In this Twitch stream we continue our analysis of the WMI spreader component of the Hermetic Wizard malware used in the recent cyber attacks on Ukraine. In this stream we focus on the COM component that is used to interface with WMI.
Sample: a259e9b0acf375a8bef8dbc27a8a1996ee02a56889cba07ef58c49185ab033ec
Research Notes: Hermetic Wizard Malware
For more information on COM reverse engineering check out Mike Bailey's COM Presentation. He also has a nice (free) video on Pluralsight.
m4n0w4r
2023-07-03 02:25:39 +0000 UTCm4n0w4r
2023-06-30 14:51:57 +0000 UTC