Hands-on malware analysis writeups. Each entry documents a sample end to end: delivery, static observations, controlled detonation in an isolated lab, and the indicators recovered.
All analysis is performed on my own hardware in isolated virtual environments. Network indicators in the writeups are defanged by convention.
| Sample | Type | Key finding |
|---|---|---|
| Trojanised FL Studio installer | Go information stealer | Functional Windows stealer that failed under Wine (incomplete winhttp); uses Telegram + Steam Community dead-drop resolvers. Recovered full C2 where three VirusTotal sandboxes returned no network indicators. |
The writeups favour reproducible, evidence-led analysis:
- Isolated KVM/QEMU lab with a hardened Windows guest (hidden hypervisor,
host-passthroughCPU, non-virtio devices) to defeat VM detection. - A fake-internet segment (
dnsmasq+ INetSim) to capture C2 and exfil traffic without the sample reaching real infrastructure. - Evidence collected with Procmon, Regshot, Sysmon, tcpdump, and INetSim request logs, then correlated by timestamp.
- Findings cross-checked against VirusTotal and mapped to MITRE ATT&CK.
These documents are for defensive and educational purposes. Samples are handled only in isolated environments. Do not re-fang or connect to any indicator listed here from a production host.