<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>nil — Zohir Hakmi</title><description>Reverse engineering, OS internals, memory forensics, and low-level security research.</description><link>https://zx41r.github.io/</link><language>en-us</language><item><title>c00ked d3v Full NexZeroCTF OSINT/4n6 Chain</title><link>https://zx41r.github.io/posts/c00ked-d3v/</link><guid isPermaLink="true">https://zx41r.github.io/posts/c00ked-d3v/</guid><description>Full solve for c00ked d3v recovering a scrubbed trail from GHCR layers to a dead host, then from deleted GitHub activity to a staging mirror, DNS TXT dead drop, and the final Gist.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>nexzeroctf</category><category>github</category><category>ghcr</category><category>docker</category><category>favicon-hash</category><category>fofa</category><category>urlscan</category><category>github-api</category><category>gitlab</category><category>dns</category><category>gist</category><category>osint</category><category>forensics</category></item><item><title>Phobos Ransomware — Malware Analysis Walkthrough</title><link>https://zx41r.github.io/posts/phobos/</link><guid isPermaLink="true">https://zx41r.github.io/posts/phobos/</guid><description>Deep analysis of Phobos ransomware: encrypted configuration, process termination, persistence mechanisms, and file encryption strategies.</description><pubDate>Sun, 04 Jan 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>phobos</category><category>ida-pro</category><category>x32dbg</category><category>aes-encryption</category><category>crc32</category><category>malware-analysis</category><category>reverse-engineering</category></item><item><title>Red Stealer — Threat Intelligence Walkthrough</title><link>https://zx41r.github.io/posts/red-stealer/</link><guid isPermaLink="true">https://zx41r.github.io/posts/red-stealer/</guid><description>Analyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&amp;CK techniques, and privilege escalation mechanisms.</description><pubDate>Sat, 03 Jan 2026 00:00:00 GMT</pubDate><category>virustotal</category><category>malwarebazaar</category><category>threatfox</category><category>redline-stealer</category><category>ioc</category><category>mitre-attack</category><category>c2</category><category>threat-intelligence</category><category>malware-analysis</category></item><item><title>RE101 — Reverse Engineering Fundamentals Walkthrough</title><link>https://zx41r.github.io/posts/re101/</link><guid isPermaLink="true">https://zx41r.github.io/posts/re101/</guid><description>Analyze diverse file types including binaries, obfuscated scripts, and corrupted archives using reverse engineering techniques to extract hidden flags.</description><pubDate>Sat, 03 Jan 2026 00:00:00 GMT</pubDate><category>base64</category><category>jsfuck</category><category>brainfuck</category><category>zip-repair</category><category>stack-strings</category><category>xor-encryption</category><category>ida</category><category>ghidra</category><category>hex-editor</category><category>malware-analysis</category><category>reverse-engineering</category></item><item><title>Ransomed — Malware Analysis Walkthrough</title><link>https://zx41r.github.io/posts/ransomed/</link><guid isPermaLink="true">https://zx41r.github.io/posts/ransomed/</guid><description>Dynamic analysis and memory forensics: stack-strings, API resolution, shellcode and process hollowing.</description><pubDate>Fri, 02 Jan 2026 00:00:00 GMT</pubDate><category>process-hollowing</category><category>shellcode</category><category>x32dbg</category><category>scdbg</category><category>ida</category><category>malware-analysis</category><category>reverse-engineering</category></item></channel></rss>