04-30-2017 , 10:17 PM
Published on Apr 13, 2017
We unpack a Dridex sample that uses process hollowing for memory execution.
Follow me on Twitter: @struppigel
Sample: https://www.hybrid-analysis.com/sampl...
Dridex article: https://countuponsecurity.com/2015/12...
Process hollowing: http://www.autosectools.com/Process-H...
API Monitor: http://www.rohitab.com/apimonitor
- Category
- License
- Standard YouTube License
- Standard YouTube License