oalabs
patreon
Live Stream VOD: Hermetic Wizard WMI Spreader Reverse Engineering COM
🕑 Added 2022-03-14 01:30:56 +0000 UTCIn this Twitch stream we continue our analysis of the WMI spreader component of the Hermetic Wizard malware used in the recent cyber attacks on Ukraine. In this stream we focus on the COM component that is used to interface with WMI.
Sample: a259e9b0acf375a8bef8dbc27a8a1996ee02a56889cba07ef58c49185ab033ec
Research Notes: Hermetic Wizard Malware
COM Reverse Engineering
For more information on COM reverse engineering check out Mike Bailey's COM Presentation. He also has a nice (free) video on Pluralsight.
Comments
m4n0w4r
Just push here some of my pseudo-code: https://github.com/m4now4r/HermeticWizard/tree/main/WMI%20spreader
m4n0w4r
Another useful vid from our friend DuMp-GuY TrIcKsTeR :https://www.youtube.com/watch?v=8tjrFm2K30Q