У нас вы можете посмотреть бесплатно Analyzing Bloated Malware - Trimming Files with a Hex Editor или скачать в максимальном доступном качестве, видео которое было загружено на ютуб. Для загрузки выберите вариант из формы ниже:
Если кнопки скачивания не
загрузились
НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если возникают проблемы со скачиванием видео, пожалуйста напишите в поддержку по адресу внизу
страницы.
Спасибо за использование сервиса ClipSaver.ru
Malware authors will often abuse file formats to complicate analysis and adding unnecessary data is one way to do this. This bloat can disrupt analysis and prevent these malicious files from being detected. In this video, we'll explore how malware authors add unnecessary data to PE files by using the overlay. We'll also explore how the data they choose to use compresses well and allows them to distribute relatively small archive files. We'll then use a hex-editor to remove this data and confirm our newly carved file is still valid using a sandbox. Cybersecurity, reverse engineering, malware analysis and ethical hacking content! 🎓 Courses on Pluralsight 👉🏻 https://www.pluralsight.com/authors/j... 🌶️ YouTube 👉🏻 Like, Comment & Subscribe! 🙏🏻 Support my work 👉🏻 / joshstroschein 🌎 Follow me 👉🏻 / jstrosch , / joshstroschein ⚙️ Tinker with me on Github 👉🏻 https://github.com/jstrosch Sample analyzed in this video on Triage: https://tria.ge/230309-s5taradb64 00:00 Introduction 00:36 Shout out to @Gi7w0rm! 00:54 Getting files from Triage 01:48 Viewing File Properties 02:28 Extracted File Size 02:47 Analyzing the File in Detect-It-Easy 03:30 Viewing the Overlay 04:18 Entropy 05:23 Removing Bloat with HxD Hex-Editor 06:59 Calculating Overlay Size