An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).
-
Updated
Feb 2, 2024 - C
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).
Kernel-Mode Driver that loads a dll into every new created process that loads kernel32.dll module
This is a virus removal (protection) tool for a virus commonly known as "Dulla virus" and several weeks later by A/V vendors Win32.Agent.cb. Motivation of the work: even though this PE infector is very dangerous and was stealthily spreading fast, the major A/V companies failed to respond to this threat. Hence, needed to make own removal and prot…
Add a description, image, and links to the malware-analyzer topic page so that developers can more easily learn about it.
To associate your repository with the malware-analyzer topic, visit your repo's landing page and select "manage topics."