Karsten Hahn (@struppigel) 's Twitter Profile
Karsten Hahn

@struppigel

MalwareAnalysisForHedgehogs, Principal Malware Researcher at GDATA, he/him 🦔🌈🏳️‍⚧️

ID: 2524769456

linkhttps://ko-fi.com/struppigel calendar_today26-05-2014 11:05:27

8,8K Tweet

23,23K Followers

734 Following

monty (@_montysecurity) 's Twitter Profile Photo

Dropped a new tool for malware researchers. It is used to continuously ingest, analyze, and alert on samples given a set of yara rules. Out of the box it works with abuse.ch MalwareBazaar recent uploads but it's modular so you can add more sources github.com/montysecurity/…

Karsten Hahn (@struppigel) 's Twitter Profile Photo

🦔 📹 New Video: Binary Refinery deobfuscation of a LummaStealer loader (PowerShell, JScript) youtube.com/watch?v=kHU_sP… #MalwareAnalysisForHedgehogs #PowerShell #JScript

vx-underground (@vxunderground) 's Twitter Profile Photo

Mildly irritating things seen by malware nerds: - Person saying {thing} evades EDR and/or AV, but they've never performed against an enterprise environment with an active Blue Team (they don't know what they're talking about). Yes, your payload avoided basic analysis, but stop

Michael Gillespie (@demonslay335) 's Twitter Profile Photo

🔒CryptoTester v1.7.2.0 for #Ransomware Analysis 🔍 New algorithms, XChaCha20 split into Draft02/03, enhancements to RSA Calculator, new derive/hash algorithms, Keystream Finder tool, and bugfixes. github.com/Demonslay335/C…

Karsten Hahn (@struppigel) 's Twitter Profile Photo

Interpreting antivirus detection names. This article is still relevant, it has been rewritten/copied by some using AI, without giving credit. So I am gonna post it again. gdatasoftware.com/blog/2019/08/3…

Europol (@europol) 's Twitter Profile Photo

Kidflix, one of the largest paedophile platforms in the world, has been shut down in an international operation against child sexual exploitation. ⏹️ Europol has supported authorities from 38 countries worldwide in shutting down the platform. More: europol.europa.eu/media-press/ne…

Kidflix, one of the largest paedophile platforms in the world, has been shut down in an international operation against child sexual exploitation.

⏹️ Europol has supported authorities from 38 countries worldwide in shutting down the platform.

More: europol.europa.eu/media-press/ne…
Karsten Hahn (@struppigel) 's Twitter Profile Photo

How to use knowledge about .NET structures and streams for writing better .NET Yara signatures. E.g. IL code patterns, method signature definitions, GUIDs, compressed length. #100DaysOfYara #GDATATechblog G DATA Global #GDATA gdatasoftware.com/blog/2025/04/3…

How to use knowledge about .NET structures and streams for writing better .NET Yara signatures.   

E.g. IL code patterns, method signature definitions, GUIDs, compressed length.

#100DaysOfYara #GDATATechblog <a href="/GDATA/">G DATA Global</a> #GDATA
gdatasoftware.com/blog/2025/04/3…
Washi (@washi_dev) 's Twitter Profile Photo

After #flareon11 challenge 7, I got inspired to build tooling for #dotnet Native AOT reverse engineering. As such, I built a #Ghidra Analyzer that can automatically recover most .NET types, methods and frozen objects (e.g., strings). Blog:👉blog.washi.dev/posts/recoveri…

After #flareon11 challenge 7, I got inspired to build tooling for #dotnet Native AOT reverse engineering.

As such, I built a #Ghidra Analyzer that can automatically recover most .NET types, methods and frozen objects (e.g., strings).

Blog:👉blog.washi.dev/posts/recoveri…
Karsten Hahn (@struppigel) 's Twitter Profile Photo

🦔 📹New Video: Analysis of Virut - Part I ➡️ self-modifying code ➡️ Ghidra markup decryption stub ➡️ API resolving ➡️ unpacking #MalwareAnalysisForHedgehogs youtube.com/watch?v=250Bxe…

Karsten Hahn (@struppigel) 's Twitter Profile Photo

"How I found Malware in a BeamNG Mod" An excellent article about hunting malware on a system with a suspected infection and analysis of a WebAssembly shellcode loader. lemonyte.com/blog/beamng-ma…

"How I found Malware in a BeamNG Mod"

An excellent article about hunting malware on a system with a suspected infection and analysis of a WebAssembly shellcode loader.

lemonyte.com/blog/beamng-ma…