Event JSON
{
"id": "013ae4c34cabe514f358515bf73aabdcdafb777a826e073a02cc2bfe30bb6917",
"pubkey": "0cc2b0c5cd8701d31062a2eb6f8aa71def61360c75deb8994e668cc1841abe56",
"created_at": 1782296615,
"kind": 1,
"tags": [
[
"t",
"reverseengineering"
],
[
"proxy",
"https://mastodon.social/@joxean/116804590984596374",
"web"
],
[
"t",
"malware"
],
[
"t",
"reversing"
],
[
"t",
"ida"
],
[
"proxy",
"https://mastodon.social/users/joxean/statuses/116804590984596374",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://mastodon.social/users/joxean/statuses/116804590984596374",
"pink.momostr"
],
[
"-"
]
],
"content": "This malware is pretty cool, it took me a while to get to the 4th obfuscation layer myself in IDA even when using a deobfuscation plugin myself, mixes its own obfuscated code deep in legitimate \"goodware\" code, uses lots of MBAs, has anti-VM tricks. High quality malware.\n\nhttps://www.elastic.co/security-labs/oxloader-malware-loader-infostealer\n\n#malware #ida #reversing #reverseengineering",
"sig": "7acc9d1b44027d46e51204308692c1c0d582e5bb5157b683c17eb2aff9745f4ae087eb0b9ef0ee750fa2f4b63743795a0ac4650d2960cc1136f971fcb76306da"
}