Open in app

Sign in

Write

Sign in

ZYWU
ZYWU

14 Followers

Home

About

Pinned

Unpacking Matryoshka: What the History Means for Russian Cybercrime

More and more cyber-attacks incidents have occupied the headlines. A man, wearing a hoodie and sitting behind a computer, hacks the world…

Mar 25, 2021
Unpacking Matryoshka: What the History Means for Russian Cybercrime
Unpacking Matryoshka: What the History Means for Russian Cybercrime
Mar 25, 2021

Two duplicated but defected keys among the Avaddon ~3000 released private keys

Jun 12, 2021
Jun 12, 2021

Emotet 殭屍網路真的被駭了嗎?

七月底的一大資安新聞是殭屍網路 Emotet 被惡搞的消息。

Aug 10, 2020
Emotet 殭屍網路真的被駭了嗎?
Emotet 殭屍網路真的被駭了嗎?
Aug 10, 2020

Dive into anti analysis of Emotet loader

We discussed the cryptor in the previous post. As for the loader part, we are going to document some carefully designs, which are use to…

Mar 31, 2019
Dive into anti analysis of Emotet loader
Dive into anti analysis of Emotet loader
Mar 31, 2019

Dive into recent Emotet’s cryptor

Sample – 7a305cbbe2a950663827953cf398078d7b18baa4

Mar 25, 2019
Dive into recent Emotet’s cryptor
Dive into recent Emotet’s cryptor
Mar 25, 2019

Pegasus Source Code Analysis Notes

The leak and background: https://malware-research.org/carbanak-source-code-leaked/

Feb 15, 2019
Pegasus Source Code Analysis Notes
Pegasus Source Code Analysis Notes
Feb 15, 2019

A Study on ConfuserEx Control Flow Flattening Technique

Recently, I came across an infostealer malware called HawkEye. HawkEye is written in C#. In this post, I’m going to sahre the control flow…

Jan 16, 2019
1
A Study on ConfuserEx Control Flow Flattening Technique
A Study on ConfuserEx Control Flow Flattening Technique
Jan 16, 2019
1

How to analysis TrickBot PoS Module w/ Labled Data Structure in IDAPro

Background

Jan 10, 2019
How to analysis TrickBot PoS Module w/ Labled Data Structure in IDAPro
How to analysis TrickBot PoS Module w/ Labled Data Structure in IDAPro
Jan 10, 2019

Decrypting EMOTET’s strings using IDAPython

EMOTET is a crime ware loader. The affiliates are — TrickBot, Zeus Panda, IceID, and so on. US-CERT has published alert on the malware in…

Jan 8, 2019
Decrypting EMOTET’s strings using IDAPython
Decrypting EMOTET’s strings using IDAPython
Jan 8, 2019
ZYWU

ZYWU

14 Followers

push ebp; mov ebp, esp;

Help

Status

About

Careers

Press

Blog

Privacy

Terms

Text to speech

Teams