Malware investigation
Starting from a (backdoored) MSI installer, the Qakbot analysis follows the infection chain to the final sample, decrypts its configuration, and writes a Malcat script to automate the process.
Result: Extracted configuration and a repeatable script.
Malware family identification
Kesakode helps answer which malware family an unpacked or dumped sample belongs to. It shows functions and strings shared with other malware families.
Result: Matching artifacts and family likelihood scores.
Detection engineering
Kesakode marks UNKNOWN and MALICIOUS functions and strings, helping you spot artifacts that have never been seen in clean programs or libraries. These are candidates for new YARA rules.
Result: Candidate YARA rule patterns. TODO: Add an approved capa finding from a 1.0 example.
Scripting and automation
The Qakbot analysis writes a Malcat script to automate configuration extraction. TODO: Add a separate 1.0 MCP workflow and its output.
Result: A repeatable configuration extractor.