Home Artists Posts Import Register
Patreon importer is back online! Tell your friends ✅

Content

In this Twitch stream we triage CryptBot a C++ INFOSTEALER that has been in operation since 2019.

The main focus of the stream is building a decent config extractor and a good yara rule for this malware but we have a little fun looking up its origins along the way.

Sample

7ccda59528c0151bc9f11b7f25f8291d99bcf541488c009ef14e2a104e6f0c5d 

Notes

CryptBot: Another C++ bot 


Files

Live Stream VOD: CryptBot Malware Triage

This is "Live Stream VOD: CryptBot Malware Triage" by OALABS on Vimeo, the home for high quality videos and the people who love them.

Comments

Karsten Hahn

Haha, I should have linked this part of the twitter thread: https://twitter.com/James_inthe_box/status/1224720428502880257 My bad.

m4n0w4r

Note here for creating string struct with variable size: https://hex-rays.com/blog/igors-tip-of-the-week-94-variable-sized-structures/