JGE, JL instructions and the usage of the API Monitor (Assembly basics Pt. 4) - Malware analysis

preview_player
Показать описание
In this malware analysis tutorial you will learn how to look for junctions using API Monitor and based on this we will change the JGE instruction to JL in 4 different debuggers (OllyDBG 2.01, OllyDBG1.1, Immunity Debugger, WinDbg), both in manual and automated way.

This video is the 5th tutorial of the Malware analysis course at Duckademy.
The 1st and the 2nd tutorials and the virtual machine are also available:

This malware analysis tutorial will cover:
01:03 Finding the junction in the sample application with API Monitor
06:40 Manual patching in OllyDbg 2.01
09:30 Manual patching in OllyDbg 1.1
11:22 Automating the patching in OllyDbg 1.1 with OllyScript
15:05 Manual patching in Immunity Debugger
16:37 Automating the patching in Immunity Debugger
24:20 Manual patching in WinDbg
31:08 Automating the patching in WinDbg

Please note that this malware analysis tutorial is for educational purposes only.

SUBSCRIBE NOW FOR NEW FREE IT TUTORIALS!

SUBSCRIBE TO OUR EMAIL LIST!

FOLLOW US!

---------------------------------------------------------------------------------
Рекомендации по теме
Комментарии
Автор

Hello. Can you tell me if there are such reversing and debugging courses for user support specialists? If there is no source text and the technical support of the programs does not respond. I need myself to find the reasons for the malfunctioning of applications or crashes of applications in the Windows system.

Anton_Zh
Автор

Thank you for these excellent videos on Malware Analysis... I have very much enjoyed watching videos 1, 2, and 5 of the course series, and I am very interested in watching the remainder of the course, but can not find them anywhere on YouTube or your duckademy.com website... where can I find / obtain the entire course,

antoniodesousa