Marius Benthin

16 Followers
61 Following
6 Posts
Senior Detection Engineer at Nextron Systems
Websitehttps://marius-benthin.de
GitHubhttps://github.com/marius-benthin
Published a new analysis of a kernel land rootkit loader for FK_Undead
https://www.gdatasoftware.com/blog/2024/12/38091-analysis-fk-undead #Rootkit #FK_Undead
A Kernel Land Rootkit Loader for FK_Undead

We discovered a Windows rootkit loader [F1] for the malware family FK_Undead. The malware family is known for intercepting user network traffic through manipulation of proxy configurations. To the best of our knowledge the rootkit loader hasn't been officially analyzed before.

Karsten Hahn and I took a closer look at the latest #BBTok .NET loaders. In my first article on the #GDATATechblog we describe how to deobfuscate Trammy.dll and share new details about the BBTok infection chain.

https://www.gdatasoftware.com/blog/2024/09/38039-bbtok-deobfuscating-net-loader

@struppigel #GDATA

BBTok Targeting Brazil: Deobfuscating the .NET Loader with dnlib and PowerShell

A complex infection chain and a targeted approach make BBTok a very challenging piece of malware to examine. Analysts Marius Benthin and Karsten Hahn were able to examine a critical part of the infection chain and describe its inner workings in this latest article.

It was a pleasure to present our project on how to use GPT to detect phishing websites together with Eduard Alles at #AVAR2023 in Dubai.

Finally it is there: A GUI version of PortexAnalyzer🔎

PortexAnalyzer is a free PE parser tailored for malware analysis. It uses the library PortEx.

🔽Download: https://github.com/struppigel/PortexAnalyzerGUI/releases
#PortEx #PortexAnalyzer

Releases · struppigel/PortexAnalyzerGUI

Graphical interface for PortEx, a Portable Executable and Malware Analysis Library - struppigel/PortexAnalyzerGUI

GitHub
I am excited to join G DATA's Malware Analysis team as a Junior Virus Analyst. Looking forward to the new challenges in the fight against cyber threats.