Save for later
Reversing the Gophe Spambot
Confronting COM Code and Surmounting STL Snags
Unobfuscated malware can still be overwhelming to analyze. Even accomplished reverse engineers may feel hand-wavey about STL and COM code. Take for example Gophe, a spambot associated with Dyre campaigns and Trickbot C2, which weighs in around 2.6 MB with a 10 KB WinMain, three embedded binaries, copious STL template-generated code, and multiple flavors of atypical COM usage. COM is 27 years old, and plugins are starting to materialize to automate its analysis, but Gophe presents a strong case for understanding COM directly and applying that knowledge to decompilation instead of assembly listings. Meanwhile, C++ reversing is well-covered, but the literature is largely orthogonal to STL code. In this talk, Michael Bailey of FireEye's FLARE Team will share how to tame STL code with knowledge of a few key structures and how to investigate COM usage that doesn't conform to the norm. This will include a guided tour of a Gophe sample to focus on tactics for effective STL and COM reversing by enriching decompilation in Hex-Rays. We'll examine what Gophe is doing with Outlook.Application, Microsoft's Messaging API (MAPI), and one other COM interface that it uses to hide from view. This reverse engineering case study is all ham and no spam, so bring your appetite!
Get a Reminder
Rating | Not enough ratings |
---|---|
Length | 0.7 hours |
Starts | On Demand (Start anytime) |
Cost | $35/month (Access to entire library- free trial available) |
From | Pluralsight |
Instructor | BSides Huntsville |
Download Videos | On Windows, MacOS, iOS, and Android Pluralsight app |
Language | English |
Subjects | IT & Networking |
Tags | Security Professional |
Get a Reminder
Similar Courses
Careers
An overview of related careers and their average salaries in the US. Bars indicate income percentile.
Customer Service Representative/Com Data Coordinator $39k
Athletic Coordinator and Facility Usage Coordinator $47k
Member, Delegate, Chair of Com. on Communications $76k
Ex-Com Member/Political Chair $94k
CIO Com Line of Service Project Manager $104k
Data Migration Analyst / Compliance-Sales/Usage Tax Prep Manager $128k
Program Manager - Usage Management $131k
Write a review
Your opinion matters. Tell us what you think.
Please login to leave a review
Rating | Not enough ratings |
---|---|
Length | 0.7 hours |
Starts | On Demand (Start anytime) |
Cost | $35/month (Access to entire library- free trial available) |
From | Pluralsight |
Instructor | BSides Huntsville |
Download Videos | On Windows, MacOS, iOS, and Android Pluralsight app |
Language | English |
Subjects | IT & Networking |
Tags | Security Professional |
Similar Courses
Sorted by relevance
Like this course?
Here's what to do next:
- Save this course for later
- Get more details from the course provider
- Enroll in this course