dirtbox, a x86/Windows Emulator
Georg Wicherski Virus Analyst, Global Research and Analysis Team
dirtbox, a x86/Windows Emulator Georg Wicherski Virus Analyst, - - PowerPoint PPT Presentation
dirtbox, a x86/Windows Emulator Georg Wicherski Virus Analyst, Global Research and Analysis Team Motivation & System Overview Why not just use CWSandbox, Anubis, Normans , JoeBox , Malware are Analys lysis is Sandbox Solutions
Georg Wicherski Virus Analyst, Global Research and Analysis Team
Why not just use CWSandbox, Anubis, Norman‘s, JoeBox, …
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
undefinde upon API return
registers after SEH protected API calls)
2010-07-11 REcon 2010, Montreal
kernel32 which wraps around ntdll
Ring 0 malware.exe ntdll
Custom x86 Basic Block Level Virtualization
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
Virtual
Physical
Logical
2010-07-11 REcon 2010, Montreal
Virtual
Physical
Logical
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
Or „The System Call Implementor‘s Sysiphus Tale“
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal
Let‘s use this for exploit development!
2010-07-11 REcon 2010, Montreal
2010-07-11 REcon 2010, Montreal