
Nikhil Hegde
@ka1do9
Followers
352
Following
556
Media
16
Statuses
187
Opinions are my own and not of my employer
India
Joined January 2020
Blog post alert!. This one is about developing tooling to deobfuscate JavaScript malware using Abstract Syntax Trees (ASTs). #windows #malware #javascript #llm.
1
0
4
Turla backdoor tries to bypass ETW, EventLog and AMSI by disabling PSEtwLogProvider and patching specific functions. But some of its patching is buggy. This blog describes the bypass techniques and why some of the function patches are faulty.
nikhilh-20.github.io
M&M: Malware and Musings
0
0
5
This blog is about PE process injection as implemented in BugSleep backdoor loader. This is an old technique, but I go over why the implementation in the loader is buggy and easily blocked by EDRs.
nikhilh-20.github.io
M&M: Malware and Musings
0
24
74
RT @Shreylocks: माननीय पोलीस,. एकवेळ त्या वेदांत अगरवाल ला शिक्षा नाही झाली तरी चालेल🙏🏽. पण त्या गरीब निर्दोष बिचाऱ्या ड्रायव्हर ला फसवू न….
0
26
0
RT @Ax_Sharma: A GitHub flaw lets attackers upload executables that appear to be hosted on a company's official repo, such as Microsoft's—w….
0
1K
0
Blog post!. In this one, I take a MIPS little-endian sample: NoaBot botnet, submit it to the ELFEN sandbox and get solid insights within 3m. This is where ELFEN shines - no need to reverse MIPS disassembly to know more about the sample!. #malware #sandbox.
nikhilh-20.github.io
M&M: Malware and Musings
1
1
3
Blog post alert! In this one - I take an INC Linux ransomware sample (targets ESXi), submit it to the ELFEN sandbox and get solid insights within 2m. For completeness, I also dive into IDA's decompilation and describe the encryption mechanism. #malware.
nikhilh-20.github.io
M&M: Malware and Musings
0
1
3
RT @TBIJ: How did London become “the libel capital of the world”?. Our latest investigation looks into Carter-Ruck – Britain’s scariest law….
thebureauinvestigates.com
The government is trying to rein in firms like Carter-Ruck. It’s not easy
0
70
0