We are working a new project: Malcat Logos. A web platform to perform LLM-assisted #malware triage at scale using solely Malcat MCP server.
Don't hesitate to contact us if you want to beta-test (in a few months). We would like feedback from SOC teams in particular.
Still working on #malware automated triage report. What do you think of this report, on a somewhat complex infection chain: https://t.co/XkDLH9ioM0
We've tried to attach a technical report to every (sub-)object open by the LLM
We tested 9 LLMs on real-world #malware triage and static unpacking tasks, using only #Malcat’s MCP server.
We compared not only their results, but also their speed and cost.
Full write-up:
https://t.co/z9KN3SR4P4
#Malcat 0.9.14 is out! This is a maintenance build, with some bonuses:
● AccessDB parsing
● RAR unpacking
● UPX (static) unpacking
● Improved __noreturn detection
● ... and as usual, up-to-date signature, constants and Kesakode DBs!
If you are facing malicious access databases (getting traction rn), you can extract the VBA easily in #Malcat:
1. Locate "Attribute VB_Name"
2. Select from the 0x01 preceeding
3. .. up until a sequence of null bytes
4. Ctrl-T-> Office RLE
We are working on a parser module!
We're happy to announce that #malcat 0.9.13 is out!
You'll find a new Apple-silicon MacOS port, two integrated MCP servers (in-GUI +headless) for automated triage and an improved interface:
https://t.co/WT7wyySRXG
#Malcat tip:
#Kesakode can be useful even when facing unknown/packed samples. Check "Show UNK" and focus on unique code and strings.
Here a simple downloader:
In the next version of #malcat, we will include an _offline_ smaller #kesakode database which will only contain conflict-free malware signatures.
This will be fast and run with every analysis. You can always get the full deal (clean + lib) afterwards with an online query.
We have released #malcat version 0.9.6, which comes with a new #malware identification service: #Kesakode!
● Works on unpacked malware
● 2000+ malware families & millions of clean + libs in DB
● Only hashes are sent
● Included in Malcat full & pro
https://t.co/6x2CiCWA5y
Wondering which #malware you are currently facing?
#Malcat's next update will embed #Kesakode, a cloud-based hash lookup service able to identfy functions, strings and constants from known malware and libaries!
No sample is uploaded, only hashes.
Stay tuned!
#Qakbot came back with new tricks. In this new blog post, we will:
● unpack it
● decrypt it (strings + cnc)
● and write a config extractor in python
using only static analysis (and #malcat of course :)
https://t.co/moDXSFNjW2
#Malcat version 0.9.5 is out!
You can now unpack & disassemble #InnoSetup installers, download samples from threat intel providers and enjoy an improved user interface.
Last but not least: Debian 12 package!
More info there:
https://t.co/5jIe3gfDhs
A bit late to the party, but here is the writeup for our #bggp4 entry, winner of the .PYC category.
It is also a good introduction to #Malcat's editing capabilities!
https://t.co/5ivNC8u8dO
Tip of the week #6: found an interesting location in your #malware? #malcat let you set up to 10 user bookmarks using Ctrl+Alt+<Number>.
You can jump back to saved locations using Alt+<Number>.
Version 0.9.4 is out!
We have added support for Ubuntu 23, a python 3.11 disassembler, magic masking selection for more robust code signatures and many QOL improvements.
More info there: https://t.co/tLf2b9G6Zr