ȸ α â


α ޴

!  å

  • ߻
  • ߻
    <Ŭ󸮽 丣> /<ν³>... | ȭ
 󼼺
 Ͼ   ̵


Ͼ ̵

<ī Ÿ>,<Ÿ ġ>,<϶ ξŰ>,<͹Ÿ > /<â>,<> | Ѻ̵

Ⱓ
2022-01-03
ePub
뷮
19 M
PC
Ȳ
1, 0, 0
å α׷ ġ ȵǽó?å α׷  ġ
 Ұ
 Ұ
ټ

 Ұ

[ѱ Ư η ]
Բ ϰ Ͼ


Ʈ Ͼ ַ ҽڵ尡 ȯ濡 Ÿ α׷ м ȴ. Ͼ (Ghidra) Ϸ ̿ܿ پ Űó Ͽ Ǽ α׷ м, ߿ м, پ о߿ Ȱ ִ. ׷ Ȱϱ ؼ dz ʿϴ. å ǽ ߽ ̳ м ȿ ֵ ߴ. پ α׷ мϸ ü ̸ ٶ.

ڼҰ

߻̹潺(cyberdefense) ҿ Cyber Threat Intelligence Analyst ϸ ֿ м, , м ð ִ. о Ŭ ü(Allsafe) ̱⵵ ϴ. JSAC, HITCON CMT, AVAR, CPRCon, Black Hat EUROPE Arsenal, CodeBlue BlueBox  ߴ.

CHAPTER 1 Ͼ Թ

1.1 Ͼ
1.2 α׷
1.3 ȣ Ծ
1.4 C
1.5 PE
1.6 x64 Űó

CHAPTER 2 Թ

2.1
2.2 ġ
2.3 Ʈ
2.4 Ʈ
2.5 CodeBrowser

CHAPTER 3 Ͼ

3.1 downloader.exe
3.2 м ٹ
3.3 Լ μ м
3.4 ü
3.5 downloader.exe м ġ

CHAPTER 4 Ghidra Script/Extension Ȯ

4.1 Ȯ
4.2 Ghidra Script
4.3 Ghidra API
4.4 Headless Analyzer
4.5 Ghidra Extension

CHAPTER 5 Ghidra vs. Crackme - ELF ũ м

5.1 ũ̶
5.2 Level1 XOR ܼ ڴ
5.3 Level2 Ŀ ڴ
5.4 Level3 ÷
5.5 Level4 Go ̳ʸ ؼ

CHAPTER 6 Ghidra vs. MOTHRA - 鵵 м

6.1 м غ
6.2 main Լ
6.3 C2 ɾ ˻
6.4 ɾ б
6.5 MOTHRA RAT м ġ

CHAPTER 7 Ghidra vs. BlackBicorn - Ŀ м

7.1 Ŀ
7.2 BlackBicorn
7.3 BlackBicorn м( 0)
7.4 BlackBicorn м( 1)
7.5 BlackBicorn м( 2)
7.6 BlackBicorn м ġ

CHAPTER 8 Ghidra vs. Godzilla Loader - ֿ м

8.1 ֿ Godzilla Loader
8.2 м
8.3 Ŀ м
8.4 ڿ ȭ
8.5 Godzilla Loader
8.6 Godzilla Loader м ġ

CHAPTER 9 Ghidra vs. SafeSpy - ȵ̵ м

9.1 ȵ̵
9.2 ȵ̵ Ƽ ̺귯
9.3 ȵ̵ м
9.4 SafeSpy м

APPENDIX A

A.1 Binary Patching
A.2 Program Difference
A.3 Version Tracking
A.4 Ghidra Server
A.5 Ŀ͸
A.6 ÷ Ű

APPENDIX B Ghidra Script Ұ

B.1 Ghidra Script
B.2 Ƽ Ghidra Script
B.3 ڵ ũƮ

APPENDIX C Ǯ

C.1 Level1.exe
C.2 Level2.exe

ټ

  • 10
  • 8
  • 6
  • 4
  • 2

(ѱ 40̳)
侲
Ʈ
 ۼ ۼ õ

ϵ ϴ.