Malcat reposted this
You like #capa but wish it would scan faster? Try out #Malcat 0.9.15, featuring a blazing fast native Capa scanner, among other improvements: https://lnkd.in/eiYQ_Ev4
Malcat is a feature-rich hexadecimal editor / disassembler for Windows and Linux targeted to IT-security professionals. Inspect 40+ binary file formats, disassemble and decompile different CPU architectures, extract embedded files and scan for Yara signatures or anomalies in a fast and easy-to-use graphical interface. Don't like what you get? Malcat is also heavily customizable and scriptable using python.
External link for Malcat
Malcat is a feature-rich hexadecimal editor / disassembler for Windows and Linux targeted to IT-security professionals. Inspect more than 40 binary file formats, dissassemble and decompile different CPU architectures, extract embedded files and scan for Yara signatures or anomalies in a fast and easy-to-use graphical interface. Don't like what you get? Malcat is also heavily customizable and scriptable using python.
Lyon, FR
Malcat reposted this
You like #capa but wish it would scan faster? Try out #Malcat 0.9.15, featuring a blazing fast native Capa scanner, among other improvements: https://lnkd.in/eiYQ_Ev4
You like #capa but wish it would scan faster? Try out #Malcat 0.9.15, featuring a blazing fast native Capa scanner, among other improvements: https://lnkd.in/eiYQ_Ev4
Malcat reposted this
Detecting #44CALIBER Stealer with #YARA Recently analyzed an unpacked sample of #44CALIBER stealer and wrote a YARA rule to detect it. The malware harvests browser data, cookies, saved passwords, autofill entries, and stored credit card details, alongside system info like the victim's IP, then exfiltrates everything to the attacker via Discord webhooks. Each stolen log is formatted with emoji-tagged fields (IP, Cookies, Passwords, CC, AutoFills). #Detection was built around a hardcoded internal path string unique to the malware's build environment, combined with its distinctive webhook message formatting, giving high quality, Zero FP and short runtime detection for this stealer family. Detection Rule: https://lnkd.in/em9saDix Triaged with Malcat #MalwareAnalysis #ThreatIntel #YARA #InfoStealer #ReverseEngineering
Malcat reposted this
"How do you reverse a MIPS binary if you've never touched one before?" Same way you reverse any other binary. Just remember to read the pointers backwards. New post: a beginner-friendly tour of ohshit.mips, a Mirai/CondiBot variant for IoT routers. Single-byte XOR "encryption", a function pointer table that's a red herring, and a punchline involving genddos[.]st that I am not going to spoil here. If you've ever opened a disassembler once, you can follow along. Every hotkey and address is in the post. Malcat tagged it as Mirai via Kesakode before I had even opened the disassembly, and the anomaly detector served me the XOR loop on a plate. Between those two it did about half the work for me, which felt a little unfair. https://lnkd.in/eW3C-DEr #ReverseEngineering #MalwareAnalysis #MIPS #IoT #Mirai
Malcat reposted this
"How do you reverse a MIPS binary if you've never touched one before?" Same way you reverse any other binary. Just remember to read the pointers backwards. New post: a beginner-friendly tour of ohshit.mips, a Mirai/CondiBot variant for IoT routers. Single-byte XOR "encryption", a function pointer table that's a red herring, and a punchline involving genddos[.]st that I am not going to spoil here. If you've ever opened a disassembler once, you can follow along. Every hotkey and address is in the post. Malcat tagged it as Mirai via Kesakode before I had even opened the disassembly, and the anomaly detector served me the XOR loop on a plate. Between those two it did about half the work for me, which felt a little unfair. https://lnkd.in/eW3C-DEr #ReverseEngineering #MalwareAnalysis #MIPS #IoT #Mirai
Malcat reposted this
We are working a new project: Malcat Logos. A web platform to perform LLM-assisted #malware triage at scale using solely Malcat MCP server. Thanks to Malcat's numerous analyses and databases, LLMs have access to a lot of useful pointers to speed up the analysis and give great results while keeping the tokens usage under control. Each LLM report is annotated with Malcat static analysis briefs so that analysts can better understand and double-check every given argument, even deep in the infection chain. Don't hesitate to contact us if you want to beta-test (in a few months). We would like feedback from SOC teams in particular.
We are working a new project: Malcat Logos. A web platform to perform LLM-assisted #malware triage at scale using solely Malcat MCP server. Thanks to Malcat's numerous analyses and databases, LLMs have access to a lot of useful pointers to speed up the analysis and give great results while keeping the tokens usage under control. Each LLM report is annotated with Malcat static analysis briefs so that analysts can better understand and double-check every given argument, even deep in the infection chain. Don't hesitate to contact us if you want to beta-test (in a few months). We would like feedback from SOC teams in particular.
Still working on Malcat-based automated LLM #malware triage. What do you think of this new kind of report (here on a somewhat complex infection chain): https://lnkd.in/dG2e9tNd A difficult aspect in AI triage is imho having to trust the LLM when not having the file open for verification. We've tried to address this issue by systematically generating a concise technical report for every (sub-)object that the LLM opens. Every (sub-)object cited by the AI reports refers this technical report.
We had 9 LLMs battle on real-world #malware triage and static unpacking tasks, using only #Malcat MCP server. We compared not only their results, but also their speed and cost. Full write-up: https://lnkd.in/dXPrphn9