Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

squiblydoo@infosec.exchangeS

squiblydoo@infosec.exchange

@squiblydoo@infosec.exchange
About
Posts
6
Topics
3
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • I don't know how to feel about this domain: maybedontbanplease[.]com
    squiblydoo@infosec.exchangeS squiblydoo@infosec.exchange

    @darfplatypus
    This python dropper is tracked as "CastleLoader", there are a few actors that are leveraging it.
    Also, happy to talk via email or another medium if desired. (My email is Squiblydoo@pm.me)

    Uncategorized

  • I don't know how to feel about this domain: maybedontbanplease[.]com
    squiblydoo@infosec.exchangeS squiblydoo@infosec.exchange

    @darfplatypus Hello! Thanks for the question. Unfortunately, I didn't see the payload. Do you happen to have it?

    Uncategorized

  • Orange Cyberdefence recently published their research on SmokedHam.
    squiblydoo@infosec.exchangeS squiblydoo@infosec.exchange

    The full report can be found here and is well worth the read. https://research.cert.orangecyberdefense.com/smokedham/smoking_out_an_affiliate.pdf
    2/2

    Uncategorized

  • Orange Cyberdefence recently published their research on SmokedHam.
    squiblydoo@infosec.exchangeS squiblydoo@infosec.exchange

    Orange Cyberdefence recently published their research on SmokedHam. We're glad to see Cert Graveyard and the code-signing certs mentioned.

    While CertGraveyard tracks the campaigns, we can't investigate them to their full depth (due to capacity), so this is great to see.
    1/2

    Uncategorized

  • I don't know how to feel about this domain: maybedontbanplease[.]com
    squiblydoo@infosec.exchangeS squiblydoo@infosec.exchange

    I don't know how to feel about this domain: maybedontbanplease[.]com

    What to do? Chat, can you help me out?

    (CastleLoader
    4ba0d3ae41a0ae3143e8c2c3307c24b0d548593f97c79a30c0387b3d62504c31 signed "SERPENTINE SOLAR LIMITED"
    NSIS -> Python execution -> loads remote resource)

    Uncategorized

  • Golden Eye Dog (APT-Q-27) seems to have come back from break
    squiblydoo@infosec.exchangeS squiblydoo@infosec.exchange

    Golden Eye Dog (APT-Q-27) seems to have come back from break.
    We've seen 6 unique EV code-signing certs for campaigns in April already.

    All of these get reported and all get revoked.
    More about them in the thread.

    h/t @g0njxa, @malwrhunterteam
    1/4

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups