bOtc0nfeu

Incremental clustering of malware packers using features based on transformed CFG

Botconf 2023 Additional papers Additional paper Incremental clustering of malware packers using features based on transformed CFG Ludovic Robin 🗣 | Corentin Jannier 🗣 | Jean-Yves Marion 🗣 Packer detection is an important topic because most malware is packed and this allows it to avoid detection based on static analysis. Identifying classes of packers is the key to effective detection

Incremental clustering of malware packers using features based on transformed CFG Read More »

Perfect Smoke and Mirrors of Enemy: Following Lazarus group by tracking DeathNote campaign

Botconf 2023 Wednesday  | 11:20 – 11:50 Short presentation Perfect Smoke and Mirrors of Enemy: Following Lazarus group by tracking DeathNote campaign Seongsu Park 🗣 Prime suspects behind the Sony Pictures Entertainment cyberattack, Wannacry outbreak are a hacker collective known as Lazarus Group with associations with the Pyongyang regime. This notorious adversary is one of

Perfect Smoke and Mirrors of Enemy: Following Lazarus group by tracking DeathNote campaign Read More »

Using systematic code reuse analysis to create robust YARA rules

Botconf 2023 Tuesday  | 13:00 – 16:30 Workshop Using systematic code reuse analysis to create robust YARA rules Jonas Wagner 🗣 | Carlos Rubio Ricote 🗣 | David Pastor Sanz 🗣 YARA is a commonly used tool to detect and identify malware. There are roughly two types of YARA rules used on binary files: 1) based on metadata and

Using systematic code reuse analysis to create robust YARA rules Read More »

Malware forensics from a distance

Botconf 2023 Tuesday  | 12:30 – 18:00 Workshop Malware forensics from a distance Vitaly Kamluk 🗣 | Nicolas Collery 🗣 This workshop aims to share knowledge of live triage and analysis of remote compromised systems to assist incident response, digital forensics, or malware discovery and in-place analysis. There are many other applications of the techniques and tools

Malware forensics from a distance Read More »

Scroll to Top