Autoplay
Autocomplete
Previous Lesson
Complete and Continue
Reverse Engineering & Malware Analysis - Intermediate Level
Introduction
1. Introduction (5:29)
Types of Malware and Malware Analysis Terminologies
2. Types of Malware (6:11)
3. Malware Analysis Terminologies (4:44)
Lab: Analysis of .NET Trojan Spyware (Info-Stealers)
4. Dynamic Analysis of .NET Trojan - Part 1 (7:11)
5. Dynamic Analysis of .NET Trojan - Part 2 (5:44)
6. Static Analysis of .NET Trojan - Part 1 (10:09)
7. Static Analysis of .NET Trojan - Part 2 (5:57)
Assembly Language Refresher and Malicious APIs
8. Assembly Language Refresher (9:50)
9. Malicious APIs (3:33)
API Hooking, Process Hijacking and Dumping Memory
10. Using API Hooking to Analyze Malware - PandaBanker (17:35)
11. Tracing Process Hijacking and Dumping Memory (13:41)
12. Fixing Section Alignment, Unmapping, fixing IAT and Re-basing (13:22)
Lab: Unpacking Emotet Trojan
13. Unpacking Part 1: Static Analysis of Emotet Trojan (6:09)
14. Unpacking Part 2: Debugging of Emotet Trojan to Hunt For Unpacked Code (11:41)
15. Unpacking Part 3: Dumping Memory and Unmapping Dumped File (8:09)
Lab: Unpacking Hancitor Trojan
16. IDA Static Analysis and xdbg Enumerating Breakpoints (8:12)
17. API Hooking and Memory Tracing (13:45)
18. Dumping Memory and Unmapping File (7:39)
Lab: Unpacking Vmprotect Trojan
19. API Hooking with VirtualProtect, VirtualAlloc and GetProcAddress (12:51)
20. Memory Tracing and Scylla Dumping (15:16)
21. PE-Studio and Interactive Delphi Reconstructor (IDR) (4:55)
Lab: Unpacking Trickbot Trojan
22. Unpacking part 1: API Hooking (9:51)
23. Unpacking part 2: Dumping from Memory Map (15:56)
24. Unpacking part 3: Un-mapping Dumped File (5:43)
Lab: Unpacking Dridex Trojan
25. Dridex - part 1 - Initial Analysis (5:27)
26. Dridex - part 2 - API Enumeration Count (13:56)
27. Dridex - part 3 - Self-Injection and Process Hacker Dumping (6:43)
28. Dridex - part 4 - Unmapping the Dumped File (4:57)
Lab: Unpacking Ramnit Trojan
29. Ramnit - part 1 - Using CreateProcessInternalW to Track Child Process (8:19)
30. Ramnit - part 2 - Tracking VirtualAlloc to Identify When To Dump (11:35)
31. Ramnit - part 3 - Unpacking UPX with CFF Explorer (5:17)
Lab: Unpacking Remcos Trojan with xdbg and dnSpy
32. Remcos - part 1 - exploring .NET with xdbg (12:01)
33. Remcos - part 2 - CreateProcessInternalW, WriteProcessMemory and NtResumeThread (7:18)
34. Remcos - part 3 - Analysis with PE-Bear and PE-Studio (4:30)
35. Remcos - part 4 - Unpacking with dnSpy by tracing Invoke (9:24)
Lab: Unpacking Zloader Trojan
36. Zloader - part 1 - PE-Studio and API Hooking until VirtualProtect (7:38)
37. Zloader - part 2 - Tracing Pointer to Unpacked Code for Dumping (5:40)
38. Zloader - part 3 - PE-Studio and PE-Bear Analysis (2:56)
Resources For Further Study
39. Bonus Lecture (1:47)
8. Assembly Language Refresher
Lesson content locked
If you're already enrolled,
you'll need to login
.
Enroll in Course to Unlock