- Apr 9, 2020
- 667
I made a short malware analysis instruction video based on the file posted here: Suspicious "game"
Description:
We investigate a "game" named crazydown.exe. The application was written in JavaScript and built with Electron Framework resulting in a huge Portable Executable. Where do we find the malware code in a 150 MB application?
Sample: Triage | Malware sandboxing report by Hatching Triage
Asar Plugin: Asar7z
Electron: Introduction | Electron
00:00 Intro, what is Electron Framework
00:50 Triage on VirusTotal
03:44 Unpacking Nullsoft
04:09 Unpacking .asar archive
06:52 Decrypting the JavaScript stealer
Description:
We investigate a "game" named crazydown.exe. The application was written in JavaScript and built with Electron Framework resulting in a huge Portable Executable. Where do we find the malware code in a 150 MB application?
Sample: Triage | Malware sandboxing report by Hatching Triage
Asar Plugin: Asar7z
Electron: Introduction | Electron
00:00 Intro, what is Electron Framework
00:50 Triage on VirusTotal
03:44 Unpacking Nullsoft
04:09 Unpacking .asar archive
06:52 Decrypting the JavaScript stealer