DanielAvinoam / BlackEnergyV2-Driver-Reverse-Engineering

Driver reverse engineering of the Russian Sandworm hacking group's BlackEnergy malware.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

BlackEnergy V2 - Full Driver Reverse Engineering

Full analysis of the main driver used in the second variation of Sandworm’s BlackEnergy malware. The malware was launched against the country of Georgia during the Russo-Georgian conflict.

This repo contains every script written during the analysis, the examined driver itself, and the memory image.

You are welcome to read the analysis in English or in Hebrew.

About

Driver reverse engineering of the Russian Sandworm hacking group's BlackEnergy malware.


Languages

Language:C 58.8%Language:Python 30.9%Language:C++ 10.3%