Analysis
Malware Families
- https://malpedia.caad.fkie.fraunhofer.de/families
AlphaBlend Campaign
- https://steemit.com/reverse/@utkonos/alphablend-malware
- https://steemit.com/reverseengineering/@utkonos/alphablend-campaign-part-2
- https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/-address
- https://docs.microsoft.com/en-us/windows/desktop/sbscs/activation-contexts
azorult
- https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update
MuddyWater
- https://www.sdkhere.com/2019/01/a-new-muddywater-apt-campaign-spreads.html
Hyperion
i586-mingw32-msvc-g++ Src/Crypter/*.cpp -o hyperion.exe
wine hyperion.exe backdoor.exe out.exe