JRT Vision

🐛 Defense & Governance

Malware
Analysis

When malware strikes, understanding is power. Our reverse engineering team dissects malicious code to determine its behaviour, origin, and impact — delivering actionable intelligence that stops threats before they spread.

0-Day Threat Detection
100% Family Attribution
🇦🇺 Australian Lab
🐛
🔍 Reverse
🔬 Analyse
🛡 Defend

Malware We
Dissect Daily

From commodity ransomware to nation-state APTs, our lab analyses every class of malicious software. Understanding the threat is the first step to neutralising it.

🔒

Ransomware

LockBit, BlackCat, Royal, and emerging strains. We decrypt behaviour, identify encryption algorithms, and develop recovery strategies without paying the ransom.

🕵

Spyware & Keyloggers

Covert surveillance tools designed to steal credentials, capture keystrokes, and exfiltrate sensitive data. We map C2 infrastructure and communication protocols.

🐉

Trojans & Backdoors

Remote access trojans (RATs) and persistent backdoors that give attackers long-term control. We identify persistence mechanisms and lateral movement capabilities.

🔄

Rootkits & Bootkits

Deep-level malware that hides below the operating system. We analyse kernel-level hooks, UEFI firmware implants, and boot sector modifications.

📦

Fileless Malware

Memory-resident threats that leave no disk footprint. We analyse PowerShell scripts, WMI events, and living-off-the-land techniques (LOLBin).

🌐

APTs & Nation-State

Advanced persistent threats with sophisticated TTPs. We attribute to known threat actors, map kill chains, and identify zero-day exploitation.

Comprehensive Malware
Analysis

From rapid triage to deep reverse engineering, we offer every level of malware analysis to match your threat severity, timeline, and budget.

Quick Triage
Fast
Triage 2-4 Hours

Rapid Malware Triage

Quick behavioural analysis to determine if a file is malicious, its severity, and recommended containment actions. Ideal for SOC teams under time pressure.

  • Static analysis & hash lookup
  • Sandbox detonation
  • Behavioural summary
  • Containment recommendations
🔧 Deep Reverse
Advanced
Reverse Engineering IDA Pro / Ghidra

Reverse Engineering

Full disassembly and decompilation of malicious binaries. We reconstruct the code flow, identify encryption routines, and map the complete attack chain from payload to C2.

  • Assembly-level disassembly
  • Decompilation (C/C++)
  • String & API extraction
  • Protocol reconstruction
🔬 Behaviour
Dynamic
Dynamic Sandbox / VM

Behavioural Analysis

Execution in isolated sandbox environments to observe real-time behaviour. File system changes, registry modifications, network connections, and API calls are all captured and analysed.

  • Isolated sandbox execution
  • Network traffic capture
  • Registry & file monitoring
  • Memory dump analysis
🌐 Threat Intel
Intelligence
Intelligence MITRE ATT&CK

Threat Intelligence

Family attribution, threat actor mapping, and IOC extraction. We map malware behaviour to MITRE ATT&CK framework and provide actionable threat intelligence for your security team.

  • Family attribution
  • MITRE ATT&CK mapping
  • IOC extraction (YARA, Sigma)
  • Threat actor correlation

The Analysis
Pipeline

A systematic, repeatable methodology that ensures every sample is analysed thoroughly, safely, and to the highest forensic standards.

01
📤

Sample Receipt

Secure submission via encrypted portal or physical delivery. We verify sample integrity, document chain of custody, and classify threat severity for prioritisation.

Encrypted Portal Integrity Check Priority Queue
02
📈

Static Analysis

Hash lookup, string extraction, PE header analysis, and entropy calculation. We identify packers, compilers, and known signatures without executing the malware.

Hash Lookup String Extraction Packer Detection
03
💻

Dynamic Analysis

Execution in isolated sandbox with full monitoring. We capture network traffic, API calls, registry changes, file system modifications, and memory behaviour in real-time.

Sandbox API Monitoring Network Capture
04
🔧

Reverse Engineering

Deep disassembly and decompilation for advanced samples. We reconstruct algorithms, decrypt payloads, and map the complete control flow to understand every capability.

Disassembly Decompilation Algorithm Reconstruction
05
📋

Intelligence Report

Comprehensive report with IOCs, YARA rules, MITRE ATT&CK mapping, and remediation guidance. Every finding is evidence-backed and ready for your SOC or legal team.

IOCs YARA Rules Remediation

Industry-Leading
Analysis Tools

Our malware lab is equipped with the best commercial and open-source tools, operated by certified analysts with years of reverse engineering experience.

🔧

Reverse Engineering

IDA Pro
Ghidra
Binary Ninja
Radare2 / Cutter
x64dbg
dnSpy / ILSpy
💻

Sandbox & Dynamic

Cuckoo Sandbox
ANY.RUN
Joe Sandbox
VMRay
Wireshark
Process Monitor
📋

Intelligence & IOCs

VirusTotal
MalwareBazaar
MITRE ATT&CK
YARA
Sigma
MISP

Malware Analysis
Across Sectors

Different industries face different malware threats. We bring sector-specific expertise to every analysis, ensuring intelligence is contextualised and actionable.

🏦

Financial Services

Banking trojans, ATM malware, and SWIFT attack analysis. We trace financial fraud malware and identify money mule infrastructure.

Banking Trojans SWIFT
🏥

Healthcare

Medical device malware, hospital ransomware, and PHI-targeting spyware. Protecting patient safety and data integrity.

Ransomware Medical Devices
🏛

Government & Defence

Nation-state APT analysis, supply chain compromise, and critical infrastructure targeting. Security-cleared analysts available.

APTs Supply Chain

Energy & Utilities

ICS/SCADA malware, power grid targeting, and industrial control system threats. Protecting critical national infrastructure.

SCADA ICS
🚀

Technology & SaaS

Supply chain attacks, cryptominers, and dev environment compromises. Supporting software vendors through incident response.

Supply Chain Cryptominers
🛒

Retail & E-commerce

PoS malware, Magecart skimmers, and payment card theft analysis. Protecting customer payment data and brand reputation.

PoS Malware Magecart
🐛 Submit Your Sample

Suspect Malware?
Let Us Analyse It.

Submit your suspicious file through our secure portal and receive a comprehensive analysis report within hours. Every sample is handled with strict confidentiality and analysed in our isolated Australian lab.

Secure Submission Portal
NDA Protected
2-4 Hour Triage
Actionable IOCs
OZ

OzComms Malware Lab

Australian Owned & Operated
📧
Email contact@ozcomms.com
📞
Phone +61 426 696 436
Turnaround 2-4 Hours (Triage)
🇦🇺
Location Australia
🛡 ISO 27001
🔒 NDA
GREM
Scroll to Top