Skip to content

*nix malware

*nix malware only

  • *nix malware
  • Twitter

Tag Archives: C

Overwriting argv[]

Malware on *nix systems can overwrite argv[] in order to hide from sysadmins and analysts. This post demonstrates this technique, ways to hunt for this behavior, and some links to real world samples which leverage this technique.

Posted byDanielFebruary 13, 2021Posted inprocfs, techniquesTags:C, deception, hunting, procfs, techniques
*nix malware, Website Powered by WordPress.com.
  • Subscribe Subscribed
    • *nix malware
    • Already have a WordPress.com account? Log in now.
    • *nix malware
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar