<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malware Analysis on XSS3cut10n3r</title><link>https://xss3cut10n3r.com/tags/malware-analysis/</link><description>Recent content in Malware Analysis on XSS3cut10n3r</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 03 Oct 2026 00:04:00 +0100</lastBuildDate><atom:link href="https://xss3cut10n3r.com/tags/malware-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>NSA Codebreaker 2025 - Task 4: Unpacking Insight</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</link><pubDate>Sat, 03 Oct 2026 00:04:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-4---unpacking-insight---malware-analysis"&gt;Task 4 - Unpacking Insight - (Malware Analysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Once back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the configuration data. FBI informs us that the facility registered to host that domain is on a watchlist for suspected criminal activity. With this tip, the FBI acquires a warrant and raids the location. Inside the facility, the server is discovered along with a suspect. The suspect is known to the FBI as a low-level malware actor. During questioning, they disclose that they are providing a service to host malware for various cybercrime groups, but recently they were contacted by a much more secretive and sophisticated customer. While they don&amp;rsquo;t appear to know anything about who is paying for the service, they provide the FBI with the malware that was hosted.&lt;/p&gt;</description></item></channel></rss>