A quick win is to pivot around known constants, thanks to Malcat's 400k+ constants DB (here a #Tropidoor dlder):
A quick win is to pivot around known constants, thanks to Malcat's 400k+ constants DB (here a #Tropidoor dlder):
Malware signatures:
* New malware entries: 20 new families
* 564116 new unique functions
* 197608 new unique strings
* 27 new unique constant fingerprints
Malware signatures:
* New malware entries: 20 new families
* 564116 new unique functions
* 197608 new unique strings
* 27 new unique constant fingerprints
bazaar.abuse.ch/sample/85f8c...
bazaar.abuse.ch/sample/85f8c...
github.com/malpedia/mal...
github.com/malpedia/mal...
If it's just saying "it looks like sha256", it's also very quick to say without AI:
If it's just saying "it looks like sha256", it's also very quick to say without AI:
"File>Download from hash" will retrieve the hash for you from:
● Triage
● MalwareBazaar
● VirusShare
● MWDB
● FileScanIO
NB: some of these sources require (free) API keys.
"File>Download from hash" will retrieve the hash for you from:
● Triage
● MalwareBazaar
● VirusShare
● MWDB
● FileScanIO
NB: some of these sources require (free) API keys.
● Summary report as HTML+ SVG
● Proximity & call graph views as SVG or PNG
● Struct/hex/disasm views as HTML
● Strings, symbols, intel, kesakode and other views as CSV
● Summary report as HTML+ SVG
● Proximity & call graph views as SVG or PNG
● Struct/hex/disasm views as HTML
● Strings, symbols, intel, kesakode and other views as CSV