Walkthroughs¶
Each walkthrough takes one real sample and answers one question with PPEE, step by step, without running anything. They start with an At a glance box like this one:
At a glance
- Sample
- the file, with its SHA-256 or name
- Question
- what you want to know
- You'll use
- the PPEE features involved, linked to their reference pages
and the full case studies end with a Verdict. Screenshots are from the Windows GUI; every step that has a CLI equivalent shows it.
Case studies¶
End-to-end investigations, one page each.
-
A NativeAOT ransomware that forgot its key
C# compiled to native code, invisible to .NET tools. Recover its method names, its shadow-copy and recovery commands, and a ransom note that admits there is no key.
NativeAOT · Strings · Manifest · Debug
-
A DLL that is only a payload container
Exports that are data, a 3.7 MB encrypted blob and masked keys. Follow
DllMainas it decodes, drops, loads and deletes the next stage, then decode that stage yourself.Navigator · Exports · Code window ·
--decode -
A validly signed dropper carrying a stealer
SIGNED & VERIFIEDwith an EV certificate. What the signature does and doesn't tell you, and where the program it runs hides.Authenticode · Exports · Overlay
-
From a URL to its call site
A shellcode loader whose import table looks ordinary. Find the APIs it resolves at run time, the C2 URL, and the one instruction that uses it.
Code analysis · Strings · References · Debug
Short walkthroughs, by question¶
Shorter walkthroughs live on the reference page of the feature they use. They have the same At a glance box.
Is it packed or protected?¶
| Walkthrough | Sample | Interface |
|---|---|---|
| Find the original entry point of a UPX-packed dropper | 77549422….exe | GUI + CLI |
The same, with --disasm only | 77549422….exe | CLI |
| A hooked function in a protected crackme | crackme-Section_name.exe | CLI |
| A 64-bit file with no unwind data | M-Dl-exeption-tls.exe | CLI |
| Are these TLS callbacks a trick? | ef431e36….dll | GUI + CLI |
| An obfuscated .NET crackme, and the deep pass | crackme | GUI + CLI |
What does it steal, and how does it send it?¶
| Walkthrough | Sample | Interface |
|---|---|---|
| Triage a stealer in four clicks | STEALERDLL.dll | GUI |
| A browser-credential stealer, judged from its code | STEALERDLL.dll | CLI |
| A credential stealer's import profile | STEALERDLL.dll | CLI |
| What a stealer resolves at run time | STEALERDLL.dll | CLI |
| A Rust infostealer, read from its panic paths | 42c6a158….exe | GUI + CLI |
What does it drop, download or unpack?¶
| Walkthrough | Sample | Interface |
|---|---|---|
| A shellcode loader: the APIs it hides | 86c6bd80….exe | CLI |
| A shellcode loader, instruction by instruction | 86c6bd80….exe | CLI |
| A dropper's embedded executable | 3c6b036f….exe | CLI + MCP |
| What does the code load from its resources? | 3c6b036f….exe | CLI |
| A URL hidden with XOR | 106710ac….exe | GUI |
| A PyInstaller program: which script runs, what is bundled | e21e0977….exe | GUI + CLI |
Where does it phone home, and who built it?¶
| Walkthrough | Sample | Interface |
|---|---|---|
| A Merlin C2 agent's configuration, no execution needed | merlin.dll | CLI |
| An obfuscated NativeAOT DLL | g4tj2aybt7y2xoq92p5e4y.dll | CLI |