August 30, 2019
- Ge! Stop! What's Segmentation? Memory segmentation The 80186 is a faster version of the 8086. It also has a 20-bit address bus and 16-bit data bus,
October 1, 2015
Extracting the Botnet Configuration: The bot configuration is encrypted inside the bot and decrypted while the bot is running. In 1.0.2.5, 1.5 and 1.6 versi
September 28, 2015
Bot Analysis: Now, you get the original Andromeda build file. Load the unpacked sample at OllyDBG. As before, after the stack frame at the EP, you see that t
September 25, 2015
Introduction: Andromeda, also known as Win32/Gamarue, is an HTTP based botnet. It was first spotted in late 2011, and is still at this moment used a lot in h
June 5, 2015
Introduction Kuluoz, aka Asprox, is a spam botnet that emerged in 2007. It has been known for sending mass of phishing emails used in conjunction with social
October 23, 2012
For part 2 of this series, please click here. Programming in a high-level language does not require a detailed knowledge of the system hardware. Assembly la
September 28, 2012
For those of you who have been following my eventful career, you already know that this is actually my second published tutorial. Just to bring you up to dat