Skip to content

Joe's Security Blog

reversing

Backdooring DLL’s Part 2

Today I have some good news. Backdooring a dll file is a lot easier than I first made it out to be. Especially if we skip the bullshit of the IAT and take advantage of shellcode. There are problems with using shellcode – size constraints are different. In my previous example, I didn’t need much […]

July 29, 2016July 31, 2016 averagejoe code, Joe you evil bastard, reversing2 Comments

CTB-Locker and Dropper

Users of the net dread this screen. They feel when they see it all hope is lost. In the case of this ransomware dropper, the same holds true. In fact, in running this, I lost my downloads folder >:( Indeed, a risk all malware reverse engineers take. Live and learn right? Anywho, let’s dive into […]

February 14, 2015February 20, 2015 averagejoe reversing4 Comments

Toorcon 16 slides and code

For those of you whom saw me at ToorCon and those of you who wish they could have, Here are my slides, and here are my code notes(pass is infected). I also had a 90 minute seminar on reverse engineering malware for newbies. Here are the slides and here are the samples / crackmes /tools. […]

October 27, 2014 averagejoe UncategorizedLeave a comment

Syrian Malware 2 – Electric Boogaloo

Back for part 2 are we? Let’s get this show on the road. We’ve seen how awful the first piece of malware was in terms of how it was thrown together in all but 10 minutes, but you aint seen nothing yet. The next one actually embeds passwords inside and even email addresses. After that, […]

July 29, 2014July 29, 2014 averagejoe code, cracking, reversingLeave a comment

Writing your own windows debugger in C

Hello all! I’m cracking away on various projects and trying to keep focus. As I was going through my old notes, I came across a talk I wanted to give but could not due to my car accident and the subsequent down time caused me to forget. I wanted to cover making your own debugger […]

December 9, 2013December 9, 2013 averagejoe code, reversingLeave a comment

reversing a botnet 2 – electric boogaloo

It happened again at work. This time twice the number of machines hit. The same people hit my company, and they took my advice when I last spoke to them – they obfuscated the executable to make it harder to perform a routine reverse engineering analysis. In this particular case, the obfuscation used was compiled […]

April 13, 2013April 17, 2013 averagejoe code, cracking, Joe you evil bastard, reversingLeave a comment
Blogroll
  • CG – Christ Gates
  • MadMouse
  • RageStorm
Find It

Home

June 2025
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
30  
« Dec    

Proudly powered by WordPress | Theme: Sweetheat by aThemes

Top