Welcome

This Blog is for Malware Researching, Reverse Engineering and System Programming

Victory and Honour

Posted by AmrThabet on 9:23 PM



We finally win and gain our victory from these corrupted people Mubarak and Omar Seliman

We fire them ALLLLL

VICTORY FOR EGYPT .. FOR THE LAND OF HONOUR

See This Pictures (more than 100 pics about the revolution)

The Egyptian Revolution

Reversing Stuxnet's Rootkit (MRxNet) Into C++

Posted by AmrThabet on 6:53 PM
Hello Again


This is the first time I reverse a rootkit. I choose Stuxnet Rootkit (as it's a famous virus) and begin reversing..

Finally now I convert it into C++ code with a commented IDA Pro v.5.1 Database for it.

at this link

http://www.woodmann.com/collaborative/knowledge/images/Bin_Stuxnet's_Rootkit_(MRxNet)_into_C%2B%2B_2011-2-6_13.54_MRxNet.rar






have a nice day

Amr Thabet

Pokas Emulator 1.1 (Cross Platform) & PokasDbg

Posted by AmrThabet on 9:02 PM
Hi everyone. Today I want to announce a new release of Pokas x86 Emulator
This version support Reconstructing The Import Table and Support working on Linux


about Reconstructing The Import Table:
-------------------------------------
it traces GetProcAddress & LoadLibraryA and then searches for Addresses in the imagebase
and after that it creates a new Section with a new Import Table
at this link

http://www.sourceforge.com/projects/x86emu/

I want also to intreduce a new application named PokasDbg
this is a GUI interface for Pokas emulator created by wxWidgets

this is a screenshot:


To download:
http://www.sourceforge.com/projects/pokasdbg/

Win32/Virut.A Malware Analysis Paper

Posted by AmrThabet on 3:00 PM
Hi again

This time I write my first malware analysis paper with the dumped source full commented .I also add a Detection and Disinfection utility that capable of detecting the infected file with Virut.A containing the signature of the virus

The link to it is here :

Virut.A.rar

CodeProject: "Write your own Unpacker"

Posted by AmrThabet on 1:31 PM
Hi everyone

some people ask me why you write only about your works in the blog and I reply that this blog is named AmrThabet so it doesn't talk about anything except me :)

maybe I'll create another blog with another name to post everything related to viruses
OK

That's the first time I join CodeProject. I love this website very much and its articles and that's the first time I join it's community

I write a practical tutorial about my emulator (Pokas x86 Emulator) to help it spread widely name "Write your own Unpacker"

at this link:
http://www.codeproject.com/KB/DLL/ownunpacker.aspx

have fun

Google Knol: "The Secrets of Viruses and Antiviruses"

Posted by AmrThabet on 1:13 PM
in 27/5/2009 I decided to join Google Arabic Knol to support Arabic articles so I wrote "The Secrets of Viruses and Antiviruses"
They said that I should not talk technically and should everyonle could understand what I'm saying.

it's the first time I write an Article in the formal shape and the first article in Arabic so it makes many problem for me. it's at this link
http://knol.google.com/k/أسرار-فيروسات-الكومبيوتر-ومضاداتها#

it took rate 5/5 and the took the highest quality prize

If you can read Arabic I hope you enjoy it

EgitMagazine Talked about me in Cairo Security Camp 2010

Posted by AmrThabet on 4:55 PM
Hi again

Here EgitMagazine talked about Cairo Secuirty Camp 2010 and talk about me in this event

see the link here :
http://www.egitmagazine.com/2010/07/28/bluekaizens-cairo-security-camp-when-egypts-it-tsecurity-experts-meet-at-one-place/