It seems Chinese skids are just as hilarious as Western skids when it comes to shitty malware. I've just reversed a Chinese bot:
- Download+exec is broken (URL, not dl path, passed to WinExec)
- Various pacotes functions that seem copypasted from elsewhere, one leaks ~64kb memory per thread.
- Totally broken functionality to add a privileged user thanks to misunderstanding of MultiByteToWideChar
- Requires admin privs, no UAC bypass.
@slipstream Hah, sweet. Definitely worth a look. I have used IDA in the past. Looking for good open source tools atm. But I don't do much reverse engineering tbh. Keep up the good work (: Following
Server run by the main developers of the project It is not focused on any particular niche interest - everyone is welcome as long as you follow our code of conduct!