bin.re » Malware
125 FOLLOWERS
This category is about Malware analysis, bitcoin, algorithms, and more. Reverse engineers/malware analysts. On the hunt for domain generation algorithms.
bin.re » Malware
7M ago
This very short post shows the Domain Generation Algorithm of BumbleBee, a loader for Cobalt Strike or other malware ..read more
bin.re » Malware
7M ago
Video that shows the DGA of the fileinfector m0yv and results of sinkholing domains for over a year ..read more
bin.re » Malware
1y ago
This unnamed XMRig malware uses a domain generation algorithm (DGA) that is seeded both by the current date, and also by the current balance of the Bitcoin genesis block ..read more
bin.re » Malware
1y ago
SharkBot uses a DGA for communication, which was changed several times during the development of SharkBot. This blogpost shows four versions of the DGA, and their differences ..read more
bin.re » Malware
1y ago
In this blog post I’ll show how remove any header, set their order, define their capitalization and how to send duplicate headers ..read more
bin.re » Malware
1y ago
This blog post shows how the open source framework “binary refinery™” can extract the download URL of complicated TA551 malspam emails ..read more
bin.re » Malware
1y ago
Domain generation algorithms are relatively straightforward to program and usually bug free. Not so the new DGA of BazarLoader, which goes haywire during the summer months ..read more
bin.re » Malware
1y ago
Bazar Loader decided to change its perfectly fine domain generation algorithm (DGA) once again. The change in the algorithm is very minor, but it yields more domain names ..read more
bin.re » Malware
1y ago
This blog post shows yet another domain generation algorithm of Bazar Loader. Although it still uses exclusively the .bazar top level domain and similar seeding, the algorithm itself is completely new ..read more
bin.re » Malware
1y ago
This blog post is about the faulty domain generation algorithm found in some BazarLoader samples. The DGA not only uses an invalid tld, it also occasionally generates invalid characters for the second level domain ..read more