Reverse engineering, with receipts

Malware Analysis & Reverse Engineering Writeups

Technical investigations backed by live, read-only Ghidra analysis sessions. Follow an address in the writing to inspect the exact decompiled code and binary evidence beside it.

Latest interactive analysis

Inside BambooToken’s Linux implant: shell and file control over MQTT

BambooToken turns an MQTT broker into a remote-control hub for Linux. Behind a 59-byte configuration blob, hex-encoded topics, and repeating XOR lies a backdoor built...

Read the writeup

Interactive analysis

Tengu: Reverse Engineering a Mirai-Style Linux/IoT Botnet

The sample examined here, tengu_sample, is a stripped, statically linked, position-independent 32-bit x86 Linux ELF. Its behavior is consistent with a Linux bot...

Read the writeup

Interactive analysis

The Gentlemen Ransomware Notes

64-bit Go PE, heavily obfuscated with Garble. About 2647 functions. Ransom note name, wallpaper, and file extension are not present as plain text in this build.

Read the writeup

Interactive analysis

Analysis of a Signed Silver Fox Group AV/EDR Killer Kernel Driver

A small 64-bit Windows kernel driver (driver.sys) was analyzed. Despite being code-signed by CR Connect (Tokyo) LLP, it functions as a straightforward AV/EDR process...

Read the writeup
reverser.space
Loading