Get a Pentest and security assessment of your IT network.

News

Dismantling KillDisk: reverse of the BlackEnergy destructive component

KillDisk is a module of BlackEnergy framework aimed at data destruction and creating havoc / distraction during the APT operations. The main tools used in our analysis today are Process Monitor and IDA Pro Disassembler. All manipulations will be performed in virtual environment based on Windows XP operating system. We start with making a quick initial setup of test VM, power on the machine and create a snapshot called Before infection. Let us head straight to the main function, i.e. the WinMain function.”]

Source: https://socprime.com/blog/dismantling-killdisk-reverse-of-the-blackenergy-destructive-component/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin