jm33_ng
  • Malware
  • Misc
  • Programming
  • R&d
  • Tools
  • Vulnerabilities
  • RSS

jm33_ng


cyber security / noob developer / poor English

Some Notes on Call Stack Spoofing

Date Fri 21 August 2026 Tags windows / malware / stack spoofing / silentmoonwalk / emp3r0r / c2 / EDR

spoofed call stack

The Basics

Forgive me if this post sounds too basic or detailed. My tutor job gave me this style. Hopefully it helps beginners.

The screenshots are taken from different runs as I didn't have the time to finish writing in one go. If you see different addresses, that's why.

What …

View comments.

more ...

Analysing an Unexciting Commodity Malware

Date Sun 19 July 2026 Tags windows / malware / libcurl / scamware

769242464da960eff6d520fc09fb6b7d.png

This report was written for a job interview (spoiler alert: I didn't get it) and has been sitting in my notes for half a year. windows-sandbox-init was used to create this report.

Executive Summary

I confirmed the file is malicious. It functions as a downloader designed to fetch and execute …

View comments.

more ...

  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • »

About jm33

Who

  • Resume

Contact

  • Email

  • Mastodon

  • Leave a message

  • Social

    • Twitter
    • GitHub
    • LinkedIn
  • Recent Posts

    • Some Notes on Call Stack Spoofing
    • Analysing an Unexciting Commodity Malware
    • Writing a Linux BOF Loader from Scratch
    • sRDI for Linux: Stealthy In-Memory ELF Loading
    • Reversing a Nim-based APT Sample with Ghidra and x64dbg
  • Tags

    • 404
    • 443
    • active directory
    • ad
    • aes
    • announcement
    • antivirus
    • anyconnect
    • apache
    • arch
    • assembly
    • asu
    • backdoor
    • baidu
    • blackhat
    • bof
    • bridge
    • C#
    • c2
    • censorship
    • cgo
    • cisco
    • cobalt strike
    • code maintainance
    • compton
    • conhost
    • conpty
    • Coursera
    • credential harvesting
    • crypto
    • cryptography
    • CVE
    • CVE-2018-18955
    • CVE-2018-7750
    • deflate
    • Diary
    • DNS污染
    • DPI
    • EDR
    • elf
    • email
    • emp3r0r
    • exploit
    • file transfer
    • gdb
    • gfw
    • ghidra
    • github
    • Glowing Bear
    • golang
    • gpu
    • great wall
    • greatwall
    • hacking
    • hacking tool
    • HiWiFi
    • HTTP2
    • https
    • in-memory
    • injection
    • IRC
    • 极路由
    • KCP
    • kcptun
    • kernel
    • killer
    • lede
    • libcurl
    • libvirt
    • linux
    • linux-bof
    • linux kernel
    • lkm
    • loader
    • log cleaner
    • LPE
    • macos
    • malware
    • mass exploit
    • mec
    • mentohust
    • Misc
    • mmap
    • mouse
    • multi-threaded crawler
    • namespace
    • natural scroll
    • netcat
    • network
    • nic
    • nim
    • obfs4
    • obfsproxy
    • ocserv
    • openwrt
    • paramiko
    • pentest
    • pep8
    • PGP
    • pi
    • port-forwarding
    • post-exploitation
    • privilege escalation
    • programming
    • project
    • proxy
    • ptrace
    • PTRACE_TRACEME
    • python
    • pythonic
    • qemu
    • QQ
    • RCE
    • redteam
    • reflective loading
    • reverse shell
    • reversing
    • rootkit
    • s2-045
    • scamware
    • scanner
    • scramblesuit
    • secure boot
    • shadowsocks
    • shadowsocks-plus
    • shell
    • shellcode
    • silentmoonwalk
    • socket
    • srdi
    • SS
    • ssh
    • ssh-harvester
    • sshd
    • SSL
    • stack spoofing
    • Stanford
    • sudo
    • switch
    • syscall
    • systemd
    • terminal
    • TMUX
    • tools
    • trasparent proxy
    • vim
    • virtualbox
    • virtualization
    • vpn
    • wayland
    • web
    • weechat
    • windows
    • windows domain
    • windows server
    • x64dbg
    • xfce4
    • xfwm
    • xhost
    • xml
    • zoomeye

© 2026 jm33-ng - About this site

Creative Commons License Content licensed under a Creative Commons Attribution-NonCommercial 4.0 International License, except where indicated otherwise.

Images hosted on this site are either my own or from the Internet