Malcat dev

296 posts

Malcat dev banner
Malcat dev

Malcat dev

@malcat4ever

https://t.co/jeuFqKrpaH, a hexadecimal editor / disassembler / decompiler for #malware analysis, #DFIR and #SOC.

Lyon, France Katılım Şubat 2021
131 Takip Edilen2.6K Takipçiler
Malcat dev
Malcat dev@malcat4ever·
We tested 9 LLMs on real-world #malware triage and static unpacking tasks, using only #Malcat’s MCP server. We compared not only their results, but also their speed and cost. Full write-up: malcat.fr/blog/benchmark…
English
2
52
124
9.9K
Malcat dev
Malcat dev@malcat4ever·
#Malcat 0.9.14 is out! This is a maintenance build, with some bonuses: ● AccessDB parsing ● RAR unpacking ● UPX (static) unpacking ● Improved __noreturn detection ● ... and as usual, up-to-date signature, constants and Kesakode DBs!
Malcat dev tweet mediaMalcat dev tweet media
English
0
14
73
4.3K
Malcat dev
Malcat dev@malcat4ever·
If you are facing malicious access databases (getting traction rn), you can extract the VBA easily in #Malcat: 1. Locate "Attribute VB_Name" 2. Select from the 0x01 preceeding 3. .. up until a sequence of null bytes 4. Ctrl-T-> Office RLE We are working on a parser module!
Malcat dev tweet media
English
0
10
47
3.2K
Malcat dev retweetledi
Squiblydoo
Squiblydoo@SquiblydooBlog·
FUD CastleLoader signed "INFOTECK SOLUTIONS PRIVATE LIMITED" The 40MB exe makes it hard for detection engines to see the 1 important line of python it will execute. Short #malcat investigation though. 62a6e64a7233f4a756d01c54840ff703a620a416929d57eebc0bdac3b9ed2019 1/3
Squiblydoo tweet mediaSquiblydoo tweet media
English
1
10
47
4.4K
PrFalken
PrFalken@martinbayard·
@malcat4ever Where can we buy such a hoodie ? 😍😍😍
English
1
0
0
75
Malcat dev
Malcat dev@malcat4ever·
If you're attending #botconf this year and want to talk about #Malcat, come say hi. I'll be easy to spot: just look for the cool hoodie :)
Malcat dev tweet media
English
4
3
26
1.3K
Malcat dev
Malcat dev@malcat4ever·
(of course this is a joke, but I bet it's what he thought)
English
0
0
10
862
Malcat dev
Malcat dev@malcat4ever·
New anti-AV technique! By setting the PE VersionInfo to specific strings (here french for "dont-scan-mf"), you'll bypass most security solutions! Even if your file is named "RAT" or Stub.dll :D
Malcat dev tweet media
English
5
20
175
11.1K
Jessica Hunt
Jessica Hunt@huntnp007·
@malcat4ever Product name literally says RAT though. Not exactly subtle. Wild that string tricks still fool some vendors in 2025.
English
2
0
0
714
Malcat dev
Malcat dev@malcat4ever·
@SquiblydooBlog We have MSI -> powershell x2 -> shellcode that fetches a Letsdiskuss profile. C2 url is decoded by looking up the position of each word in the original lorem ipsum. All this and ... all the C2 urls are down :D
Malcat dev tweet mediaMalcat dev tweet mediaMalcat dev tweet media
English
0
2
20
5K
Squiblydoo
Squiblydoo@SquiblydooBlog·
Fake Microsoft Teams, "MTSetup_v15.3.7191.msi" signed by "Tryphena Lewis" 18c5b7a39be2f4a4b2fd45f0f273874f5efcc8751d4e592e5f2bcf6dbf781277 FUD-lite Uploaded to MalwareBazaar here https://bazaar.abuse[.]ch/sample/18c5b7a39be2f4a4b2fd45f0f273874f5efcc8751d4e592e5f2bcf6dbf781277
Squiblydoo tweet media
English
3
10
31
9.7K
Malcat dev
Malcat dev@malcat4ever·
Underrated use for LLMs: the ability to port Go programs to other languages, so that nobody has to touch this ugly language ever again.
English
1
1
15
927
Malcat dev
Malcat dev@malcat4ever·
In Malcat, hitting <Ctrl+M> will start the in-GUI MCP server (works in free version too). You can then interact with the current analysis using your LLM of choice. Here I renamed functions and variables of the C2 dispatcher function for an unknown malware:
Malcat dev tweet media
English
0
4
41
2.5K
Malcat dev retweetledi
Luke Acha
Luke Acha@luke92881·
@HuntYethHounds @rifteyy @SquiblydooBlog @andrewdanis @s1dhy ran xchanger through malcat MCP (using claude). Out of the box, got domains & registry behavior, failed to get the hard-coded XOR key. I had to have claude disassemble the .NET to get that additional info. Then had it create and HTML report. So, semi-automated. 🤷
English
1
1
9
619
Malcat dev
Malcat dev@malcat4ever·
@struppigel Wait 'til they learn about password-protected zip files.
English
1
0
8
360
RedDrip Team
RedDrip Team@RedDrip7·
#APT #Bitter 3ee66f56461fc046f600230d11ebe731 (MSI) f57975b8bc1169b35ae17b975327195e (EXE) hxxps://99media.com[.]pk/scvz zoemagicbook[.]com
RedDrip Team tweet mediaRedDrip Team tweet media
HT
2
10
30
3.1K