Reverse Engineering Tutorial Explores Hybrid Analysis of Linux x86-64 Crackme Using Ghidra and GDB
A comprehensive tutorial series introduces readers to hybrid reverse engineering of a Linux crackme titled Getting started keygen authored by Mazzotti. The binary presents itself as an introductory challenge yet contains realistic C++ constructs including optimized stack frames, mangled names, and opaque data structures.
The first article begins with basic triage using the file command, revealing a 64-bit PIE ELF dynamically linked against libc and libstdc++. Strings extraction surfaces user prompts such as "Enter a string of characters (no spaces)" and responses including "Bro, what are you trying to do?" and "OMG! You did it! :3".
Static analysis proceeds in Ghidra, where the analyst locates the true entry point at address 0x1340, demangles C++ symbols, and identifies imported std::string operations. The tutorial contrasts non-optimized and optimized (-O1) compilation outputs to explain why the frame pointer is omitted and why Ghidra initially mislabels stack variables such as local_58 and local_7c.
Dynamic validation occurs inside GDB with careful calculation of ASLR-adjusted addresses. Breakpoints placed before and after input allow verification of stack layout, growth and shrinkage behavior, and the actual four-byte size of certain locals that the decompiler had sized incorrectly.
The series stresses iterative refinement: decompiler output supplies hypotheses, the debugger confirms or refutes them, and corrected information is returned to Ghidra to improve type recovery. Subsequent installments will apply mutation testing and reconstruct the hidden validation algorithm in Python.
Related articles
How Malware Evades Sandboxes: Detection Techniques and Defense Strategies
Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.
Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers
Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.
Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware
Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.
SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points
Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.