Malware Analysis - Unpacking Lumma Stealer from Emmenhtal and Pure Crypter
Автор: MalwareAnalysisForHedgehogs
Загружено: 2025-03-02
Просмотров: 5605
Last time we extracted a download URL, in this video we unpack the rest of the Emmenhtal to Pure Crypter to Lumma Stealer infection chain.
Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Tools: binary refinery, Sysinternals strings.exe, notepad++, dnSpyEx, NetReactorSlayer, DiE, Python 3, dnlib
string-decrypt script: https://gist.github.com/struppigel/7f...
Posh script: https://bazaar.abuse.ch/sample/0a92ab...
Posh loaded: https://bazaar.abuse.ch/sample/9297b5...
wvff.pdf (encrypted): https://bazaar.abuse.ch/sample/26b50b...
Lumma payload: https://www.virustotal.com/gui/file/2...
ConfuserEx 2 deobfuscation video: • Malware Analysis - ConfuserEx 2 Deobfuscat...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
#malware #malwareanalysis #reverseengineering
00:00 Intro
00:33 Unpacking first PowerShell layer
09:17 Unpacking .NET mediafire downloader
10:16 Analyzing .NET downloader
12:07 Decrypting wvff.pdf
13:03 Deobfuscating NET Reactor 6.X
21:54 Unpacking Lumma Stealer
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: