Windows 10 is ‘mine’…, Part 1

May 5, 2020 in Malware Analysis, Reversing, Tips & Tricks, Uncategorized

I don’t like Windows 10, but it likes… the progress… So… now that win7 is ded, and winxp doesn’t work that well for malware analysis (and it’s 32-bit only), I […]

SettingSyncHost.exe as a LolBin

February 2, 2020 in Living off the land, LOLBins, Uncategorized

This native OS binary has two interesting options: -LoadAndRunDiagScript <name> -LoadAndRunDiagScriptNoCab <name> When executed with these options, it will extract the .bat file stored inside its resources, save it as […]