Malware Samples Crashing x64dbg Fixed!
Update: 2019-01-27
Description
We dive into why some recent malware samples have been crashing in x64dbg. Expand for more...
Example (Vidar) sent from subscriber packed with packer that crashes old versions of x64dbg :
7b2c480736bc2ea3c6e064077e78c6a0acabbd83d0e4e637673c9deb966296d5
Download x64dbg (with fix for crash):
https://x64dbg.com/#start
Donate to x64dbg:
https://www.bountysource.com/teams/x64dbg
Corkami PE file map:
https://github.com/corkami/pics/tree/master/binary/pe102
MSDN PE file documentation:
https://docs.microsoft.com/en-us/windows/desktop/debug/pe-format#export-directory-table
PE Bear download:
https://github.com/hasherezade/pe-bear-releases/releases/tag/0.3.9.5
Feedback, questions, and suggestions are always welcome : )
Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw
As always check out our tools, tutorials, and more content over at https://www.openanalysis.net
#x64dbg #MalwareAnalysis #Tutorial #OpenAnalysis
Example (Vidar) sent from subscriber packed with packer that crashes old versions of x64dbg :
7b2c480736bc2ea3c6e064077e78c6a0acabbd83d0e4e637673c9deb966296d5
Download x64dbg (with fix for crash):
https://x64dbg.com/#start
Donate to x64dbg:
https://www.bountysource.com/teams/x64dbg
Corkami PE file map:
https://github.com/corkami/pics/tree/master/binary/pe102
MSDN PE file documentation:
https://docs.microsoft.com/en-us/windows/desktop/debug/pe-format#export-directory-table
PE Bear download:
https://github.com/hasherezade/pe-bear-releases/releases/tag/0.3.9.5
Feedback, questions, and suggestions are always welcome : )
Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw
As always check out our tools, tutorials, and more content over at https://www.openanalysis.net
#x64dbg #MalwareAnalysis #Tutorial #OpenAnalysis
Comments
In Channel























