malwareresearch | Unsorted

Telegram-канал malwareresearch - Malware Research

9374

Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033

Subscribe to a channel

Malware Research

Hi everyone. Does anyone have the exact encryptor used by The Gentleman group for reverse engineering of the malware? Thanks 🙏

Читать полностью…

Malware Research

911578c4d665c12299d237228b7eb5dfe32cf57d1a7b1c155a0fe95d8b31dbb5

Читать полностью…

Malware Research

specially if any one have craxs rat

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: jijing
User ID: 8990459509
Reason: None given.

Читать полностью…

Malware Research

When a sample drops many files, a naming convention that keeps the process and timestamp together can save a lot of guesswork later. How do people here keep the relationship between a dropped file and the process that created it clear?

Читать полностью…

Malware Research

That evidence-first approach sounds right. For ambiguous cases, a short record of the evidence, alternatives considered and what would disprove the conclusion could be as useful as the final answer. It makes uncertainty visible rather than letting the agent hide it.

Читать полностью…

Malware Research

That’s a good point. I’m still experimenting with different samples, from simple to more complex and ambiguous ones.
So far, I’ve mainly focused on whether the agent can gather the right evidence and reach conclusions that can be verified manually in IDA. Testing misleading routines and uncertainty handling would definitely be a useful next step.

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Jack Truan
User ID: 8746380384
Reason: scam

Читать полностью…

Malware Research

The useful test for an IDAPython agent is not whether it names an encryption algorithm but whether every conclusion links back to a function, trace or decompiler view an analyst can inspect. That makes the tool easier to trust and to correct when it is wrong.

Читать полностью…

Malware Research

Oh, didn't know Andreas Zeller created this as well. His course on debugging is great

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Margaret R Rowley
User ID: 976225967
Reason: spam

Читать полностью…

Malware Research

hey guy, anyone know fuzzing binary :v i need learn ab this techniques :v

Читать полностью…

Malware Research

Please provide a description

Читать полностью…

Malware Research

If you would like to join the Nullspire hacking team, send us a message.

Читать полностью…

Malware Research

Can someone grab this from VT for me?

006f0ba963a63d9b2822b139ac806dee71eb6a3382b1b1db74b5cf2e60b57a51

Читать полностью…

Malware Research

1c8860b24267cf5ed4bb21db453bc3288c4e9339eeb5d85500847fe2e4dffd73

Читать полностью…

Malware Research

What about providing hashes?

Читать полностью…

Malware Research

Hey anyone have rat malware?

Читать полностью…

Malware Research

/fban @lmXhUBWcHhMZVh

Читать полностью…

Malware Research

Fedban reason update cancelled.

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: @​Co4de
User ID: 7724068664
Reason: spam

Читать полностью…

Malware Research

Matching a manual walkthrough is a strong sanity check. The next useful test would be a deliberately misleading sample or ambiguous routine, because that shows whether the agent can express uncertainty instead of forcing a clean answer. Does the workflow keep a record of rejected hypotheses too?

Читать полностью…

Malware Research

Absolutely, I agree. That is one reason I find integrating the agent with IDA useful. The goal is not just for the agent to give a conclusion, but to link it back to the relevant function, decompiled code, cross-references, or other evidence.
The analyst can then verify the conclusion directly in IDA and correct the agent if needed. I think that kind of traceability and human verification is very important when using AI for reverse engineering.
For reference, here is a separate video where I manually analyze how the malware encrypts the captured keystrokes. The findings from the manual analysis match what the AI agent identified in the demo:
https://youtu.be/EgOQsfhb_j0

Читать полностью…

Malware Research

I’ve been experimenting with how AI agents can assist with malware reverse engineering by interacting directly with reverse engineering tools and helping analysts investigate unfamiliar code.
In this video, watch an AI agent use tools exposed through IDAPython to analyze a malware sample and determine the encryption algorithm and encryption key used to encrypt captured keystrokes before they are stored in a file. This is currently a quick demonstration without detailed audio narration. I’ll be creating a more detailed video with audio soon, where I’ll walk through the setup, tools, and the complete reverse engineering workflow step by step.
For now, have a look at the demo to see how an AI agent can reason over disassembled code, leverage IDA capabilities through IDAPython, and assist with extracting meaningful information from malware.
AI-Powered Reverse Engineering:
https://youtu.be/gK9BFd_5OAc

Читать полностью…

Malware Research

https://www.fuzzingbook.org/

This Is a good resource

Читать полностью…

Malware Research

Check open security training v2 web site

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Eleanor E werner
User ID: 810745975
Reason: spam

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Nullspire
User ID: 8013035498
Reason: illegal activity

Читать полностью…

Malware Research

That makes the reporting task clearer. First get the expected behaviours and labels from the team, then use curated samples in an isolated lab and record what the sandbox observes rather than only its verdict. Different platforms can disagree because their telemetry, signatures and execution environment differ. Your report should show those gaps instead of treating one verdict as ground truth.

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Quarix
User ID: 8455952624
Reason: no maldev

Читать полностью…
Subscribe to a channel