Posts by Tag

MalwareAnalysis

Back to Top ↑

analysis

Pulling the Thread: Invite Only

8 minute read

How a suspicious filename led to 88 phishing domains, a shared hosting cluster, and an operator who probably should have used a different email address.

Threat Actors are playing the META

3 minute read

Cybercriminals and nation-state actors are converging on the same TTPs—not because they collaborate, but because efficiency is universal. They’re all playing...

Back to Top ↑

ThreatIntelligence

Back to Top ↑

opinion

Pulling the Thread: Invite Only

8 minute read

How a suspicious filename led to 88 phishing domains, a shared hosting cluster, and an operator who probably should have used a different email address.

Threat Actors are playing the META

3 minute read

Cybercriminals and nation-state actors are converging on the same TTPs—not because they collaborate, but because efficiency is universal. They’re all playing...

Back to Top ↑

ReverseEngineering

SharkyCTF 2020

15 minute read

SharkyCTF is a CTF organized during Sat, 09 May 2020 — Sun, 10 May 2020 . I participated with my CTF Team T-Regex and I was able to solve some challenges in ...

Back to Top ↑

iran

Back to Top ↑

Forensic

SharkyCTF 2020

15 minute read

SharkyCTF is a CTF organized during Sat, 09 May 2020 — Sun, 10 May 2020 . I participated with my CTF Team T-Regex and I was able to solve some challenges in ...

Back to Top ↑

Network

SharkyCTF 2020

15 minute read

SharkyCTF is a CTF organized during Sat, 09 May 2020 — Sun, 10 May 2020 . I participated with my CTF Team T-Regex and I was able to solve some challenges in ...

Back to Top ↑

WriteUp

Back to Top ↑

attribution

Back to Top ↑

cybercrime

Pulling the Thread: Invite Only

8 minute read

How a suspicious filename led to 88 phishing domains, a shared hosting cluster, and an operator who probably should have used a different email address.

Back to Top ↑

clickfix

Pulling the Thread: Invite Only

8 minute read

How a suspicious filename led to 88 phishing domains, a shared hosting cluster, and an operator who probably should have used a different email address.

Back to Top ↑

DPRK

Back to Top ↑