sysfatal.github.io

Logo

sysfatal(blog)

27 January 2022

Gopper, keep a close eye on this proc!

by e__soriano


Gopper

I have written a mini tool named Gopper (gopher copper :)) in Go. It implements the procedure explained above. In addition, it also detects the following suspicious actions:

Gopper can be used together with Frida-trace or any other analysis tool. It does not interfere with the watched process.

Gopper git:

https://gitlab.etsit.urjc.es/esoriano/gopper

Comments

You can comment this post in twitter

(cc) Enrique Soriano-Salvador Algunos derechos reservados. Este trabajo se entrega bajo la licencia Creative Commons Reconocimiento - NoComercial - SinObraDerivada (by-nc-nd). Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

tags: reversing - evasion - malware