2f2427e9b4ecc5452b9f0