logo

It’s getting hot in here

ID: 15c7a43b-87e1-5e6e-b35c-092ae59757cf

STIX ID: report--15c7a43b-87e1-5e6e-b35c-092ae59757cf

Feed Name: Plausible Deniablility

Threat Score
30/100

Date Published: 2022-08-28

Date Updated: 2026-08-11

Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}

...
...

This write-up describes a CTF reverse-engineering exercise where the author statically analyzed a small Windows malware sample using Ghidra. The analysis identifies code that enumerates InMemoryOrderModuleList to find ntdll, resolves syscall stubs (Hell's Gate technique) to bypass EDR hooks, XOR-decrypts strings and a payload, and extracts the embedded shellcode which yields the challenge flag.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.