Sign in

Karsten Hahn

@struppigel.bsky.social
322 followers 31 following 111 posts
PostsRepliesMedia
Karsten Hahn @struppigel.bsky.social · 28/09/2026
New blog: OpenSUpdater Hides in Recompiled 7zip SFX blog.gdatasoftware.com/2026/09/3849...
011
Karsten Hahn @struppigel.bsky.social · 20/06/2026
I published an API tracer for kernel mode drivers using speakeasy emulation AI notice: It's vibe-coded. I manually analyzed ~20 drivers to verify and improve the output and tested with a corpus of ~100 drivers. github.com/struppigel/h...
010
Karsten Hahn @struppigel.bsky.social · 19/06/2026
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6...
012
Karsten Hahn @struppigel.bsky.social · 13/06/2026
I submitted a new sample to samplepedia.cc PoisonX rootkit. Video solution follows the next days. samplepedia.cc/sample/db5d2...
030
Karsten Hahn @struppigel.bsky.social · 12/06/2026
This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing. The generated test files rely on real threat actor infrastructure to download or exfiltrate. hxxps://github.com/DataDog/guarddog/blob/main/tests
334
Karsten Hahn @struppigel.bsky.social · 07/05/2026
😂 @rifteyy just pointed me to this gem in the VT comment section for the empty file www.virustotal.com/gui/file/e3b...
010
Karsten Hahn @struppigel.bsky.social · 24/03/2026
My malware analysis courses have now a new certificate design. malwareanalysis-for-hedgehogs.learnworlds.com/courses
010
Karsten Hahn @struppigel.bsky.social · 23/03/2026
Added a task for the SugarSMP spark stealer sample to samplepedia samplepedia.cc/sample/060ed...
000
Karsten Hahn @struppigel.bsky.social · 03/03/2026
New blog: Using LLMs the right way for malware analysis 💡Tips for building an autonomous AI analysis lab on a 12 yo laptop and getting stuff done faster without loss of accuracy. blog.gdatasoftware.com/2026/03/3838...
000
Karsten Hahn @struppigel.bsky.social · 28/02/2026
The wallet exfiltration webhook uses a photo of Abdullah Öcalan as its avatar image.
100
Karsten Hahn @struppigel.bsky.social · 28/02/2026
GuvercinInstaller.exe 1/72 #kurdishmyth stealer, NodeJS ➡️Infects discord_desktop_core\index.js ➡️Steals various browser and discord data. ➡️Exfiltrates via discord webhook. The code references kurdishmyth and mythprivate www.virustotal.com/gui/file/496...
100
Karsten Hahn @struppigel.bsky.social · 21/02/2026
samplepedia.cc update: You have now a new "My articles" overview (see profile dropdown menu), which allows you to add article drafts and manage articles. You can decide to publish such a draft as a solution later.
020
Karsten Hahn @struppigel.bsky.social · 21/02/2026
Found a nice trainings sample for analysis of kernel mode rootkits ↓ samplepedia.cc/sample/465dc...
010
Karsten Hahn @struppigel.bsky.social · 10/02/2026
Looks like the dev told an LLM to generate test files for a Shai Hulud detection app. The LLM complied and generated malicious test files... github.com/Cobenian/sha...
010
Karsten Hahn @struppigel.bsky.social · 01/02/2026
I created an extraction script for custom PyInstaller applications as seen in suspected EvilAI PDF apps. Script (modified pyinstxtractor-ng): github.com/struppigel/h... Article: samplepedia.cc/sample/8c9d9...
031
Karsten Hahn @struppigel.bsky.social · 01/02/2026
#Samplepedia updates * you can upload images for articles * view count for samples and articles * expert difficulty available samplepedia.cc
030
Karsten Hahn @struppigel.bsky.social · 23/01/2026
If you like binary refinery, check out this sample It's also mostly undetected yet on VT: samplepedia.cc/sample/361f2...
041
Karsten Hahn @struppigel.bsky.social · 08/01/2026
Samplepedia update: Users can submit their own images with the samples and there is a platform field. samplepedia.cc
020
Karsten Hahn @struppigel.bsky.social · 04/01/2026
I have created a website, where you can share your sample analysis (via links or posts) and search samples for training based on tags and difficulty. If you write analysis blogs, you can share them there. samplepedia.cc
0147
Karsten Hahn @struppigel.bsky.social · 17/11/2025
I am suggesting a new malware type: the browser remote access tool (BRAT) It's a form of browser hijacker that remotely controls your browser based on server commands. Typical form: press key combos for copy-pasting URLs, opening tabs, context menu, downloading files etc
031
Karsten Hahn @struppigel.bsky.social · 13/11/2025
For anyone who wants to understand certificates better and how to spot abuse, this is a great read certcentral.org/training
022
Karsten Hahn @struppigel.bsky.social · 30/09/2025
My #VirusBulletin2025 loot 😍 I also met someone from vxunderground and all I got was this lousy sticker
130
Karsten Hahn @struppigel.bsky.social · 27/08/2025
IDA, why are you doing this? I lost my work because IDA refused to save. I needed to reboot the system to get network connection again. Without network there is no licensing server available. Surely there must be a better way to not loose work?
131
Karsten Hahn @struppigel.bsky.social · 20/08/2025
These PDF editors are functional but each contain a backdoor ➡️https://virustotal.com/gui/file/fde67ba523b2c1e517d679ad4eaf87925c6bbf2f171b9212462dc9a855faa34b bazaar.abuse.ch/sample/17355... URLs pdfreplace(dot)com pdfmeta(dot)com pdfartisan(dot)com appsuites(dot)ai #TamperedChef
083
Karsten Hahn @struppigel.bsky.social · 16/07/2025
Nikola Knežević created an overview of AsyncRAT forks and how they relate to each other. Great research. #AsyncRAT #QuasarRAT www.welivesecurity.com/en/eset-rese...
065
Karsten Hahn @struppigel.bsky.social · 10/02/2025
This curious wanna-be Batch virus appeared already on several systems. But why? autoexec.NT does not work anymore and it has an endless loop that pretends to scan. Did not find any tmp.bat yet. Not sure it even exists. www.virustotal.com/gui/file/e28...
120