Reverse engineering, with receipts
Malware Analysis & Reverse Engineering Writeups
Technical investigations backed by live, read-only Ghidra analysis sessions. Follow an address in the writing to inspect the exact decompiled code and binary evidence beside it.
Latest interactive analysis
Inside BambooToken’s Linux implant: shell and file control over MQTT
BambooToken turns an MQTT broker into a remote-control hub for Linux. Behind a 59-byte configuration blob, hex-encoded topics, and repeating XOR lies a backdoor built...
Read the writeupInteractive analysis
Tengu: Reverse Engineering a Mirai-Style Linux/IoT Botnet
The sample examined here, tengu_sample, is a stripped, statically linked, position-independent 32-bit x86 Linux ELF. Its behavior is consistent with a Linux bot...
Read the writeupInteractive analysis
The Gentlemen Ransomware Notes
64-bit Go PE, heavily obfuscated with Garble. About 2647 functions. Ransom note name, wallpaper, and file extension are not present as plain text in this build.
Read the writeupInteractive analysis
Analysis of a Signed Silver Fox Group AV/EDR Killer Kernel Driver
A small 64-bit Windows kernel driver (driver.sys) was analyzed. Despite being code-signed by CR Connect (Tokyo) LLP, it functions as a straightforward AV/EDR process...
Read the writeup