Posts

Showing posts from October, 2020

Malware Reverse Engineering

Image
I recently analyzed and submitted some malware to Microsoft Security Intelligence that I found on a YouTube video.  The video has since been reported so it may not be available.  https://www.youtube.com/watch?v=uQG6Xwxdb2A This YouTube video promoted downloading a program that claimed to "generate" keys for copyrighted software. Windows Defender identified it as Trojan:Win32/Wacatac.C!ml .  Here below is the Virus Total entry: https://www.virustotal.com/gui/file/509e1b4447cd7f0c448b31d88a41dbca6ceca5a029caabfa2bd10b7c965bbe51/detection The first thing I did was analyze for malicious registry changes with a program from Nir Soft called  RegistryChangesView v1.26 . I did not find malicious registry changes. The few changes to the registry were normal Windows behavior, for example here was one registry change: ================================================== Registry Key : HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-...