Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Malware Analysis

Hands-on malware analysis writeups. Each entry documents a sample end to end: delivery, static observations, controlled detonation in an isolated lab, and the indicators recovered.

All analysis is performed on my own hardware in isolated virtual environments. Network indicators in the writeups are defanged by convention.

Writeups

Sample Type Key finding
Trojanised FL Studio installer Go information stealer Functional Windows stealer that failed under Wine (incomplete winhttp); uses Telegram + Steam Community dead-drop resolvers. Recovered full C2 where three VirusTotal sandboxes returned no network indicators.

Approach

The writeups favour reproducible, evidence-led analysis:

  • Isolated KVM/QEMU lab with a hardened Windows guest (hidden hypervisor, host-passthrough CPU, non-virtio devices) to defeat VM detection.
  • A fake-internet segment (dnsmasq + INetSim) to capture C2 and exfil traffic without the sample reaching real infrastructure.
  • Evidence collected with Procmon, Regshot, Sysmon, tcpdump, and INetSim request logs, then correlated by timestamp.
  • Findings cross-checked against VirusTotal and mapped to MITRE ATT&CK.

Disclaimer

These documents are for defensive and educational purposes. Samples are handled only in isolated environments. Do not re-fang or connect to any indicator listed here from a production host.

Releases

Packages

Contributors