Mac Malware Minutes RodrigoStealer Hex Decode Debugging
>> YOUR LINK HERE: ___ http://youtube.com/watch?v=AxWUhQTYERk
This video focuses on reversing a decoding function from a recent macOS stealer (called Rodrigo and similar to AMOS) using LLDB and Binary Ninja. • This sample is written in C++ and uses a function to convert hex bytes for ascii characters to a string and pass the result to the system() function for its main stealer capabilities. • Malware sample RodrigoStealer.zip has been uploaded to Objective-See's Malware Repo on Github for anyone that wants to download and follow along: • • https[:]//github.com/objective-see/Malware/blob/main/RodrigoStealer.zip","styleRuns":[{"startIndex":0,"length":557,"styleRunExtensions":{"styleRunColorMapExtension":{"colorMap":[{"key":"USER_INTERFACE_THEME_DARK","value":4294967295},{"key":"USER_INTERFACE_THEME_LIGHT","value":4279440147}]}},"fontFamilyName":"Roboto"}]},"headerRuns":[{"startIndex":0,"length":557,"headerMapping":"ATTRIBUTED_STRING_HEADER_MAPPING_UNSPECIFIED"}]}},{"itemSectionRenderer":{"contents":[{"messageRenderer":{"text":{"runs":[{"text":"Comments are turned off. "},{"text":"Learn more","navigationEndpoint":{"clickTrackingParams":"CKcBEJY7GAAiEwiGoo_S-8iLAxWh00IFHbgaGs0=","commandMetadata":{"webCommandMetadata":{"url":"https://support.google.com/youtube/answer/9706180?hl=en","webPageType":"WEB_PAGE_TYPE_UNKNOWN","rootVe":83769}},"urlEndpoint":{"url":"https://support.google.com/youtube/answer/9706180?hl=en"}}}]},"trackingParams":"CKcBEJY7GAAiEwiGoo_S-8iLAxWh00IFHbgaGs0="}}],"trackingParams":"CKYBELsvGAIiEwiGoo_S-8iLAxWh00IFHbgaGs0=","sectionIdentifier":"comment-item-section"}}],"trackingParams":"CKUBELovIhMIhqKP0vvIiwMVodNCBR24GhrN"}},"secondaryResults":{"secondaryResults":{"results":[{"compactVideoRenderer":{"videoId":"XP10bUAbNeY","thumbnail":{"thumbnails":[{"url":"https://i.ytimg.com/vi/XP10bUAbNeY/hqdefault.jpg?sqp=-oaymwEiCKgBEF5IWvKriqkDFQgBFQAAAAAYASUAAMhCPQCAokN4AQ== rs=AOn4CLBBbAO4M3rCBDr8bjSRlRVni--pEQ","width":168,"height":94},{"url":"https://i.ytimg.com/vi/XP10bUAbNeY/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE= rs=AOn4CLDkv0QCKHQe_tVkzN4uF3431ia7SA","width":336,"height":188}]},"title":{"accessibility":{"accessibilityData":{"label":"Mac Malware Minutes - Banshee Stealer Triage Anti-Analysis (arm64) by L0psec Reversing 452 views 6 months ago 13 minutes, 20 seconds"}},"simpleText":"Mac Malware Minutes - Banshee Stealer Triage Anti-Analysis (arm64)"},"longBylineText":{"runs":[{"text":"L0psec Reversing","navigationEndpoint":{"clickTrackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0yB3JlbGF0ZWQ=","commandMetadata":{"webCommandMetadata":{"url":"/@L0psec","webPageType":"WEB_PAGE_TYPE_CHANNEL","rootVe":3611,"apiUrl":"/youtubei/v1/browse"}},"browseEndpoint":{"browseId":"UCkBBn_kpNjIyMbbN9Kwy2Xw","canonicalBaseUrl":"/@L0psec"}}}]},"publishedTimeText":{"simpleText":"6 months ago"},"viewCountText":{"simpleText":"452 views"},"lengthText":{"accessibility":{"accessibilityData":{"label":"13 minutes, 20 seconds"}},"simpleText":"13:20"},"navigationEndpoint":{"clickTrackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0yB3JlbGF0ZWRImaLgptCQ5YoDmgEFCAEQ-B0=","commandMetadata":{"webCommandMetadata":{"url":"/watch?v=XP10bUAbNeY","webPageType":"WEB_PAGE_TYPE_WATCH","rootVe":3832}},"watchEndpoint":{"videoId":"XP10bUAbNeY","nofollow":true,"watchEndpointSupportedOnesieConfig":{"html5PlaybackOnesieConfig":{"commonConfig":{"url":"https://rr4---sn-uxaxiv0nxx5q-nv4l.googlevideo.com/initplayback?source=youtube oeis=1 c=WEB oad=3200 ovd=3200 oaad=11000 oavd=11000 ocs=700 oewis=1 oputc=1 ofpcc=1 msp=1 odepv=1 id=5cfd746d401b35e6 ip=2a02%3A27aa%3A0%3A0%3A0%3A0%3A0%3Ad49 initcwndbps=983750 mt=1739735084 oweuc= pxtags=Cg4KAnR4Egg1MTM5MzE2Mw rxtags=Cg4KAnR4Egg1MTM5MzE2MA%2CCg4KAnR4Egg1MTM5MzE2MQ%2CCg4KAnR4Egg1MTM5MzE2Mg%2CCg4KAnR4Egg1MTM5MzE2Mw%2CCg4KAnR4Egg1MTM5MzE2NA"}}}}},"shortBylineText":{"runs":[{"text":"L0psec Reversing","navigationEndpoint":{"clickTrackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0yB3JlbGF0ZWQ=","commandMetadata":{"webCommandMetadata":{"url":"/@L0psec","webPageType":"WEB_PAGE_TYPE_CHANNEL","rootVe":3611,"apiUrl":"/youtubei/v1/browse"}},"browseEndpoint":{"browseId":"UCkBBn_kpNjIyMbbN9Kwy2Xw","canonicalBaseUrl":"/@L0psec"}}}]},"channelThumbnail":{"thumbnails":[{"url":"https://yt3.ggpht.com/SLT_HgbxFI16kaQMmt5tzWMCRakbRU_-JpaLBhsZJTi0ko-xJlgqywwnQCxAi67XJ7RWaMrg=s68-c-k-c0x00ffffff-no-rj","width":68,"height":68}]},"trackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs1A5uvsgNSN3f5c","shortViewCountText":{"accessibility":{"accessibilityData":{"label":"452 views"}},"simpleText":"452 views"},"menu":{"menuRenderer":{"items":[{"menuServiceItemRenderer":{"text":{"runs":[{"text":"Add to queue"}]},"icon":{"iconType":"ADD_TO_QUEUE_TAIL"},"serviceEndpoint":{"clickTrackingParams":"CKMBEP6YBBgFIhMIhqKP0vvIiwMVodNCBR24GhrN","commandMetadata":{"webCommandMetadata":{"sendPost":true}},"signalServiceEndpoint":{"signal":"CLIENT_SIGNAL","actions":[{"clickTrackingParams":"CKMBEP6YBBgFIhMIhqKP0vvIiwMVodNCBR24GhrN","addToPlaylistCommand":{"openMiniplayer":false,"openListPanel":true,"videoId":"XP10bUAbNeY","listType":"PLAYLIST_EDIT_LIST_TYPE_QUEUE","onCreateListCommand":{"clickTrackingParams":"CKMBEP6YBBgFIhMIhqKP0vvIiwMVodNCBR24GhrN","commandMetadata":{"webCommandMetadata":{"sendPost":true,"apiUrl":"/youtubei/v1/playlist/create"}},"createPlaylistServiceEndpoint":{"videoIds":["XP10bUAbNeY"],"params":"CAQ%3D"}},"videoIds":["XP10bUAbNeY"]}},{"clickTrackingParams":"CKMBEP6YBBgFIhMIhqKP0vvIiwMVodNCBR24GhrN","openPopupAction":{"popup":{"notificationActionRenderer":{"responseText":{"simpleText":"Added to queue"},"trackingParams":"CKQBELlqIhMIhqKP0vvIiwMVodNCBR24GhrN"}},"popupType":"TOAST"}}]}},"trackingParams":"CKMBEP6YBBgFIhMIhqKP0vvIiwMVodNCBR24GhrN"}},{"menuServiceItemRenderer":{"text":{"runs":[{"text":"Share"}]},"icon":{"iconType":"SHARE"},"serviceEndpoint":{"clickTrackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0=","commandMetadata":{"webCommandMetadata":{"sendPost":true,"apiUrl":"/youtubei/v1/share/get_share_panel"}},"shareEntityServiceEndpoint":{"serializedShareEntity":"CgtYUDEwYlVBYk5lWQ%3D%3D","commands":[{"clickTrackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0=","openPopupAction":{"popup":{"unifiedSharePanelRenderer":{"trackingParams":"CKIBEI5iIhMIhqKP0vvIiwMVodNCBR24GhrN","showLoadingSpinner":true}},"popupType":"DIALOG","beReused":true}}]}},"trackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0=","hasSeparator":true}}],"trackingParams":"CJ8BEKQwGAAiEwiGoo_S-8iLAxWh00IFHbgaGs0=","accessibility":{"accessibilityData":{"label":"Action menu"}},"targetId":"watch-related-menu-button"}},"thumbnailOverlays":[{"thumbnailOverlayTimeStatusRenderer":{"text":{"accessibility":{"accessibilityData":{"label":"13 minutes, 20 seconds"}},"simpleText":"13:20"},"style":"DEFAULT"}},{"thumbnailOverlayToggleButtonRenderer":{"isToggled":false,"untoggledIcon":{"iconType":"WATCH_LATER"},"toggledIcon":{"iconType":"CHECK"},"untoggledTooltip":"Watch later","toggledTooltip":"Added","untoggledServiceEndpoint":{"clickTrackingParams":"CKEBEPnnAxgBIhMIhqKP0vvIiwMVodNCBR24GhrN","commandMetadata":{"webCommandMetadata":{"sendPost":true,"apiUrl":"/youtubei/v1/browse/edit_playlist"}},"playlistEditEndpoint":{"playlistId":"WL","actions":[{"addedVideoId":"XP10bUAbNeY","action":"ACTION_ADD_VIDEO"}]}},"toggledServiceEndpoint":{"clickTrackingParams":"CKEBEPnnAxgBIhMIhqKP0vvIiwMVodNCBR24GhrN","commandMetadata":{"webCommandMetadata":{"sendPost":true,"apiUrl":"/youtubei/v1/browse/edit_playlist"}},"playlistEditEndpoint":{"playlistId":"WL","actions":[{"action":"ACTION_REMOVE_VIDEO_BY_VIDEO_ID","removedVideoId":"XP10bUAbNeY"}]}},"untoggledAccessibility":{"accessibilityData":{"label":"Watch later"}},"toggledAccessibility":{"accessibilityData":{"label":"Added"}},"trackingParams":"CKEBEPnnAxgBIhMIhqKP0vvIiwMVodNCBR24GhrN"}},{"thumbnailOverlayToggleButtonRenderer":{"untoggledIcon":{"iconType":"ADD_TO_QUEUE_TAIL"},"toggledIcon":{"iconType":"PLAYLIST_ADD_CHECK"},"untoggledTooltip":"Add to queue","toggledTooltip":"Added","untoggledServiceEndpoint":{"clickTrackingParams":"CKABEMfsBBgCIhMIhqKP0vvIiwMVodNCBR24GhrN","commandMetadata":{"webCommandMetadata":{"sendPost":true}},"signalServiceEndpoint":{"signal":"CLIENT_SIGNAL","actions":[{"clickTrackingParams":"CKABEMfsBBgCIhMIhqKP0vvIiwMVodNCBR24GhrN","addToPlaylistCommand":{"openMiniplayer":false,"openListPanel":true,"videoId":"XP10bUAbNeY","listType":"PLAYLIST_EDIT_LIST_TYPE_QUEUE","onCreateListCommand":{"clickTrackingParams":"CKABEMfsBBgCIhMIhqKP0vvIiwMVodNCBR24GhrN","commandMetadata":{"webCommandMetadata":{"sendPost":true,"apiUrl":"/youtubei/v1/playlist/create"}},"createPlaylistServiceEndpoint":{"videoIds":["XP10bUAbNeY"],"params":"CAQ%3D"}},"videoIds":["XP10bUAbNeY"]}}]}},"untoggledAccessibility":{"accessibilityData":{"label":"Add to queue"}},"toggledAccessibility":{"accessibilityData":{"label":"Added"}},"trackingParams":"CKABEMfsBBgCIhMIhqKP0vvIiwMVodNCBR24GhrN"}},{"thumbnailOverlayNowPlayingRenderer":{"text":{"runs":[{"text":"Now playing"}]}}}],"accessibility":{"accessibilityData":{"label":"Mac Malware Minutes - Banshee Stealer Triage Anti-Analysis (arm64) - 13 minutes, 20 seconds - Go to channel - L0psec Reversing - 452 views - 6 months ago - play video"}}}},{"lockupViewModel":{"contentImage":{"collectionThumbnailViewModel":{"primaryThumbnail":{"thumbnailViewModel":{"image":{"sources":[{"url":"https://i.ytimg.com/vi/lZKo8YP3GPw/hqdefault.jpg?sqp=-oaymwEWCKgBEF5IWvKriqkDCQgBFQAAiEIYAQ== rs=AOn4CLB7TvzLGdQDnrPfF_SVVJr2m7V0ag","width":168,"height":94},{"url":"https://i.ytimg.com/vi/lZKo8YP3GPw/hqdefault.jpg?sqp=-oaymwEXCNACELwBSFryq4qpAwkIARUAAIhCGAE= rs=AOn4CLBzDussFugHgvSJaaN_obUNZLBSVA","width":336,"height":188}]},"overlays":[{"thumbnailOverlayBadgeViewModel":{"thumbnailBadges":[{"thumbnailBadgeViewModel":{"icon":{"sources":[{"clientResource":{"imageName":"PLAYLISTS"}}]},"text":"12 videos","badgeStyle":"THUMBNAIL_OVERLAY_BADGE_STYLE_DEFAULT","backgroundColor":{"lightTheme":2630687,"darkTheme":2630687}}}],"position":"THUMBNAIL_OVERLAY_BADGE_POSITION_BOTTOM_END"}},{"thumbnailHoverOverlayViewModel":{"icon":{"sources":[{"clientResource":{"imageName":"PLAY_ALL"}}]},"text":{"content":"Play all","styleRuns":[{"startIndex":0,"length":8}]},"style":"THUMBNAIL_HOVER_OVERLAY_STYLE_COVER"}}],"backgroundColor":{"lightTheme":4143409,"darkTheme":4143409}}},"stackColor":{"lightTheme":12561555,"darkTheme":9668470}}},"metadata":{"lockupMetadataViewModel":{"title":{"content":"Mac Malware Minutes"},"metadata":{"contentMetadataViewModel":{"metadataRows":[{"metadataParts":[{"text":{"content":"L0psec Reversing
#############################
![](http://youtor.org/essay_main.png)