hasherezade Profile Banner
hasherezade Profile
hasherezade

@hasherezade

Followers
84,239
Following
845
Media
1,182
Statuses
23,339

Programmer, #malware analyst. Author of #PEbear , #PEsieve , #TinyTracer . Private account. All opinions expressed here are mine only (not of my employer etc)

Poland
Joined July 2013
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@hasherezade
hasherezade
2 years
- where do you see yourself in 30+ years? me:
Tweet media one
403
14K
97K
@hasherezade
hasherezade
2 years
Surprise! #PEbear is Open Source now! - please check it out and let me know what do you think!
Tweet media one
44
698
2K
@hasherezade
hasherezade
30 days
BTW, I am not saying that this is what happened in the #xz backdoor case, but what does not help is, github makes it quite trivial to spoof user accounts... I was just able to make a commit as this person, in my own repository:
Tweet media one
103
171
2K
@hasherezade
hasherezade
2 years
To whomever it concerns: I am NOT in any ways affiliated with Azov (or any other #ransomware ). It’s a common practice among cyber criminals to try to frame security researchers.
Tweet media one
70
282
2K
@hasherezade
hasherezade
9 months
If you ever need to convert an EXE into a DLL: // #exe_to_dll
Tweet media one
15
417
1K
@hasherezade
hasherezade
4 years
email: "I got ransomware" Gmail suggested response: "I'm so proud of you!" 😆
Tweet media one
27
199
1K
@hasherezade
hasherezade
2 years
The more I know people, the more I love machines.
50
101
868
@hasherezade
hasherezade
4 years
age++ I am glad I made it till 32. not (just) because of the current pandemic, but because in general no day of life is given for granted. feeling grateful for all I’ve got and seen so far, the good and the bad. life’s beautiful.
Tweet media one
104
10
810
@hasherezade
hasherezade
3 years
If anyone interested, I made an implementation of #TransactedHollowing - the PE injection technieque used by the #Osiris loader:
Tweet media one
13
257
743
@hasherezade
hasherezade
2 years
Process Overwriting - yet another variant of #ProcessHollowing :
Tweet media one
9
250
720
@hasherezade
hasherezade
2 years
New release: #PEbear 0.5.5:
Tweet media one
4
173
709
@hasherezade
hasherezade
2 years
Happy New Year from Warsaw!
16
29
686
@hasherezade
hasherezade
1 year
New release: #PEbear 0.6.5: - several new features, fixes and improvements - check it out!
Tweet media one
18
167
670
@hasherezade
hasherezade
6 months
New #PEsieve / #HollowsHunter (v0.3.8) is out: & - including features discussed in the following video:
Tweet media one
@hasherezade
hasherezade
10 months
Sneak preview of the upcoming #PEsieve / #HollowsHunter : -detecting obfuscated beacons. You can get a test version from the AppVeyor build server. Feedback welcome 😊
5
127
365
12
210
645
@hasherezade
hasherezade
6 years
there is a stereotype that Christmas with family = memorable, while Christmas alone = miserable. but in real life it may be quite opposite. in whatever situation you are - be good to yourself, and don't treat this whole thing too serious.
17
143
616
@hasherezade
hasherezade
28 days
Due to the fact that I am gonna be more and more busy with my family life, I am looking for a person who would like to become a successor of my open source projects. You need to know C/C++, and be very committed. Please share your offers!
52
84
623
@hasherezade
hasherezade
4 years
Finally our paper about the "Silent Night" #Zloader / #Zbot is out! - by me (analysis) and @prsecurity_ (intelligence): - via @Malwarebytes
21
264
613
@hasherezade
hasherezade
4 years
When I read my code from many years ago, I not only remember the code, but often also get a full-blown flashback from the moment of writing it: random memories of the whole surroundings, with sounds, smells, emotions, etc. Anyone else can relate?
81
38
603
@hasherezade
hasherezade
5 years
Idea for a new Netflix series: like “Narcos”, but about malware authors
40
106
603
@hasherezade
hasherezade
8 years
Master Boot Record visualized in @angealbertini 's style - by Jared Atkinson
Tweet media one
3
376
562
@hasherezade
hasherezade
6 years
if you are planning to invite me to speak at your conference just because I am a woman, better punch me on the face instead
32
63
554
@hasherezade
hasherezade
5 years
"procrastination-based project" - a project that you start doing in order to procrastinate doing another project 😉
Tweet media one
10
97
526
@hasherezade
hasherezade
5 years
Slides from my talk " #PEsieve an open source scanner for hunting and unpacking malware" #BlueHatIL
11
225
523
@hasherezade
hasherezade
1 year
New release: #TinyTracer v2.3 : - with improved syscalls tracing support - now syscalls are automatically mapped to corresponding functions names
Tweet media one
7
168
520
@hasherezade
hasherezade
6 years
If you follow your dreams and work hard enough, one day you will prove your worth to all the doubters. But on the way you may find out that their approval is the least important thing in your life.
13
115
503
@hasherezade
hasherezade
2 years
From non IT-related things, this year I started to learn drawing. This is my current status (may delete later)
Tweet media one
Tweet media two
35
5
508
@hasherezade
hasherezade
4 months
Happy New Year! I have for you a new #PEbear (v0.6.7) with some of the requested features, such as strings, and patterns searching. Plus other improvements & bugfixes. Check it out! 🐻💙
Tweet media one
Tweet media two
Tweet media three
10
149
503
@hasherezade
hasherezade
4 years
How it started: How it’s going:
Tweet media one
Tweet media two
5
52
493
@hasherezade
hasherezade
5 months
I know some people use #PEbear to unmap PEs dumped from memory. Since upcoming releases you will be able to do it just by one click:
13
124
502
@hasherezade
hasherezade
6 years
If anyone wants to play with the good old #Stuxnet , I uploaded a bundle of its components to @virusbay_io :
9
181
490
@hasherezade
hasherezade
2 years
My new paper for @MBThreatIntel : " #JSSLoader - the #shellcode edition" : // #FIN7
Tweet media one
18
186
490
@hasherezade
hasherezade
4 years
debugging in production 😅
10
145
478
@hasherezade
hasherezade
4 years
felt cute, might delete later 😉
Tweet media one
23
5
465
@hasherezade
hasherezade
3 years
age++ what a strange year... sometimes it feels like a month, sometimes like 10 years has passed...
Tweet media one
77
3
470
@hasherezade
hasherezade
8 years
Victims of !XPTLOCK5.0 - please do not pay the ransom! I've got the key, help coming soon (at least for some of you) // #ransomware
Tweet media one
8
574
462
@hasherezade
hasherezade
4 years
New release: #PEbear 0.5.0 - refactored to Qt5 (yes, finally!) 🐻💙
Tweet media one
13
158
468
@hasherezade
hasherezade
2 years
My new screwdrivers set is the prettiest I ever had 😍
Tweet media one
Tweet media two
23
14
465
@hasherezade
hasherezade
6 years
Sometimes malware authors create their own executable format - it's really fun to reverse the full structure (sample: )
Tweet media one
Tweet media two
7
171
444
@hasherezade
hasherezade
6 years
My new post for @Malwarebytes "Reversing malware in a custom format: #HiddenBee elements" :
3
243
444
@hasherezade
hasherezade
2 years
* artwork by Tristan Elwell
9
18
441
@hasherezade
hasherezade
7 years
My small tool for converting #PE files dumped from the memory into their raw form:
Tweet media one
8
274
433
@hasherezade
hasherezade
4 years
It was the beginning of 2000 when I decided that I will learn programming. I was 11-12 at the time. Had absolutely no resources, and no idea where to begin, but I didn’t give up. So, in 2020 I will be celebrating 20th anniversary of being in this amazing field.
16
25
433
@hasherezade
hasherezade
2 years
New #PEsieve / #HollowsHunter (v0.3.4): & - with threads' callstack scan. Check it out!
Tweet media one
4
146
430
@hasherezade
hasherezade
6 years
I woke up to this news and still not sure if I am not dreaming: - thank you @Forbes , I feel so much honored! and congratulations to @Fox0x01 and @StackSmashing
65
45
427
@hasherezade
hasherezade
3 years
#MalwareTipsAndTricks : did you know this (lower level) way of enumerating processes? snippet: [1/3]
Tweet media one
12
137
428
@hasherezade
hasherezade
2 months
New #PEsieve / #HollowsHunter (v0.3.9): & - now you can search for your own signatures in memory. Details: . Check it out!
Tweet media one
8
166
436
@hasherezade
hasherezade
7 years
Interesting trick to make a persistence key unnoticed by autoruns:
Tweet media one
7
292
429
@hasherezade
hasherezade
4 years
I am near to finish the longest & most detailed malware analysis writeup I ever written... coming soon! I hope you will like it 😊
13
24
427
@hasherezade
hasherezade
8 months
Did you miss my bedtime stories? 😉 Because some new stuff is coming... I am happy to announce that now I am a part of @_CPResearch_ !
@_CPResearch_
Check Point Research
8 months
Let's explore the link between #Rhadamanthys stealer and #HiddenBee coin miner! In our latest blog, @hasherezade walks you through the custom executable formats, evolution, and features of this interesting, multilayer malware toolkit.
5
80
180
60
29
415
@hasherezade
hasherezade
8 years
I started making a small compendium of injection techniques commonly used in #malware :
5
232
396
@hasherezade
hasherezade
2 years
My dog (RIP), painted by my boyfriend: //may delete later
Tweet media one
25
2
405
@hasherezade
hasherezade
3 years
I wanted to play with this technique, and there was no PoC provided, so I made my own. If anyone needs, it is here: // #ProcessGhosting
@dez_
Joe Desimone
3 years
‼️ Process Ghosting: a new process tampering technique for AV evasion. Nice write-up by @GabrielLandau
6
141
339
2
143
392
@hasherezade
hasherezade
3 years
New #PEbear is out! with dark mode, and other improvements:
Tweet media one
Tweet media two
8
98
389
@hasherezade
hasherezade
1 year
I made a writeup on #Magniber #ransomware (from 2022) demonstrating the capabilities of the latest #TinyTracer :
Tweet media one
15
122
388
@hasherezade
hasherezade
2 years
New release: #mal_unpack (0.9.4): + the (experimental) companion driver (0.1.1.17): - check it out & share your opinions!
Tweet media one
10
126
379
@hasherezade
hasherezade
5 years
New releases: #PEsieve 0.1.5 () & #HollowsHunter 0.1.8 ()
Tweet media one
8
157
377
@hasherezade
hasherezade
3 years
Did you know this #antidebug technique? (detecting if kernel mode debugging is enabled) - implementation:
Tweet media one
7
100
372
@hasherezade
hasherezade
3 years
a simple but nice trick for obfuscating the execution flow: can you spot what happens there? // #NSISpacker
Tweet media one
11
73
365
@hasherezade
hasherezade
10 months
Sneak preview of the upcoming #PEsieve / #HollowsHunter : -detecting obfuscated beacons. You can get a test version from the AppVeyor build server. Feedback welcome 😊
5
127
365
@hasherezade
hasherezade
2 years
New #PEsieve / #HollowsHunter (v0.3.3) - with new features and many improvements - check it out: &
Tweet media one
11
106
359
@hasherezade
hasherezade
2 years
Recently I started working on a driver for mal_unpack ( a tool from #PEsieve family) - if anyone curious, I open-sourced the code: - please share what do you think
3
129
363
@hasherezade
hasherezade
2 years
New #mal_unpack (0.9): - with the (experimental) companion driver: - is ready! Check it out & share your opinions!
Tweet media one
6
146
353
@hasherezade
hasherezade
6 months
#MalUnpack with the latest #PEsieve (0.3.8) is ready: // #malwareUnpacking
Tweet media one
3
89
348
@hasherezade
hasherezade
7 years
The slides from my presentation "Wicked #malware persistence methods":
9
223
346
@hasherezade
hasherezade
7 years
Do you know this trick for checking OS architecture? I found it in #Kronos and looks pretty neat:
Tweet media one
15
156
334
@hasherezade
hasherezade
3 years
New releases: #PEsieve () & #HollowsHunter ( ) - v0.2.9.8
Tweet media one
Tweet media two
3
115
331
@hasherezade
hasherezade
2 years
I crossed 10000 Github contributions 👀... I guess I can call it some milestone 😉
Tweet media one
11
9
337
@hasherezade
hasherezade
6 years
Malwarebytes #CrackMe 2 is live!
7
156
334
@hasherezade
hasherezade
5 months
Finally got it! They get prettier and prettier every year, thanks @Mandiant ! #flareon9
Tweet media one
Tweet media two
17
3
336
@hasherezade
hasherezade
2 years
lol, hello #SaintBot ...
Tweet media one
4
20
330
@hasherezade
hasherezade
5 years
I started making a small wiki for #PEsieve :
8
115
324
@hasherezade
hasherezade
6 months
To whoever needs to hear it: putting other people down may give you some delusion of superiority, but it won’t make you any ahead in life. In fact, you are sabotaging yourself the most.
Tweet media one
12
46
323
@hasherezade
hasherezade
6 years
My new small utility: PE to shellcode converter: - for now it is experimental, available for testing (32 bit only)
5
159
317
@hasherezade
hasherezade
7 years
Nice set of video tutorials - DLL injection, simple keyloggers and more: (C/C++)
0
147
316
@hasherezade
hasherezade
6 years
"Practical #Malware Analysis" - a course by Sam Bowne ( @sambowne ):
3
146
311
@hasherezade
hasherezade
4 years
In this paper I share some ideas on how to generate a shellcode in assembly from your C code
3
98
315
@hasherezade
hasherezade
3 years
New release: #pe_to_shellcode ( #pe2shc ) - added DCP support: now the generated shellcode can be injected into a processes with DCP ( "Dynamic Code Prohibited" ) enabled
Tweet media one
2
116
309
@hasherezade
hasherezade
7 months
no-shower week has begun😅 #flareon10
Tweet media one
12
27
304
@hasherezade
hasherezade
3 years
New #PEbear - with improvements and... a legacy version:
Tweet media one
4
67
304
@hasherezade
hasherezade
6 years
Slides from my talk presented today at @WarConPL - "Building a Malwarestein. Adapting and repurposing existing malware into new projects":
4
156
304