<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malware Analysis on Matthew Green | DFIR, Threat Intelligence &amp; Research</title><link>https://dfir.au/areas/malware-analysis/</link><description>Recent content in Malware Analysis on Matthew Green | DFIR, Threat Intelligence &amp; Research</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Wed, 05 Apr 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://dfir.au/areas/malware-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>Automating Qakbot decode at scale</title><link>https://dfir.au/posts/2023/qakbot/</link><pubDate>Wed, 05 Apr 2023 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2023/qakbot/</guid><description>Extract Qakbot configuration data and automate decoding at scale with Velociraptor. Covers payload unpacking, decryption and campaign indicators.</description></item></channel></rss>