Shares tags: Youtube, SupplyChain, 3CXDesktopApp • Same author: struppigel • Published within a week
3CX SmoothOperator ffmpeg.dll with Binary Ninja
2023-04-03 • struppigel •
This malware analysis video walks through the trojanized 3CX desktop app supply chain attack by reversing the malicious ffmpeg.dll in Binary Ninja. The analysis starts from public reporting, unpacks the MSI, compares the signed components, and follows DLL entry point logic to the patched malware code. The malicious ffmpeg.dll loads d3dcompiler_47.dll, extracts embedded data from that file, checks synchronization events, and continues into the SmoothOperator execution flow described in contemporary 3CX reporting.
Related Reports
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
2023-04-21 •
50% Match
X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe
Symantec
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month