#MalwareAnalysisForHedgehogs

2026-01-25

🦔 📹 New Video: Can office files be malicious without Macros?

➡️ VSTO Add-Ins
➡️ External Templates
➡️ Checklist for Office analysis
#MalwareAnalysisForHedgehogs
youtube.com/watch?v=RtHHckH5IsI

2025-12-21

🦔 📹New Video: RenPy game loads stealer, beginner friendly
➡️ strategies for finding malware in 2956 files
➡️ extracting and decompiling RenPy
➡️ remote access tool config extraction
➡️ unpacking native payload
#MalwareAnalysisForHedgehogs #RenPy
youtube.com/watch?v=Fmfg0F1e2tM

2025-11-30

🦔📹 New Video: Modifying string decrypter for a new ConfuserEx2 variant
➡️ Defeating antis with Harmony hooks
➡️ AsmResolver
➡️ .NET string deobfuscation

#MalwareAnalysisForHedgehogs

youtube.com/watch?v=sARnT7o8L60

2025-10-26

🦔 📹 Video: Analysis of malicious NordVPN setup
➡️ beginner-suitable
➡️ sorry, no spoilers here ;)

youtube.com/watch?v=5-OY3ISH6Bk

#MalwareAnalysisForHedgehogs

2025-09-08

🦔 📹 New video: What breakpoints to set for unpacking malware?
➡️ Steps of unpacking stub
➡️ Breakpoint targets
➡️ VirtualAlloc from user to kernel mode

#MalwareAnalysisForHedgehogs #Unpacking
youtube.com/watch?v=fn8rAm9u4rc

2025-08-09

🦔 📹 New Video: There is more than Clean and Malicious

➡️ 7 file analysis verdicts and what they mean

#MalwareAnalysisForHedgehogs #Verdicts
youtube.com/watch?v=XwT23XVtAw0

2025-07-05

🦔 📹 Virut Part III: File infection analysis and bait file creation

#MalwareAnalysisForHedgehogs #Virut
youtube.com/watch?v=FcXPSpBh4ps

2025-05-30

Virut part II: process infection and NTDLL hooking 🦔📹
➡️x64dbg scripting
➡️conditional breakpoints
➡️more import table resolving
➡️fixing control flow
➡️marking up hook code

#MalwareAnalysisForHedgehogs #Virut
youtube.com/watch?v=nuxnvjGgUQ

2025-04-30

🦔 📹New Video: Analysis of Virut - Part I
➡️ self-modifying code
➡️ Ghidra markup decryption stub
➡️ API resolving
➡️ unpacking
#MalwareAnalysisForHedgehogs
youtube.com/watch?v=250Bxe0qlQY

2024-06-09

New video: Why antivirus software detects cracks as malware or PUP 🦔📹

#MalwareAnalysisForHedgehogs #cracks #antivirus
youtube.com/watch?v=KA7R9rt5r4

2024-05-20

🦔 📹 New Video: D3fack loader analysis

➡️ Inno Setup pascal script analysis
➡️ string deobfuscation with binary refinery
➡️ JPHP decompilation

Sample was first described by @RussianPanda9xx

youtube.com/watch?v=y09ZreJaWE
#MalwareAnalysisForHedgehogs #D3fackLoader

2023-07-23

New Video: Why Windows system files have wrong compile timestamps 🦔📹

#MalwareAnalysisForHedgehogs #Repro
youtu.be/8Q_cbAolKGg?si=34Wsq8

2023-07-02

New Video: How to find the main code in an Electron App. Unpacking Ageostealer. 🦔📹

#MalwareAnalysisForHedgehogs #Electron #JS

youtu.be/kGwa9poV8OU

2023-05-21

New Video: Auto Start Monitoring and Disinfection Training with Sysinternals Autoruns

Topics: IFEO, Run, RunOnce, Services, Scheduled Tasks, Active Setup, Startup folder

#MalwareAnalysisForHedgehogs #Disinfection #ASEPs
youtu.be/NNRSFrIyLUg

2023-04-26

New Video: Packer identifiers do not tell you if a file is packed 🦔📹

#MalwareAnalysisForHedgehogs #Packer #PackerIdentifiers

youtu.be/ozyBOXpKm1I

2023-04-07

New Video: C2 extraction for 3CX SmoothOperator 🦔📹

youtu.be/_jsgCRNcf1o

#MalwareAnalysisForHedgehogs #3CX #SmoothOperator

2023-04-05

New Video: How the malware in 3CX SmoothOperator abuses authenticode signatures. 🎥🦔

#MalwareAnalysisForHedgehogs #SmoothOperator #3CX
youtu.be/jCXIKHCpvn8

2023-04-03

New video: 3CX SmoothOperator analysis of ffmpeg with Binary Ninja
🦔📹
#MalwareAnalysisForHedgehogs #3CX #SmoothOperator
youtu.be/fTX-vgSEfjk

2023-01-28

New Video: Packers, polymorphism and common misconceptions🦔📹

#MalwareAnalysisForHedgehogs #Packers
youtu.be/ESLEf66EzDk

2023-01-17

New video: Does writing malware help with malware analysis? 🦔

#MalwareAnalysisForHedgehogs
youtu.be/vzfmjBYaTwg

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst