-
Recent Posts
Recent Comments
Archives
- March 2015
- February 2015
- December 2014
- November 2014
- October 2014
- September 2014
- August 2014
- July 2014
- June 2014
- May 2014
- April 2014
- March 2014
- February 2014
- January 2014
- December 2013
- November 2013
- October 2013
- September 2013
- August 2013
- July 2013
- June 2013
- May 2013
- April 2013
- March 2013
- February 2013
- January 2013
- December 2012
- November 2012
- October 2012
- September 2012
- August 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
Categories
Meta
Author Archives: darryl
A Quick Peek at Network Injection
Like many of you, I’ve been looking at the various NSA document leaks to see what kind of tools and techniques are being used. I suppose these releases will give cybercriminals new ideas and we will see some of these … Continue reading
Wild Wild West – 07/2014
Added the following packs: RIG Exploit Kit Niteris aka “CottonCastle” “Snet” Special thanks to Kafeine for his valuable input.
Posted in Exploit Packs
Comments Off on Wild Wild West – 07/2014
Reversing a PHP Script Dynamically and Statically
A reader sent me two PHP scripts because the PHP Converter program I wrote wasn’t able to handle it. They are both similar so I’ll just work on one of them in this post. Here’s what it looks like: And … Continue reading
Posted in Malscript, Tools
Tagged deobfuscation, php obfuscation, phpconverter
Comments Off on Reversing a PHP Script Dynamically and Statically
Deobfuscating PHP Scripts
Occasionally people send me PHP scripts to help them analyze it. Most of the time, it’s simply unescaping the script and finding the right variable to echo. I got two tricky ones within the past couple of months and finally … Continue reading
Posted in Malscript, Tools
Tagged php obfuscation, php script
Comments Off on Deobfuscating PHP Scripts
Reversing RIG EK’s Flash File
VirusTotal is showing 0 out of 51 for RIG EK’s SWFIE exploit (MD5: 65AFF3A3774298B3ED5BA2C43F8A1979). Here’s a really quick overview on how to reverse this exploit file so we can determine which vulnerability it’s using. This method can also be used … Continue reading
Posted in Exploit Packs, Malscript, Tools
Tagged exploit kit, flash, rig
Comments Off on Reversing RIG EK’s Flash File