Live Stream VOD: PikaBot Part 2 (Patreon)
Published:
2023-03-12 17:57:07
Imported:
2023-09
Content
In this Twitch stream we complete our analysis of the PikaBot loader. We use Dumpulator and some IDA scripting to resolve all of the encrypted stack strings and the dynamic imports, then we analyze the functionality.
Note* at the end of the stream I miss an important function call in the binary which is responsible for the registry key loading, we tackle this in the next stream!
Samples
- Packed
67c61f649ec276eb57fcfe70dbd6e33b4c05440ee10356a3ef10fad9d0e224ef - Unpacked
05d1b791865c9551ed8da6a170eb6f945a4d1e79cb70341f589cc47bacf78cc3 - UnpacMe Analysis