Jump to content
Tuts 4 You
Sign in to follow this  
Xyl2k

Malware music video

Recommended Posts

Xyl2k

Hello,
I'm doing reverse videos since some time now about exotic malwares and fun things.
My videos aren't about detailing specific threats, just small overview of what they do (i try to do my video small in length)
So if you like reversing, assembly and electronic/dubstep here you go.

Chinese adware and steganography
Having a look on Win32/Kawpfuni.A (Military-espionage malware)
Having a look on Trojan/Win32.Shifu (Shifu)
Having fun with Tyupkin (ATM Malware)
Having a look on CryptoFortress config
Having fun with Dyre and API's
Having a look on Win32/Modputty.A
Having a look on Dridex config
Having a look on GreenDispenser (ATM Malware)
Having a look on DarkComet RAT config

  • Like 9

Share this post


Link to post
Share on other sites
crystalboy

Nice music and nice accelerated videos of malware tracing! :)

Thanks for sharing. :)

Share this post


Link to post
Share on other sites
Alzri2

Those videos should be kept in a museum to let other generations learn about/from them ;)

Just a question, how much does it take you to analyze a typical malware ? Am I the only one taking hours to understand what a malware does ?

Share this post


Link to post
Share on other sites
Pancake

Nice ones. May i ask you which plugins are you using? You are getting a bunch of useful features i see.

 

And btw, why arent tese files packed/virtualized/obfuscated at all? And how did you get real ATM to try the malware on it? The ATM stuff seems like super-super-super interesting topic man!

Edited by Pancake

Share this post


Link to post
Share on other sites
Xyl2k

@Pancake: i replicate the environment of the atm, haven't released in a while so here is a new one:

Having a look on Backdoor.Win32.ATMitch.a (ATM Malware)

You can see fake xfs api call result expressed in malware logs at the end, related to obfuscations yeah some are, i unpack them before doing the video.

Share this post


Link to post
Share on other sites
null_endian
3 hours ago, Xyl2k said:

new video, fast tracing of a zbot: https://www.youtube.com/watch?v=C-dEOt0GzSE

Hey thanks for the vid I just watched it. How long does it take you to figure this out? I assume you have sped up the video a lot... For me, it takes a lot longer to locate different pieces of the code.

Share this post


Link to post
Share on other sites
Xyl2k

it don't take me long to figure how things work (especially for this one) since it's zeus based if you have previous experiences with zeus, things go easier.
for example this one https://www.youtube.com/watch?v=Z7tEwl1YvMg i did 4 years ago, you may recognize things if you watch it in parallel with kins 3.3.7.0

and yep it's speeded up, my keyboard would be full of blood otherwise :)

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×