YoVDO

Lockbit's DLL Name Seeding Technique for API Hashing - Part 5

Offered By: Dr Josh Stroschein via YouTube

Tags

Malware Analysis Courses Reverse Engineering Courses Windows Internals Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of Lockbit's runtime-linking technique in this 14-minute video tutorial. Delve into how Lockbit utilizes the DLL name as a seed for API hashing, a unique twist on standard malware techniques. Learn to identify the image_base, parse the image DOS header, and understand DATA Directories. Examine the IMAGE_EXPORT_DIRECTORY and AddressOf* functions. Discover how the DLL name generates checksums that serve as seeds for API name computation. Gain insights into the UNICODE structure and its relevance. Enhance your reverse engineering skills and grasp the broader implications of these techniques on malware analysis efforts.

Syllabus

Finding the image_base
Parsing the image dos header
DATA Directories
The IMAGE_EXPORT_DIRECTORY
AddressOf*
Checksum from a DLL name - where the seeds come from
Brief note on the UNICODE structure


Taught by

Dr Josh Stroschein

Related Courses

The RedTeam Blueprint - A Unique Guide To Ethical Hacking
Udemy
Indicators of Compromise - From Malware Analysis to Eradication
44CON Information Security Conference via YouTube
Counterfeiting the Pipes with FakeNet 2.0 - Part 2
Black Hat via YouTube
Advanced Process Injection Techniques
NorthSec via YouTube
Hypervisors in Your Toolbox - Monitoring and Controlling System Events with HyperPlatform
nullcon via YouTube