← Home
my skillset
 

18 year old independent malware analyst, teacher, and computer science student from Czech Republic. I analyse malware, help and teach others.

YouTube

I make educational YouTube videos about malware analysis. I have covered some of the popular modern malware distribution methods such as ClickFix and I would like to make more videos in the future. I also run amateur-level anti-malware software tests.

Fileless malware PowerShell ClickFix XMRig miners AV Tests BATRAT
View channel

Latest video

Skills & Experience

Malware Disinfection

8+ years · 3,000+ people helped

Extensive knowledge in malware disinfection and remediation. Deep understanding of Windows OS, Sysinternals suite, FRST and in the past RSIT or HijackThis. Performed disinfections both physically and remotely, mostly by guiding users step by step.

Malware Analysis

Sandboxes · Reverse engineering

Extensive experience using online sandboxes - VirusTotal, Triage, AnyRun, Hybrid Analysis and more. Grown increasingly confident in reverse engineering and deobfuscating malware at a deeper level.

Script Malware

Red teaming · Blue teaming

Strong red team knowledge around creating undetected, script-based malware - including implementing full payloads within initial script stages. This same knowledge makes me effective at deobfuscating and analysing multi-stage scripts defensively.

AV Collaboration

Anti-malware industry

Invited to collaborate with and help improve an anti-malware product from a known vendor. I am submitting missed malicious samples, sharing my analysis, and providing feedback on detection improvements.

Teacher

Computer science · IT support

Teaching computer science and IT at primary and elementary school level. Also handle technical support for everything falling under tech - 3D printers, laser wood cutters, and more.

Notable work

Malware Blog · Discovery

TamperedChef / EvilAI Campaign

Discovered and wrote up a malware family falling under the TamperedChef/EvilAI campaign that went undetected for many years. The discovery at least temporarily disrupted their network - the threat actors shut down all discovered websites relevant to this variant.

Browse all analysis reports