[su_panel border="1px solid #ddd" radius="3" text_align="center"]
Blaze\\\'s Security Blog
Personal blog about internet & malware threats.
[/su_panel]
Earth Estries alive and kicking
Earth Estries, also known as Salt Typhoon and a few other names, is a China-nexus APT actor, and is known to have used multiple implants such as Snappybee (Deed RAT), ShadowPad, and ...
Steam Phishing: popular as ever
A month or so ago a friend of mine received the following message on Steam from someone in their Friends list (they were already friends):Figure 1 - 'this is for you'Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â The two ...
Microsoft Word and Sandboxes
Today's post is a brief one on some Microsoft Word and sandbox detection / discovery / fun.Collect user name from Microsoft OfficeMost sandboxes will trigger somehow or something if a tool or ...
Analyse, hunt and classify malware using .NET metadata
IntroductionEarlier last week, I ran into a sample that turned out to be PureCrypter, a loader and obfuscator for all different kinds of malware such as Agent Tesla and RedLine. Upon further investigation, ...
Digital artists targeted in RedLine infostealer campaign
2021-06-17: updated with information from Twitter user ARC In this post, we'll look at a campaign, that targeted multiple 3D or digital artists using NFT, with malware named RedLine. This malware is ...
Blue Team Puzzle
Several years ago, I created a "malware puzzle" - basically, a crossword puzzle but with terms related to malware. You can find that puzzle here:Â https://bartblaze.blogspot.com/2013/08/malware-puzzle.htmlSeeing crosswords are a hobby of mine, I ...
Satan ransomware rebrands as 5ss5c ransomware
Bart | | 5ss5c, 5SS5C Encoder, 5ss5c ransomware, 5ss5c_CRYPT, 5ss5c_token, [email protected], DBGer ransomware, EternalBlue, Mimikatz, Ransomware, Satan ransomware
The cybercrime group that brought us Satan, DBGer and Lucky ransomware and perhaps Iron ransomware, has now come up with a new version or rebranding named "5ss5c".In a previous blog post, Satan ...
Monero download site and binaries compromised
Bart | | getmonero compromised, getmonero hack, Monero, Monero download site and binaries compromised, Monero hack, Monero project compromised
IntroductionEarlier this evening I saw a tweet appear which claimed Monero has been hacked and a malicious binary (instead of the real one) has been served:Warning Monero users: If you downloaded Monero ...
Run applications and scripts using Acer’s RunCmd
This weekend I was cleaning up an old Acer laptop of mine and discovered a hidden folder on the root drive, C:\OEM.Inside's a bunch of interesting files, one of these is a ...
Analysing a massive Office 365 phishing campaign
Bart | | O365 phishing, office, office 365, office 365 phishing, OWA phishing, Phishing, spear-phishing
Last week, a friend of mine reached out with a query: a contact in his address book had sent him a suspicious email. As it turns out, it was. In this blog ...

