Analyzing Microsoft Zero-Day Exploit (CVE-2021-40444)

preview_player
Показать описание
In this video we are looking at the brand new zero-day exploit for CVE-2021-40444, we understand the attack chain and deobfuscate some exploit code.

Samples:

00:00 Intro
00:46 Dynamic analysis
08:37 Static analysis
10:58 Deobfuscation
19:00 Analyzing exploit
22:52 Infection chain
27:45 Final payload
31:30 Summary

#cve-2021-40444 #zeroday #malware #infosec #reverseengineering
Рекомендации по теме
Комментарии
Автор

Straight to the point, Awesome analysis!

itsnee
Автор

Great analysis. Looking forward for more!

clipper
Автор

good explanation, nice audio quality and analysis sharing the Deobfuscation code and where to download the sample malware is cool as well! Information Sharing!

mysteryhogs
Автор

Excellent work on simplifying the analysis!

garaldo
Автор

Very Nicely Explained.. Thanks for Sharing Sir

anandsinghdhouni
Автор

Omg. Please show us how you animate yourself in that south park style.

Ltbnary
Автор

what an awesome demonstration, nicely done! 😻

_CryptoCat
Автор

Excellent! Could you do some more vid on zero-day exploits!

eagle
Автор

this is quality content :)
can you post some resource for reading about structure and rendering of docx files

duckie
Автор

Holy Cr*p, how did you synchronize your ANIMATED mouth correctly to the SPEECH? (Sorry, the explanation of the attack chain is also good :) )

kanamung
Автор

Wow. Nice! Thank you. By the way, what do you use for making the talking avatar in your videos?

roboedar
Автор

Great video, how did you manage to compile file to call out?

dano
Автор

Can you please show how to reproduce this ?

chhatrapalsinhzala
Автор

Sir please make a video on how to exploit Open port services using CVE 🙂.

xxehacker
Автор

Sorry, I'm learning how to analyze cve now.
And I choose cve-2021-40444 as my first practice, but i have trouble with building environment.
I downloaded sample from you provided link above in my Win10 VM but I couldn't open .
It show me that I can't unzip this file.
Could you tell me how to do?
Thanks!!!!
Your video help me a lot!

kwiuekf
Автор

Please can you share for payload generating?

lakshmikumar
Автор

Hi, thanks for the great video!
Can you please tell me how did you menage to make your ubuntu machine intercept the windows's box http connections, any blog, link or anything that may help is appreciated, thanks.

hakim
Автор

Was there something that was in the script to prevent you from commenting out the check function or even just the shift part of it?

jamiekomodo
Автор

my boy have an Bulgarian or (Eastern European) accent :)

sharebt
Автор

why send and configure a payload like a reverse tcp when you can hidden with a crypter a simple trojan that works much better and have the full control of device?

youtubee