Descubre 4n4lDetector Pro y Pescan.io

Analiza archivos de forma avanzada con 4n4lDetector Pro y prueba la versión online en Pescan.io. Todo desde tu navegador o tu escritorio.

Intelligent String para priorizar IOCs útiles, heurísticas de flujo anómalo, generación de reglas YARA con un clic, carving de encabezados PE, y detección de firmas Microsoft manipuladas. Compatible con 32/64-bit y formatos comunes (.exe, .dll, .sys, .ocx, .scr, .drv, .cpl). Funciona desde cualquier navegador o en tu escritorio con CLI, GUI y plataforma web integrada. Incluye hash intelligence, gamificación interna, Interest Words, y más de 10,000 reglas para detección avanzada de malware.

Process Simulator

I found this tool in my catchall, having developed it years before. It is useful for simulating processes, along with their respective form names, and also uses a wildcard text box. It helped me analyze various banking malware, as I managed to make them believe that I had my browser open and that I was visiting pages that are used to make bank transfers. In this way, the malware launches the injections for each bank, it also simulates Antivirus applications, Firewalls, Sandboxes, Virtual Machines, Debuggers and Hacking Tools (to force the malware to change its execution modes in the environment), all this is configurable by the user from the configuration button. It simulates MDI applications, applications with standard forms, and also has a console mode to facilitate automatic execution in sandbox environments. Finally, the tool also has mock function libraries loaded automatically by some Google Chrome, Opera, Firefox, Internet Explorer, Safari and Microsoft Edge browsers and debuggers via the following process names:

  • chrome.exe
  • opera.exe
  • firefox.exe
  • iexplore.exe
  • safari.exe
  • microsoftedge.exe
The Bukake runs all the processes selected in the options, while the Kill Process button kills them quickly. What did they think? ;)

Config File and Help option:

Library simulation:


23/12/2022
Pass: 4n0nym0us

No hay comentarios:

Publicar un comentario