Order of Six Angles @orderofsixangles 27.08.2026 04:03 Скопировать Пожаловаться broke Pyarmor with Frida to recover JavaScript malware payloads https://youtu.be/5jMK_g4kLLc?si=Yt6o_antuPw6apEF YouTube Breaking Efimer Loader with Frida (Stream - 18/08/2026) In this stream we analyze the Efimer loader that is protected with the Pyarmor project (https://github.com/dashingsoft/pyarmor) and decrypt the loader's follow-on payloads by dumping Python runtime metadata by hooking and calling Python's runtime functions with Frida (https://frida.re/). We then move onto a BinjaLattice MCP showcase where we get it to analyze a stealer sample with Binary Ninja and Cursor. Learn how to reverse engineer malware: https://training.invokere.com/ Stream files available with Premium: https://training.invokere.com/course/premium Twitch: https://www.twitch.tv/InvokeReversing Twitter: https://twitter.com/InvokeReversing BlueSky: https://bsky.app/profile/invokereversing.bsky.social/ Mastodon: https://infosec.exchange/@invokereversing 00:00 Stream Intro 00:59 Intro to Pyarmor, Frida, Efimer 07:34 Frida Scripts for Dynamic Hooking 23:00 Ghidra vs Binja Tangent 28:20 Frida Hooking Pyarmor 44:00 Decrypting Second Stage Payload 48:20 Writing Decryption Script 58:34 Analyzing Obfuscated JavaScript 1:00:49 Malicious JavaScript Analysis 1:09:52 Answering Questions 1:17:04 Binja Lattice MCP Showcase 1:36:16 Wrapping Up 30 1K
Обсуждение 0
Обсуждение не доступно в веб-версии. Чтобы написать комментарий, перейдите в приложение Telegram.
Обсудить в Telegram