March 4, 20226 min readStatic Analysis of a Ryuk Ransomware Sample (Hermes Variant)Static reverse engineering of two 32-bit PE binaries identified as Ryuk ransomware (Hermes variant). Covers the dropper/loader and the encryption payload, including persistence, process injection, and VSS deletion behavior.Read full article
March 4, 20225 min readMalware Sample AnalysisStatic/dynamic analysis of two 32-bit PE binaries — a WinMain-based narrow-down analysis using IDARead full article
January 1, 20216 min readPractical Malware Analysis v1An introduction to malware analysis techniques — static/dynamic analysis, malware types, and Windows DLL import analysisRead full article
January 1, 20216 min readAnubis Stealer: Malware AnalysisStatic and dynamic analysis of the Anubis banking trojan/stealer: persistence mechanisms, C2 communication, and credential theft techniquesRead full article