TheAbsnt
TheAbsnt
TheAbsnt
Let's explore the mechanics behind the misbehaving binaries

Memory-Only Mayhem: JScript to Powershell to .NET Loader to Infostealer

Memory-Only Mayhem: JScript to Powershell to .NET Loader to Infostealer

Guardians Paradox: When Protector becomes Predator - Malware Version

Guardians Paradox: When Protector becomes Predator - Malware Version

Challenge #2: IcedID Configuration Extraction

Challenge #2: IcedID Configuration Extraction

Analysis of ChineseAPT: RedDelta's Recent Infection Chain

Analysis of ChineseAPT: RedDelta's Recent Infection Chain