Syndicated Blog

[su_panel border="1px solid #ddd" radius="3" text_align="center"]
Blaze\\\'s Security Blog
Personal blog about internet & malware threats.
[/su_panel]
A screenshot of a computer  AI-generated content may be incorrect.

Earth Estries alive and kicking

| | Earth Estries
Earth Estries, also known as Salt Typhoon and a few other names, is a China-nexus APT actor, and is known to have used multiple implants such as Snappybee (Deed RAT), ShadowPad, and ...
Steam Phishing: popular as ever

Steam Phishing: popular as ever

A month or so ago a friend of mine received the following message on Steam from someone in their Friends list (they were already friends):Figure 1 - 'this is for you'                The two ...
Microsoft Word and Sandboxes

Microsoft Word and Sandboxes

Today's post is a brief one on some Microsoft Word and sandbox detection / discovery / fun.Collect user name from Microsoft OfficeMost sandboxes will trigger somehow or something if a tool or ...
A screen shot of a computer  Description automatically generated

Analyse, hunt and classify malware using .NET metadata

IntroductionEarlier last week, I ran into a sample that turned out to be PureCrypter, a loader and obfuscator for all different kinds of malware such as Agent Tesla and RedLine. Upon further investigation, ...
Digital artists targeted in RedLine infostealer campaign

Digital artists targeted in RedLine infostealer campaign

| | Crypto, infostealer, nft, redline
2021-06-17: updated with information from Twitter user ARC In this post, we'll look at a campaign, that targeted multiple 3D or digital artists using NFT, with malware named RedLine. This malware is ...
Blue Team Puzzle

Blue Team Puzzle

Several years ago, I created a "malware puzzle" - basically, a crossword puzzle but with terms related to malware. You can find that puzzle here: https://bartblaze.blogspot.com/2013/08/malware-puzzle.htmlSeeing crosswords are a hobby of mine, I ...
Satan ransomware rebrands as 5ss5c ransomware

Satan ransomware rebrands as 5ss5c ransomware

The cybercrime group that brought us Satan, DBGer and Lucky ransomware and perhaps Iron ransomware, has now come up with a new version or rebranding named "5ss5c".In a previous blog post, Satan ...
Monero download site and binaries compromised

Monero download site and binaries compromised

IntroductionEarlier this evening I saw a tweet appear which claimed Monero has been hacked and a malicious binary (instead of the real one) has been served:Warning Monero users: If you downloaded Monero ...
Run applications and scripts using Acer's RunCmd

Run applications and scripts using Acer’s RunCmd

This weekend I was cleaning up an old Acer laptop of mine and discovered a hidden folder on the root drive, C:\OEM.Inside's a bunch of interesting files, one of these is a ...
Analysing a massive Office 365 phishing campaign

Analysing a massive Office 365 phishing campaign

Last week, a friend of mine reached out with a query: a contact in his address book had sent him a suspicious email. As it turns out, it was. In this blog ...