1. X
  2. The Malware Files
Log inSign up
The Malware Files
140 posts
Image
user avatar
The Malware Files
@themalwarefiles
Story-driven and technical breakdowns of the world’s most fascinating malware
CyberSpace
themalwarefiles.com
Joined April 2025
1
Following
12
Followers
RepliesRepliesMediaMedia

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.

Don't miss what's happening

People on X are the first to know.

Log inSign up
  • user avatar
    The Malware Files
    @themalwarefiles
    Jul 9
    Most malware analyses start with static strings and hashes, but LockBit Black makes dynamic analysis just as hard as it can. In this report, @Nanaaisha_1 runs a LockBit Black sample in a FLAREVM environment and documents everything from entropy analysis and packer detection
    Image
    LOCKBIT RANSOMWARE: A FULL-SPECTRUM MALWARE ANALYSIS
    From themalwarefiles.com
    51
  • user avatar
    The Malware Files
    @themalwarefiles
    Jul 9
    Your EDR trusts Sysmon for one view of a process, the kernel for another, and the call stack for a third. But what if they all contradict each other? In this deep dive, Birkan reveals how stack spoofing and indirect syscalls create partial bypasses at individual telemetry
    themalwarefiles.com
    HOW RELIABLE ARE THE LOGS? Part 2
    Detection Engineering Series — Part 2 | Birkan KES | March 2026
    10
  • user avatar
    The Malware Files
    @themalwarefiles
    Jul 7
    A single hash with no context isn't much to go on, but it's enough to unravel an entire malware ecosystem. In this investigation, Macs-Hit follows a DCRat sample from MalwareBazaar through VirusTotal, CAPE Sandbox, and raw PCAP analysis. You'll learn how a hardcoded Google DNS
    Image
    The 21-Month Blind Spot: Why DCRat is still Evading Enterprise Defenses in 2026
    From themalwarefiles.com
    25
  • user avatar
    The Malware Files
    @themalwarefiles
    Apr 9
    CVE? CVSS? Mitigations? Cybersecurity terms can be overwhelming, especially for a newbie. In this article, @Dhanush_Nehru helps you to unlock the mystery behind some of these buzzwords in vulnerability management, and breaks them down for you to understand them better.
    Image
    The No-Nonsense Guide to Cybersecurity Vulnerabilities
    From themalwarefiles.com
    319
  • user avatar
    The Malware Files
    @themalwarefiles
    Mar 11
    SikoMode is a Nim-compiled infostealer that checks for a C2 connection the moment it runs. No connection, and it quietly wipes itself from disk, leaving no trace. If it does connect, it reads a JPEG off the desktop, encrypts it with RC4 using a key pulled from a separate file,
    themalwarefiles.com
    [PMAT] Malware Analysis: SikoMode
    This is a write up which describes one of the ways to approach the challenge: SikoMode from PMAT course, which covers the concepts related…
    44
  • See @themalwarefiles's full profile

    Sign up
    Log in
Advertisement
Advertisement