Remove blogs author james-quinn
article thumbnail

The odd case of a Gh0stRAT variant

AlienVault

As 2018 drew to a close and 2019 took over, I began to see a different behavior from SMB malware authors. In addition to a standard malware analysis blog post, I’d also like to take this time to document and describe my methods for analysis, in the hopes that you as a reader will use these techniques in the future. dwm_dropped.

SMB 40