~/xavifortes

Malware analysis & reverse engineering

Writeups from pulling apart real samples. Everything here is static analysis unless stated otherwise. Samples are linked to public repositories rather than hosted here, and indicators on this site are defanged.

2

writeups

7

samples analysed

19

indicators published

4

submissions

Shared back

Indicators and samples go to the public trackers so detection vendors and other researchers can act on them, not just sit in a writeup.

7 samples from the RenPy/MSBuild loader chain, linked into a dropped_by / dropping chain

ThreatFox

2026-08

21 indicators — 15 downloader C2 domains, the stage-1 install tracker, and 5 sample hashes — all approved

YARAify

2026-08

6 detection rules covering the carrier project, launcher script, dropper and both loader stages

Microsoft Security Intelligence

2026-08

Full chain submitted for Defender coverage, with a note not to signature the clean Ren'Py launcher