Uploaded November 2017 | Updated September 2026, 2 weeks ago
Open Analysis Live! A quick tutorial on mapping output from your sandbox with disassembled code in IDA. How to quickly match API calls and locate interesting code sections!
-----
OALABS DISCORD
discord.gg/6h5Bh5AMDU
OALABS PATREON
patreon.com/oalabs
OALABS TIP JAR
ko-fi.com/oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
The sandbox run and the test binary can be found on Hybrid Analysis here:
hybrid-analysis.com/sample/0e7a10d984f62562a2152a80039b2e36fbc5d70c4b449d57a3df56324f213ecf?environmentId=100
The source code for the test binary can be found on github here:
gist.github.com/herrcore/1a39ed8701dac039c1568d62243a1924
Everyone's favorite open source sandbox:
github.com/cuckoosandbox
Our IDA Pro tips tutorial video:
youtu.be/qCQRKLaz2nQ
We are always looking for feedback, what did you like, what do you want to see more of, what do you want to see us analyze next? Let us know on twitter:
twitter.com/herrcore
twitter.com/seanmw
As always check out our tools, tutorials, and more content over at openanalysis.net
Open Analysis Live! A quick tutorial on mapping output from your sandbox with disassembled code in IDA. How to quickly match API calls and locate interesting code sections!
-----
OALABS DISCORD
discord.gg/6h5Bh5AMDU
OALABS PATREON
patreon.com/oalabs
OALABS TIP JAR
ko-fi.com/oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
The sandbox run and the test binary can be found on Hybrid Analysis here:
hybrid-analysis.com/sample/0e7a10d984f62562a2152a80039b2e36fbc5d70c4b449d57a3df56324f213ecf?environmentId=100
The source code for the test binary can be found on github here:
gist.github.com/herrcore/1a39ed8701dac039c1568d62243a1924
Everyone's favorite open source sandbox:
github.com/cuckoosandbox
Our IDA Pro tips tutorial video:
youtu.be/qCQRKLaz2nQ
We are always looking for feedback, what did you like, what do you want to see more of, what do you want to see us analyze next? Let us know on twitter:
twitter.com/herrcore
twitter.com/seanmw
As always check out our tools, tutorials, and more content over at openanalysis.net
![Why Is The PE Entry Point Not The Same As Main SEH and The _security_init_cookie [Patreon Unlocked]
In this tutorial we examine why the entry point for MSVC console applications is not the same as main. We also dive into understanding
the security_init_cookie and scrt_common_main_seh functions. Expand for more...
In this tutorial is part of our RE101 series on Patreon where we discuss basic reverse engineering concepts. The full tutorial article including links for further reading and self-study examples is here:
https://www.patreon.com/posts/why-is-pe-entry-61343353
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
OALABS PATREON
https://www.patreon.com/oalabs
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ Why Is The PE Entry Point Not The Same As Main SEH and The _security_init_cookie [Patreon Unlocked]](https://i.ytimg.com/vi/suwZB3EA_u4/mqdefault.jpg)
![What Is The Most Interesting Malware From 2022 [ Reverse Engineering AMA ]
What is the most interesting malware from 2022? What new techniques have been observed?
Big thanks to all the reverse engineers who helped us put this together!
Rattle (Jesko)
https://twitter.com/huettenhain
https://github.com/binref/refinery
Jordan (psifertex)
https://twitter.com/psifertex
https://binary.ninja/
Karsten
https://twitter.com/struppigel
https://www.youtube.com/c/MalwareAnalysisForHedgehogs
Drakonia
https://twitter.com/dr4k0nia
https://dr4k0nia.github.io/
C3rb3ru5
https://twitter.com/c3rb3ru5d3d53c
https://c3rb3ru5d3d53c.github.io/
Josh
https://twitter.com/jershmagersh
https://pwnage.io/
Dodo
https://twitter.com/dodo_sec
https://github.com/dodo-sec
Washi
https://twitter.com/washi_dev
https://washi.dev/
OALABS PATREON
https://www.patreon.com/oalabs
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
Twitch
https://www.twitch.tv/oalabslive
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ What Is The Most Interesting Malware From 2022 [ Reverse Engineering AMA ]](https://i.ytimg.com/vi/suxFVJijfbc/mqdefault.jpg)




![Are Red Team Tools Helping or Hurting Our Industry? [OALABS Call-In Show]
Our live discord call-in show debates! Are red team tools really helping our industry or are they just giving malware operators a free lunch?!
OALABS PATREON
https://www.patreon.com/oalabs
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
Twitch
https://www.twitch.tv/oalabslive
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ Are Red Team Tools Helping or Hurting Our Industry? [OALABS Call-In Show]](https://i.ytimg.com/vi/ur6csODQHKI/mqdefault.jpg)



