• bitcoinBitcoin(BTC)$61,540.00-2.78%
  • ethereumEthereum(ETH)$1,598.00-9.14%
  • tetherTether(USDT)$1.000.06%
  • binancecoinBNB(BNB)$575.66-4.17%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.10-4.66%
  • solanaSolana(SOL)$64.32-5.21%
  • tronTRON(TRX)$0.321760-2.80%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.021.86%
  • HyperliquidHyperliquid(HYPE)$59.54-8.50%
  • dogecoinDogecoin(DOGE)$0.082582-5.43%
  • USDSUSDS(USDS)$1.000.03%
  • leo-tokenLEO Token(LEO)$9.56-3.68%
  • RainRain(RAIN)$0.013186-6.19%
  • stellarStellar(XLM)$0.2042651.78%
  • zcashZcash(ZEC)$375.32-19.37%
  • moneroMonero(XMR)$317.60-15.45%
  • cardanoCardano(ADA)$0.160089-11.61%
  • CantonCanton(CC)$0.149177-0.42%
  • chainlinkChainlink(LINK)$7.44-6.10%
  • whitebitWhiteBIT Coin(WBT)$43.83-4.07%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.09%
  • bitcoin-cashBitcoin Cash(BCH)$217.56-10.52%
  • daiDai(DAI)$1.00-0.01%
  • the-open-networkToncoin(TON)$1.51-7.85%
  • MemeCoreMemeCore(M)$2.90-12.31%
  • hedera-hashgraphHedera(HBAR)$0.080706-3.56%
  • litecoinLitecoin(LTC)$43.70-3.54%
  • LABLAB(LAB)$9.73-20.81%
  • avalanche-2Avalanche(AVAX)$6.87-9.76%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • suiSui(SUI)$0.71-7.60%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • shiba-inuShiba Inu(SHIB)$0.000005-6.49%
  • tether-goldTether Gold(XAUT)$4,310.32-3.12%
  • crypto-com-chainCronos(CRO)$0.058033-3.96%
  • nearNEAR Protocol(NEAR)$1.98-11.31%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.37%
  • pax-goldPAX Gold(PAXG)$4,329.74-3.03%
  • BittensorBittensor(TAO)$195.62-5.53%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.057201-3.90%
  • worldcoin-wldWorldcoin(WLD)$0.532.75%
  • mantleMantle(MNT)$0.52-5.60%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • OndoOndo(ONDO)$0.343231-6.63%
  • polkadotPolkadot(DOT)$0.95-7.47%
  • AsterAster(ASTER)$0.62-5.74%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

A Coding Implementation to Recover Hidden Malware IOCs with FLARE-FLOSS Beyond Classic Strings Analysis

May 10, 2026
in AI & Technology
Reading Time: 2 mins read
A A
A Coding Implementation to Recover Hidden Malware IOCs with FLARE-FLOSS Beyond Classic Strings Analysis
ShareShareShareShareShare

YOU MAY ALSO LIKE

Alien Isolation 2’s First Trailer Takes The Horror To A Colony Planet

Google DeepMind Releases Gemma 4 QAT Checkpoints: Q4_0 and a New Mobile Format Cut On-Device Memory

banner("STEP 6 — IOC hunting in the deobfuscated strings")
PATTERNS = [
   ("URL",          re.compile(r"https?://[^\s\"<>]+")),
   ("IP",           re.compile(r"\b(?:\d{1,3}\.){3}\d{1,3}\b")),
   ("PE/script",    re.compile(r"[A-Za-z0-9_]+\.(?:exe|dll|sys|ps1|bat)\b", re.I)),
   ("Win32 API",    re.compile(r"\b(?:Reg(?:Open|Set|Create|Delete)Key(?:Ex)?A?|VirtualAlloc(?:Ex)?|CreateRemoteThread|WinExec|LoadLibraryA?|GetProcAddress|InternetOpenA?)\b")),
   ("Registry",     re.compile(r"SOFTWARE\\\\?[A-Za-z0-9_\\\\]+", re.I)),
   ("Base64-like",  re.compile(r"\b[A-Za-z0-9+/]{24,}={0,2}\b")),
]
hits = []
for kind, items in buckets.items():
   for e in items:
       s = e.get("string","")
       for label, pat in PATTERNS:
           if pat.search(s): hits.append((kind, label, s))


if hits:
   print(f"{'BUCKET':<10}{'IOC':<14}STRING")
   print("-"*72)
   for kind,lbl,s in hits[:40]:
       print(f"{kind:<10}{lbl:<14}{s[:80]}")
   print(f"\n→ {len(hits)} IOC hits total. Note: most are inside the 'decoded' bucket")
   print("  — those would be invisible to plain `strings`!")
else:
   print("(no IOC pattern matches)")


banner("STEP 7 — Visualize string-type counts and length distribution")
import matplotlib.pyplot as plt
fig, (ax1, ax2) = plt.subplots(1, 2, figsize=(13, 4.5))


labels = list(buckets); counts = [len(v) for v in buckets.values()]
bars = ax1.bar(labels, counts, color=["#5fa8d3","#62b6cb","#cae9ff","#ff7b7b"])
ax1.set_title("FLOSS strings by type"); ax1.set_ylabel("count")
for b,n in zip(bars,counts): ax1.text(b.get_x()+b.get_width()/2, n, str(n), ha="center", va="bottom")


for kind, items in buckets.items():
   lens = [len(e.get("string","")) for e in items]
   if lens: ax2.hist(lens, bins=30, alpha=0.55, label=f"{kind} (n={len(lens)})")
ax2.set_title("String-length distribution"); ax2.set_xlabel("characters")
ax2.set_ylabel("frequency (log)"); ax2.set_yscale("log"); ax2.legend()
plt.tight_layout(); plt.savefig("floss_summary.png", dpi=110); plt.show()


print("\n✓ Tutorial complete.")
print(f"   Artifacts: {WORK/'sample.exe'}, {WORK/'floss.json'}, {WORK/'floss_summary.png'}")

Credit: Source link

ShareTweetSendSharePin

Related Posts

Alien Isolation 2’s First Trailer Takes The Horror To A Colony Planet
AI & Technology

Alien Isolation 2’s First Trailer Takes The Horror To A Colony Planet

June 5, 2026
Google DeepMind Releases Gemma 4 QAT Checkpoints: Q4_0 and a New Mobile Format Cut On-Device Memory
AI & Technology

Google DeepMind Releases Gemma 4 QAT Checkpoints: Q4_0 and a New Mobile Format Cut On-Device Memory

June 5, 2026
AI agents are learning on the job — just not for your whole team
AI & Technology

AI agents are learning on the job — just not for your whole team

June 5, 2026
Google Shuts Down The AI Image App Pixel Studio
AI & Technology

Google Shuts Down The AI Image App Pixel Studio

June 5, 2026
Next Post
WWE Backlash: Live results and analysis for Reigns vs. Fatu – ESPN

WWE Backlash: Live results and analysis for Reigns vs. Fatu - ESPN

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Genius Group Limited (GNS) Discusses AI Treasury Strategy and Execution of Phase 1 Transcript

Genius Group Limited (GNS) Discusses AI Treasury Strategy and Execution of Phase 1 Transcript

June 4, 2026
Aurora Mobile Limited 2026 Q1 – Results – Earnings Call Presentation (NASDAQ:JG) 2026-05-29

Aurora Mobile Limited 2026 Q1 – Results – Earnings Call Presentation (NASDAQ:JG) 2026-05-29

May 29, 2026
Mitsubishi Heavy Industries, Ltd. (MHVIY) Discusses Progress and Strategic Initiatives Under 2024 Medium-Term Business Plan – Slideshow

Mitsubishi Heavy Industries, Ltd. (MHVIY) Discusses Progress and Strategic Initiatives Under 2024 Medium-Term Business Plan – Slideshow

May 30, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!