Hi,
Some time ago i wrote a little tutorial on Carberp, from a reversing point of view, here the link:
http://quequero.org/Carberp_Reverse_Engineering
Some additional info with Wireshark Extension to automate decryption
Decrypting Carberp C&C communication
http://securityblog.s21sec.com/2011/07/ ... ation.html
In attachment with password infected the sample used for analysis
Regards,
Evilcry
Some time ago i wrote a little tutorial on Carberp, from a reversing point of view, here the link:
http://quequero.org/Carberp_Reverse_Engineering
Some additional info with Wireshark Extension to automate decryption
Decrypting Carberp C&C communication
http://securityblog.s21sec.com/2011/07/ ... ation.html
In attachment with password infected the sample used for analysis
Regards,
Evilcry
Attachments
(128.13 KiB) Downloaded 64 times