139 Followers
47 Following
76 Posts

In Malcat, hitting <Ctrl+M> will start the in-GUI MCP server (works in free version too). You can then interact with the current analysis using your LLM of choice.

Here I renamed functions and variables of the C2 dispatcher function for an unknown malware:

We're happy to announce that #malcat 0.9.13 is out!

You'll find a new Apple-silicon MacOS port, two integrated MCP servers (in-GUI +headless) for automated triage and an improved interface:

https://malcat.fr/blog/0913-is-out-macos-port-mcp-server-and-dark-mode

Quick peek at the upcoming 0.9.3 release. It will also feature a 100% headless MCP server for full and pro users.

Sometimes, the absence of signature match is also interesting. Here the hashtag#Chrysalis sideloaded dll, where we can quickly spot the few interesting functions.

Make sure to check "Show UNK" !

A quick update on Malcat's MacOS development (apple silicon):

A couple of visual glitches, but the analysis & UI are now functional \o/

My @malcat Full License ran out after one year while my personal Professional License ist still valid for 2 Months. I'll pretty sure renew my Pro License. It's the first tool that I throw at an sample.

You can check out the free version at https://malcat.fr/download.html

PS: It's the only commercial Software that I purchased in the last 2 Years.

Get the software

Buy or download for free Malcat, the ultimate binary file dissector for Windows and Linux targeted to IT-security professionals.

MALCAT

#malcat 0.9.12 is out!

Enjoy .pyc and .net stack analysis, py 3.14 support, nuitka / inno 6.7 / .net singlefile bundle parsers and may other improvements:

https://malcat.fr/blog/0912-is-out-python-314-pyc-and-net-stack-analysis/

0.9.12 is out: Python 3.14, PYC and .NET stack analysis

Malcat version 0.9.12 is out! This time we have focused on python and dotnet disassembly, with a new stack analysis that should improve their disassembly listing readability. We have also added support for python 3.14 and packed a large number of minor improvements.

MALCAT

#kesakode DB update to 1.0.48:

● new sigs: Crazyhunter, Echogather, IranBot, MaskGramStealer, PulsarRat and Themeforestrat
● 9 existing entries updated
● FP-fixed signatures: 82
● 1146 new clean programs whitelisted
● +527K unique functions
● +700K unique strings

#Malcat tip:

#Kesakode can be useful even when facing unknown/packed samples. Check "Show UNK" and focus on unique code and strings.

Here a simple downloader:

My humble contribution to the Malware Analysis Community. Hope it helps !

Thanks @malcat 🙏

#malcat #malware #purelogsstealer

https://prfalken.org/from-winword-to-purelogsstealer-with-malcat/

From WinWord to PureLogsStealer with Malcat – PrFalken's Cyber Security Journey