75da9dfe4d0ef6db1d68533ef66a70d4c26230fc82e50e6428f4931800f7b3b2
|
0xca5ade19a931
|
medium
|
|
This sample is a second stage payload shellcode extracted from a loader. The goal is to understand its API hashing algorithm and to decrypt the third-stage payload. In addition tampering with security products as evasion techniques can be identified. How is the third-stage payload executed?
|
1
|
|
1
|
27 Sep 2026
|
291df8186e62df74b8fcf2c361c6913b9b73e3e864dde58eb63d5c3159a4c32d
|
malcat
|
medium
|
|
Use emulation and/or static analysis to get to the final malware and extract its configuration
|
1
|
|
1
|
04 Jan 2026
|
5544e6c66cbf6503cddef2797acbff4fb81ededaef2334a596e6484cfaa0b8e8
|
struppigel
|
medium
|
|
Unpack the payload. This can be done either with a debugger or using only static unpacking with binary refinery. Note: The payload is obfuscated with VMProtect, deobfuscating it is not part of the task.
|
2
|
|
0
|
26 Dec 2025
|