Uploaded June 2019 | Updated September 2026, 2 weeks ago
This tutorial covers the basics needed to get started with reverse engineering C++ malware. We cover classes, constructors, structs, and a few tricks to help speed up your analysis with IDA. We have a short blog post here: oalabs.openanalysis.net/2019/06/03/reverse-engineering-c-with-ida-pro-classes-constructors-and-structs
-----
OALABS DISCORD
discord.gg/6h5Bh5AMDU
OALABS PATREON
patreon.com/oalabs
OALABS TIP JAR
ko-fi.com/oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
Automated Malware Unpacking
unpac.me
The compiled example we analyzed is available on malshare here:
malshare.com/sample.php?action=detail&hash=4bd19107be0e1fda595e009a6c787f86
You can download the freeware version of IDA here (sorry no decompiler): hex-rays.com/products/ida/support/download_freeware.shtml
If you want to try Ghidra there is an excellent online tutorial website you can check out here: https://ghidra.re/online-courses/
Ghidra download: ghidra-sre.org
Feedback, questions, and suggestions are always welcome : )
Sergei twitter.com/herrcore
Sean twitter.com/seanmw
As always check out our tools, tutorials, and more content over at openanalysis.net
#ReverseEngineering #cpp #structs #IDAPro
This tutorial covers the basics needed to get started with reverse engineering C++ malware. We cover classes, constructors, structs, and a few tricks to help speed up your analysis with IDA. We have a short blog post here: oalabs.openanalysis.net/2019/06/03/reverse-engineering-c-with-ida-pro-classes-constructors-and-structs
-----
OALABS DISCORD
discord.gg/6h5Bh5AMDU
OALABS PATREON
patreon.com/oalabs
OALABS TIP JAR
ko-fi.com/oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
Automated Malware Unpacking
unpac.me
The compiled example we analyzed is available on malshare here:
malshare.com/sample.php?action=detail&hash=4bd19107be0e1fda595e009a6c787f86
You can download the freeware version of IDA here (sorry no decompiler): hex-rays.com/products/ida/support/download_freeware.shtml
If you want to try Ghidra there is an excellent online tutorial website you can check out here: https://ghidra.re/online-courses/
Ghidra download: ghidra-sre.org
Feedback, questions, and suggestions are always welcome : )
Sergei twitter.com/herrcore
Sean twitter.com/seanmw
As always check out our tools, tutorials, and more content over at openanalysis.net
#ReverseEngineering #cpp #structs #IDAPro




![Why Is The PE Entry Point Not The Same As Main SEH and The _security_init_cookie [Patreon Unlocked]
In this tutorial we examine why the entry point for MSVC console applications is not the same as main. We also dive into understanding
the security_init_cookie and scrt_common_main_seh functions. Expand for more...
In this tutorial is part of our RE101 series on Patreon where we discuss basic reverse engineering concepts. The full tutorial article including links for further reading and self-study examples is here:
https://www.patreon.com/posts/why-is-pe-entry-61343353
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
OALABS PATREON
https://www.patreon.com/oalabs
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ Why Is The PE Entry Point Not The Same As Main SEH and The _security_init_cookie [Patreon Unlocked]](https://i.ytimg.com/vi/suwZB3EA_u4/mqdefault.jpg)
![What Is The Most Interesting Malware From 2022 [ Reverse Engineering AMA ]
What is the most interesting malware from 2022? What new techniques have been observed?
Big thanks to all the reverse engineers who helped us put this together!
Rattle (Jesko)
https://twitter.com/huettenhain
https://github.com/binref/refinery
Jordan (psifertex)
https://twitter.com/psifertex
https://binary.ninja/
Karsten
https://twitter.com/struppigel
https://www.youtube.com/c/MalwareAnalysisForHedgehogs
Drakonia
https://twitter.com/dr4k0nia
https://dr4k0nia.github.io/
C3rb3ru5
https://twitter.com/c3rb3ru5d3d53c
https://c3rb3ru5d3d53c.github.io/
Josh
https://twitter.com/jershmagersh
https://pwnage.io/
Dodo
https://twitter.com/dodo_sec
https://github.com/dodo-sec
Washi
https://twitter.com/washi_dev
https://washi.dev/
OALABS PATREON
https://www.patreon.com/oalabs
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
Twitch
https://www.twitch.tv/oalabslive
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ What Is The Most Interesting Malware From 2022 [ Reverse Engineering AMA ]](https://i.ytimg.com/vi/suxFVJijfbc/mqdefault.jpg)




![Are Red Team Tools Helping or Hurting Our Industry? [OALABS Call-In Show]
Our live discord call-in show debates! Are red team tools really helping our industry or are they just giving malware operators a free lunch?!
OALABS PATREON
https://www.patreon.com/oalabs
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
Twitch
https://www.twitch.tv/oalabslive
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ Are Red Team Tools Helping or Hurting Our Industry? [OALABS Call-In Show]](https://i.ytimg.com/vi/ur6csODQHKI/mqdefault.jpg)