It’s getting hot in here
ID: 15c7a43b-87e1-5e6e-b35c-092ae59757cf
STIX ID: report--15c7a43b-87e1-5e6e-b35c-092ae59757cf
Feed Name: Plausible Deniablility
Date Published: 2022-08-28
Date Updated: 2026-08-11
Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}
This write-up describes a CTF reverse-engineering exercise where the author statically analyzed a small Windows malware sample using Ghidra. The analysis identifies code that enumerates InMemoryOrderModuleList to find ntdll, resolves syscall stubs (Hell's Gate technique) to bypass EDR hooks, XOR-decrypts strings and a payload, and extracts the embedded shellcode which yields the challenge flag.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
