Analyzing Microsoft Zero-Day Exploit (CVE-2021-40444)

Описание к видео Analyzing Microsoft Zero-Day Exploit (CVE-2021-40444)

In this video we are looking at the brand new zero-day exploit for CVE-2021-40444, we understand the attack chain and deobfuscate some exploit code.

Samples:
court.docx: https://bazaar.abuse.ch/sample/938545...
side.html: https://bazaar.abuse.ch/sample/d0fd7a...
ministry.cab: https://bazaar.abuse.ch/sample/1fb13a...

deobfuscate.py: https://github.com/lasq88/MalwareAnal...

CVE-2021-40444 advisory: https://msrc.microsoft.com/update-gui...

00:00 Intro
00:46 Dynamic analysis
08:37 Static analysis
10:58 Deobfuscation
19:00 Analyzing exploit
22:52 Infection chain
27:45 Final payload
31:30 Summary

#cve-2021-40444 #zeroday #malware #infosec #reverseengineering

Комментарии

Информация по комментариям в разработке