I created an extraction script for custom PyInstaller applications as seen in suspected EvilAI PDF apps.
Script (modified pyinstxtractor-ng): github.com/struppigel/h...
Article: samplepedia.cc/sample/8c9d9...
@struppigel.bsky.social
I created an extraction script for custom PyInstaller applications as seen in suspected EvilAI PDF apps.
Script (modified pyinstxtractor-ng): github.com/struppigel/h...
Article: samplepedia.cc/sample/8c9d9...
#Samplepedia updates
* you can upload images for articles
* view count for samples and articles
* expert difficulty available
samplepedia.cc
anyPDF malware analysis report
rifteyy.org/report/anypd...
That's very useful, thank you!
27.01.2026 15:29 β π 1 π 0 π¬ 0 π 0Samples are in samplepedia.cc?tag=openxml
25.01.2026 07:31 β π 1 π 0 π¬ 0 π 0π¦ πΉ New Video: Can office files be malicious without Macros?
β‘οΈ VSTO Add-Ins
β‘οΈ External Templates
β‘οΈ Checklist for Office analysis
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=RtHH...
If you like binary refinery, check out this sample
It's also mostly undetected yet on VT:
samplepedia.cc/sample/361f2...
@invokereversing.bsky.social is analyzing Floxif with binary ninja
π
www.youtube.com/watch?v=2F_B...
Samplepedia update: Users can submit their own images with the samples and there is a platform field.
samplepedia.cc
I have created a website, where you can share your sample analysis (via links or posts) and search samples for training based on tags and difficulty.
If you write analysis blogs, you can share them there.
samplepedia.cc
I added a python script to monitor a folder during dynamic analysis and dump changed files with timestamp
github.com/struppigel/h...
π¦ πΉNew Video: RenPy game loads stealer, beginner friendly
β‘οΈ strategies for finding malware in 2956 files
β‘οΈ extracting and decompiling RenPy
β‘οΈ remote access tool config extraction
β‘οΈ unpacking native payload
#MalwareAnalysisForHedgehogs #RenPy
www.youtube.com/watch?v=Fmfg...
New blog: Browser Hijacking techniques -- when malware has different preferences than you
www.gdatasoftware.com/blog/2025/11...
#GDATA #GDATATechblog #BrowserHijacking
I added a RenPy archive (.rpa, .rpi) extractor to my tools repo
github.com/struppigel/h...
My colleague Banu wrote about a new infostealer Arkanix
www.gdatasoftware.com/blog/2025/12...
I am not sure. Probably part of his trainings.
30.11.2025 11:02 β π 0 π 0 π¬ 0 π 0π¦πΉ New Video: Modifying string decrypter for a ConfuserEx2 variant
β‘οΈ Defeating antis with Harmony hooks
β‘οΈ AsmResolver
β‘οΈ .NET string deobfuscation
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=sARn...
Black Friday offers:
60% off for 2 malware analysis courses (beginner & intermediate)
Or 40% off for single course
malwareanalysis-for-hedgehogs.learnworlds.com/courses
Lecture on Anti Tamper by Tim Blazytko www.youtube.com/watch?v=hQi9...
22.11.2025 07:00 β π 1 π 1 π¬ 1 π 0Rhadamanthys loader deobfuscation
cyber.wtf/2025/11/19/r...
I am suggesting a new malware type: the browser remote access tool (BRAT)
It's a form of browser hijacker that remotely controls your browser based on server commands.
Typical form: press key combos for copy-pasting URLs, opening tabs, context menu, downloading files etc
For anyone who wants to understand certificates better and how to spot abuse,
this is a great read
certcentral.org/training
π¦ πΉ Video: Analysis of malicious NordVPN setup
β‘οΈ beginner-suitable
β‘οΈ sorry, no spoilers here ;)
www.youtube.com/watch?v=5-OY...
#MalwareAnalysisForHedgehogs
I am looking for good resources for Linux malware analysis, including books and courses.
If you have any recommendations please let me know.
Thank you @threatresearch.bsky.social
06.10.2025 13:04 β π 0 π 0 π¬ 0 π 0My #VirusBulletin2025 loot π
I also met someone from vxunderground and all I got was this lousy sticker
Steam game BlockBlasters downloads malware
written by Arvin Tan
#GDATATechblog @GDATA #GDATA
www.gdatasoftware.com/blog/2025/09...
My colleague Banu wrote about the connection between AppSuite, OneStart and ManualFinder
www.gdatasoftware.com/blog/2025/09...
Invite link for our Discord expired, because I did not change the default limit.
Here is a new one, this time without limit
discord.gg/8xB38EedHT
π¦ πΉ New video: What breakpoints to set for unpacking malware?
β‘οΈ Steps of unpacking stub
β‘οΈ Breakpoint targets
β‘οΈ VirtualAlloc from user to kernel mode
#MalwareAnalysisForHedgehogs #Unpacking
www.youtube.com/watch?v=fn8r...