Sample
- SHA256
-
75da9dfe4d0ef6db1d68533ef66a70d4c26230fc82e50e6428f4931800f7b3b2 - Difficulty
- medium
- Platform
- Windows
- Tags
- api hashing shellcode stage 2 x64
- Likes
- 0
- Views
- 34
- Submitter
- 0xca5ade19a931
Analysis
Goal
This sample is a second stage payload shellcode extracted from a loader. The goal is to understand its API hashing algorithm and to decrypt the third-stage payload. In addition tampering with security products as evasion techniques can be identified. How is the third-stage payload executed?
Description
The shellcode reads the API hashes from a buffer and replaces their values with the addresses of the resolved functions.
See if you can determine what API hashing algorithm is used.
Can you identify the decryption algorithm used to extract the payload?
The third-stage payload is an executable that is reflectively loaded and executed.
Recommended Tools
binaryninja ghidra
Comments
Please login to view and post comments.