Uploaded December 2022 | Updated September 2026, 2 weeks ago
What are some tips for dealing with static config extraction of .NET malware?
--
Big thanks to all the reverse engineers who helped us put this together!
Rattle (Jesko)
twitter.com/huettenhain
github.com/binref/refinery
Jordan (psifertex)
twitter.com/psifertex
https://binary.ninja/
Karsten
twitter.com/struppigel
youtube.com/c/MalwareAnalysisForHedgehogs
Drakonia
twitter.com/dr4k0nia
dr4k0nia.github.io
C3rb3ru5
twitter.com/c3rb3ru5d3d53c
c3rb3ru5d3d53c.github.io
Josh
twitter.com/jershmagersh
pwnage.io
Dodo
twitter.com/dodo_sec
github.com/dodo-sec
Washi
twitter.com/washi_dev
https://washi.dev/
-----
OALABS PATREON
patreon.com/oalabs
OALABS DISCORD
discord.gg/6h5Bh5AMDU
Twitch
twitch.tv/oalabslive
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----
What are some tips for dealing with static config extraction of .NET malware?
--
Big thanks to all the reverse engineers who helped us put this together!
Rattle (Jesko)
twitter.com/huettenhain
github.com/binref/refinery
Jordan (psifertex)
twitter.com/psifertex
https://binary.ninja/
Karsten
twitter.com/struppigel
youtube.com/c/MalwareAnalysisForHedgehogs
Drakonia
twitter.com/dr4k0nia
dr4k0nia.github.io
C3rb3ru5
twitter.com/c3rb3ru5d3d53c
c3rb3ru5d3d53c.github.io
Josh
twitter.com/jershmagersh
pwnage.io
Dodo
twitter.com/dodo_sec
github.com/dodo-sec
Washi
twitter.com/washi_dev
https://washi.dev/
-----
OALABS PATREON
patreon.com/oalabs
OALABS DISCORD
discord.gg/6h5Bh5AMDU
Twitch
twitch.tv/oalabslive
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
unpac.me/#
-----





![Why Is The PE Entry Point Not The Same As Main SEH and The _security_init_cookie [Patreon Unlocked]
In this tutorial we examine why the entry point for MSVC console applications is not the same as main. We also dive into understanding
the security_init_cookie and scrt_common_main_seh functions. Expand for more...
In this tutorial is part of our RE101 series on Patreon where we discuss basic reverse engineering concepts. The full tutorial article including links for further reading and self-study examples is here:
https://www.patreon.com/posts/why-is-pe-entry-61343353
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
OALABS PATREON
https://www.patreon.com/oalabs
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ Why Is The PE Entry Point Not The Same As Main SEH and The _security_init_cookie [Patreon Unlocked]](https://i.ytimg.com/vi/suwZB3EA_u4/mqdefault.jpg)
![What Is The Most Interesting Malware From 2022 [ Reverse Engineering AMA ]
What is the most interesting malware from 2022? What new techniques have been observed?
Big thanks to all the reverse engineers who helped us put this together!
Rattle (Jesko)
https://twitter.com/huettenhain
https://github.com/binref/refinery
Jordan (psifertex)
https://twitter.com/psifertex
https://binary.ninja/
Karsten
https://twitter.com/struppigel
https://www.youtube.com/c/MalwareAnalysisForHedgehogs
Drakonia
https://twitter.com/dr4k0nia
https://dr4k0nia.github.io/
C3rb3ru5
https://twitter.com/c3rb3ru5d3d53c
https://c3rb3ru5d3d53c.github.io/
Josh
https://twitter.com/jershmagersh
https://pwnage.io/
Dodo
https://twitter.com/dodo_sec
https://github.com/dodo-sec
Washi
https://twitter.com/washi_dev
https://washi.dev/
OALABS PATREON
https://www.patreon.com/oalabs
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU
Twitch
https://www.twitch.tv/oalabslive
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/ What Is The Most Interesting Malware From 2022 [ Reverse Engineering AMA ]](https://i.ytimg.com/vi/suxFVJijfbc/mqdefault.jpg)



