RSSAmplifier

Blog

Fumi's Box

Sharing thoughts about subjects I care about

fumik0.comRSS feed ↗10 posts

Latest posts

You’re Not the Worst One Here

Every morning I open my phone and there it is again. Another model dropped. Another framework that changes everything. Another person on X/LinkedIn explaining, with quiet confidence, how they ve already integrated AI into every corner of their workflow while the rest of us were apparently still figuring out folders. It s exhausting in a way that s [ ]

Lu0bot – An unknown NodeJS malware using UDP

In February/March 2021, A curious lightweight payload has been observed from a well-known load seller platform. At the opposite of classic info-stealers being pushed at an industrial level, this one is widely different in the current landscape/trends. Feeling being in front of a grey box is somewhat a stressful problem, where you have no idea [ ]

Anatomy of a simple and popular packer

It s been a while that I haven t release some stuff here and indeed, it s mostly caused by how fucked up 2020 was. I would have been pleased if this global pandemic hasn t wrecked me so much but i was served as well. Nowadays, with everything closed, corona haircut is new trend and finding a graphic [ ]

Let’s play (again) with Predator the thief

Whenever I reverse a sample, I am mostly interested in how it was developed, even if in the end the techniques employed are generally the same, I am always curious about what was the way to achieve a task, or just simply understand the code philosophy of a piece of code. It is a very [ ]

Haruko Malware Tracker – 1 Year Anniversary Update

Hi folks, It s been one year that the tracker (https://tracker.fumik0.com) is now active and over this past months, I understood that maintaining this solo project was definitely not an easy task. But, right now, Haruko is step by step a growing place that provides a start for OSINT stuff, learning Reverse malware analysis or helping [ ]

Overview of Proton Bot, another loader in the wild!

Loaders nowadays are part of the malware landscape and it is common to see on sandbox logs results with loader tagged on. Specialized loader malware like Smoke or Hancitor/Chanitor are facing more and more with new alternatives like Godzilla loader, stealers, miners and plenty other kinds of malware with this developed feature as an option. [ ]

Let’s nuke Megumin Trojan

When you are a big fan of the Konosuba franchise, you are a bit curious when you spot a malware called Megumin Trojan (Written in C++) on some selling forums and into some results of sandbox submissions. Before some speculation about when this malware has appeared, this one is not recent and there are some [ ]

Let’s play with Qulab, an exotic malware developed in AutoIT

After some issues that kept me far away from my researches, it s time to put my hands again on some sympathetic stuff. This one is technically and finally my real first post of the year (The anti-VM one was a particular case). So today, we will dig into Qulab Stealer + Clipper, another password-stealer that [ ]

CPU Power Usage – Sandbox Evasive Technique

Hi Folks, I m not usually in this kind of paper, but this time, I am exceptionally writing a really short one about something related to some VM evasive PoC. There is always some tricks to detect if you are running on a virtual machine or not. Most of them are stupid, but it s enough accurate [ ]

Let’s dig into Vidar – An Arkei Copycat/Forked Stealer (In-depth analysis)

Sometimes when you are reading tons and tons of log of malware analysis, you are not expecting that some little changes could be in fact impactful. I paid the price when I was analyzing a supposed Arkei malware. my Yara rule at that time was supposed to trigger this malware, but after some reversing, I [ ]