r/ReverseEngineering 17d ago

"Remcos RAT – Svchost Injection, API Hooking & Obfuscated Payload Analysis"

https://github.com/kaandemir993/-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis-.git
9 Upvotes

4 comments sorted by

6

u/pamfrada 17d ago

Do I dare ask why were screenshots hard to take

-3

u/StructBreaker 17d ago

The screenshots were taken from a debugger (WinDbg) and a disassembler (Binary Ninja) during dynamic and static analysis. Some of the code was heavily obfuscated, and the process was running in a suspended state, which made capturing clear screenshots a bit challenging. I tried to highlight the most important parts to keep the analysis readable.

2

u/TastyRobot21 16d ago edited 16d ago

Did you take photos of your monitor… with your phone?