Welcome to Njósnir
Spies had been posted all the way south to Naumudal
Meta
The first post on Njósnir — what this site is, what to expect, and why it is named after the scouts of the sagas.
Welcome to Njósnir, a site for malware reverse-engineering write-ups.
The name is Old Norse for the scouts, the spies — the people sent out to watch, gather intelligence, and report back. That is also a fair description of what happens here: samples go into the sandbox, and reports come back out.
What to expect
- Unpacking write-ups — defeating packers and obfuscation, dumping and reconstructing payloads
- Static analysis — disassembly walkthroughs, annotated decompilations, algorithm identification
- Dynamic analysis — behavioral runs in isolated VMs, network capture, API tracing
- Tooling notes — the sandbox infrastructure and automation behind the analyses
All analysis is performed in isolated environments on samples obtained for research purposes. Indicators are shared where they can help defenders.
More soon. The ravens are already out.