本文へ移動
cccskills
無料GitHub で公開

diffing-malware-samples-to-find-changes

Compares two related malware samples to surface what changed between variants using section-level hashing, import-set differences, and fuzzy similarity scoring. Activates for requests to diff two samples, compare malware variants, or measure similarity between two binaries for variant tracking.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md2.7 KB
  • LICENSE340 B
  • references/api-reference.md1.3 KB
  • scripts/analyst.py3.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Diffing Malware Samples to Find Changes

When to Use

  • You have two related samples (suspected variants of one family) and want a fast, structural diff before a full BinDiff.
  • You need to quantify similarity and pinpoint changed sections/imports for variant tracking.

Do not use this as authoritative function-level diffing — that requires BinDiff/Diaphora on disassembly. This skill does structural/statistical diffing and executes nothing.

Prerequisites

  • Two sample files (read inertly). Optional: ssdeep/tlsh for fuzzy scores (degrade gracefully).

Workflow

Step 1: Structural diff

python scripts/analyst.py diff a.bin b.bin

Compares file size, per-section SHA-256 and entropy, and the import name sets, reporting added/ removed/changed sections and imports.

Step 2: Similarity score

Reports a byte-level similarity ratio and, if available, ssdeep/tlsh fuzzy-hash comparison scores.

Step 3: Prioritize changed regions

Changed sections (same name, different hash) and new imports are the high-value targets for deeper disassembly diffing.

Step 4: Document

Record what changed and the similarity score to support variant/lineage tracking.

Validation

  • Section comparison keys on section name; identical sections report equal hashes.
  • Import diff lists are accurate (added vs removed vs common).
  • Fuzzy-hash scores are reported only when the library is available, else clearly omitted.

Pitfalls

  • Recompilation shifting addresses makes raw byte diff noisy — rely on section/import structure.
  • Packers making both samples look similar (packed) while the payloads differ — unpack first.
  • Treating a high byte-similarity as proof of same author without corroboration.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する