Uploaded November 2017 | Updated September 2026, 1 week ago
Open Analysis Live! In this tutorial we walk through the process of locating, reverse engineering, and replicating a domain generation algorithm (DGA).
-----
OALABS DISCORD
discord.gg/6h5Bh5AMDU
OALABS PATREON
patreon.com/oalabs
OALABS TIP JAR
ko-fi.com/oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
1) DGA overview 2:26
2) Locating a DGA by tracing API calls that use a domain as an argument 12:02
3) Locating a DGA by tracing TLD string use 29:36
4) Replicating DGA in Python 33:20
Original Sample:
malwr.com/analysis/ODNmNzk3Yzc4OTc4NGEwOGIxMTk5Y2NjZDc4N2JlMjk
virustotal.com/en/file/5823bd2a5965cda23aff9962a235614329be1c8effbf752565143023c3344eeb/analysis
Stage1 Unpacked Sample:
malwr.com/analysis/ZWZkNjQyMmJkZTE2NDMwMDgxY2QwYzZmNzMxNGNkYWE
virustotal.com/en/file/304d8eca79033ef6be37038629bbdcab48f5c880f599d4aa2b6040cbc65cb6c0/analysis
Payload (Injected DLL):
malwr.com/analysis/MGI5MWJmZmIwZGE5NGM0MzljZWFmODcwOTNiODBmMjE
virustotal.com/en/file/ee608599f3e5bf714f5a440c60798580dcf272e19ef93aae73cdd9add18dcbcd/analysis
Ramnit DGA script (Python):
gist.github.com/herrcore/caa41b90ffcf1374b6b6b0c659be6607
Feedback, questions, and suggestions are always welcome : )
Sergei twitter.com/herrcore
Sean twitter.com/seanmw
As always check out our tools, tutorials, and more content over at openanalysis.net
Open Analysis Live! In this tutorial we walk through the process of locating, reverse engineering, and replicating a domain generation algorithm (DGA).
-----
OALABS DISCORD
discord.gg/6h5Bh5AMDU
OALABS PATREON
patreon.com/oalabs
OALABS TIP JAR
ko-fi.com/oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
1) DGA overview 2:26
2) Locating a DGA by tracing API calls that use a domain as an argument 12:02
3) Locating a DGA by tracing TLD string use 29:36
4) Replicating DGA in Python 33:20
Original Sample:
malwr.com/analysis/ODNmNzk3Yzc4OTc4NGEwOGIxMTk5Y2NjZDc4N2JlMjk
virustotal.com/en/file/5823bd2a5965cda23aff9962a235614329be1c8effbf752565143023c3344eeb/analysis
Stage1 Unpacked Sample:
malwr.com/analysis/ZWZkNjQyMmJkZTE2NDMwMDgxY2QwYzZmNzMxNGNkYWE
virustotal.com/en/file/304d8eca79033ef6be37038629bbdcab48f5c880f599d4aa2b6040cbc65cb6c0/analysis
Payload (Injected DLL):
malwr.com/analysis/MGI5MWJmZmIwZGE5NGM0MzljZWFmODcwOTNiODBmMjE
virustotal.com/en/file/ee608599f3e5bf714f5a440c60798580dcf272e19ef93aae73cdd9add18dcbcd/analysis
Ramnit DGA script (Python):
gist.github.com/herrcore/caa41b90ffcf1374b6b6b0c659be6607
Feedback, questions, and suggestions are always welcome : )
Sergei twitter.com/herrcore
Sean twitter.com/seanmw
As always check out our tools, tutorials, and more content over at openanalysis.net


![Understanding Pointers for Reverse Engineers - Pointer Basics in Assembly [ Patreon Unlocked ]
Full Patreon tutorial (with examples):
https://www.patreon.com/posts/understanding-1-68718093
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
OALABS PATREON
https://www.patreon.com/oalabs
Twitch
https://www.twitch.tv/oalabslive
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ Understanding Pointers for Reverse Engineers - Pointer Basics in Assembly [ Patreon Unlocked ]](https://i.ytimg.com/vi/x0eYXkIhUUY/mqdefault.jpg)




