RSSAmplifier

Blog

Blaze's Security Blog

Personal blog about internet & malware threats.

bartblaze.blogspot.comRSS feed ↗25 posts

Latest posts

Autumn Dragon: China-nexus APT Group Targets South East Asia

In this report, we describe how we tracked for several months a sustained espionage campaign against the government, media, and news sectors in several countries including Laos, Cambodia, Singapore, the Philippines and Indonesia. Since early 2025, China’s involvement in the Indo-Pacific has been more prolific, from escalating maritime tensions, to being peacebroker in Myanmar’s military junta and…

Earth Estries alive and kicking

Earth Estries, also known as Salt Typhoon and a few other names, is a China-nexus APT actor, and is known to have used multiple implants such as Snappybee (Deed RAT), ShadowPad, and several more. In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode. The execution flow is as follows: That is all. Find below indicators…

Steam Phishing: popular as ever

A month or so ago a friend of mine received the following message on Steam from someone in their Friends list (they were already friends): Figure 1 - 'this is for you' The two links are different and refer to a Gift Card on Steam's community platform. As you might have noticed, the domain is not related to Steam at all, but rather is an attempt at phishing. The URLs are: ste r mco r…

Microsoft Word and Sandboxes

Today's post is a brief one on some Microsoft Word and sandbox detection / discovery / fun. Collect user name from Microsoft Office Most sandboxes will trigger somehow or something if a tool or malware tries to collect system information or user information. But what if we collect the user name via the registry and more specifically, what user info Microsoft Office sees? This information is stored…

New North Korean based backdoor packs a punch

In recent months, North Korean based threat actors have been ramping up attack campaigns in order to achieve a myriad of their objectives, whether it be financial gain or with espionage purposes in mind. The North Korean cluster of attack groups is peculiar seeing there is quite some overlap with one another, and it is not always straightforward to attribute a specific campaign to a specific…

Analyse, hunt and classify malware using .NET metadata

Introduction Earlier last week, I ran into a sample that turned out to be PureCrypter , a loader and obfuscator for all different kinds of malware such as Agent Tesla and RedLine. Upon further investigation, I developed Yara rules for the various stages, which can be found here (excluding the final payload): PureZip 2nd stage downloader (PureLogStealer related) With that out of the way, all of…

Fara: Faux YARA

FARA, or Faux YARA, is a simple repository that contains a set of purposefully erroneous Yara rules. It is meant as a training vehicle for new security analysts, those that are new to Yara and even Yara veterans that want to keep their rule writing (and debugging) sharp. Example "faux" rule Find it over on Github: https://github.com/bartblaze/FARA

Yara rules collection

Quite a while ago, I've published some of my private Yara rules online, on Github. They can be found here: https://github.com/bartblaze/Yara-rules There's two workflows running on that Github repository: YARA-CI : runs automatically to detect signature errors, as well as false positives and negatives. Package Yara rules : allows download of a complete rules file (all Yara rules from this repo in…

Digital artists targeted in RedLine infostealer campaign

2021-06-17: updated with information from Twitter user ARC In this post, we'll look at a campaign, that targeted multiple 3D or digital artists using NFT, with malware named RedLine . This malware is a so called "infostealer" or "information stealer" that is capable of extracting sensitive data from your machine (such as wallet information, credentials, and so on). As a side-note; NFTs, or…

Blue Team Puzzle

Several years ago, I created a "malware puzzle" - basically, a crossword puzzle but with terms related to malware. You can find that puzzle here: https://bartblaze.blogspot.com/2013/08/malware-puzzle.html Seeing crosswords are a hobby of mine, I thought it'd be fun to create another one more than seven years later - this time, all things blue team! Obviously you don't need to be part of a blue…

Satan ransomware rebrands as 5ss5c ransomware

The cybercrime group that brought us Satan, DBGer and Lucky ransomware and perhaps Iron ransomware , has now come up with a new version or rebranding named "5ss5c". In a previous blog post, Satan ransomware adds EternalBlue exploit , I described how the group behind Satan ransomware has been actively developing its ransomware, adding new functionalities (specifically then: EternalBlue) and…

Monero download site and binaries compromised

Introduction Earlier this evening I saw a tweet appear which claimed Monero has been hacked and a malicious binary (instead of the real one) has been served: Warning Monero users: If you downloaded Monero in the past 24 hours you may have installed malware. Monero's official website served compromised binaries for at least 30 minutes during the past 24 hours. Investigations are ongoing.…

Run applications and scripts using Acer's RunCmd

This weekend I was cleaning up an old Acer laptop of mine and discovered a hidden folder on the root drive, C:\OEM . Inside's a bunch of interesting files, one of these is a tool called RunCmd_X64.exe . The file is a legitimate and signed binary by Acer: Figure 1 - Signed RunCmd_X64 The tool contains a useful help file as follows: A tool to execute a command file. RunCmd.exe filepath [/T | /F]…

Analysing a massive Office 365 phishing campaign

Last week, a friend of mine reached out with a query: a contact in his address book had sent him a suspicious email. As it turns out, it was. In this blog post, we'll have a quick look at an Office 365 phishing campaign, which turned out to be massive. This type of phishing has been on the rise for a while now (at least since 2017), and it's important to point out, as seemingly attacks are only…

MAFIA ransomware targeting users in Korea

A new ransomware family was discovered and sent to me by MalwareHunterTeam , which we'll call MAFIA due to the extension it uses to encrypt files. The ransomware appears to target users in Korea, and may have been developed with at least knowledge of the Korean language. Another interesting (and new to me) feature is the use of "Onion.Pet", a Tor proxy as a means for C2 (network) communication.…

RedEye ransomware: there's more than meets the eye

A rather anonymous account reached out to me on Twitter asking to check out a "scary & really nasty" sample. It turned out to be RedEye ransomware, a new strain or variant by the same creator of Annabelle ransomware , which I discovered in February earlier this year. Analysis This ransomware is named " RedEye " by the author " iCoreX ". Properties: MD5 : 832090ba6fe32a3c7c36dbd76f270215 SHA1 :…

PSCrypt ransomware: back in business

PSCrypt is ransomware first discovered last year, in 2017, targeting users and organisations alike in Ukraine, and the malware itself is based on GlobeImposter ("GI") ransomware. I've written about PSCrypt in the past, when it was distributed via Crystal Finance Millenium's hacked website: Crystal Finance Millennium used to spread malware In this quick blog post, we'll take a look at the latest…

Vietnamese ransomware wants you to add credit to a mobile phone

In this quick blog post we'll have a look at BKRansomware, a Vietnamese ransomware that wants you to top up its phone. Update : 2018-05-06, scroll down for the update, added to the conclusion. Analysis This ransomware is named " BKRansomware " based on the file name and debug path. Properties: MD5 : 892da86e60236c5aaf26e5025af02513 SHA1 : 6f36c02161a83a3683921fc73319474157f4fb92 SHA256 :…

Ransomnix ransomware variant encrypts websites

Ransomnix is a (supposedly Jigsaw, but not really) ransomware variant that holds websites for ransom, and encrypts any files associated with the website. This ransomware was discovered in the second half of 2018, and there's a brief write-up by Amigo-A here as well: Ransomnix ransomware In this blog post, we'll discuss a newer variant. Analysis Several encrypted websites were discovered, which…

Satan ransomware adds EternalBlue exploit

Today, MalwareHunterTeam reached out to me about a possible new variant of Satan ransomware. Satan ransomware itself has been around since January 2017 as reported by Bleeping Computer . In this blog post we'll analyse a new version of the infamous Satan ransomware, which since November 2017 has been using the EternalBlue exploit to spread via the network, and consequently encrypt files. Analysis…

This is Spartacus: new ransomware on the block

In this blog post, we'll analyse Spartacus, one of many new ransomware families popping up in 2018. Analysis This instance of Spartacus ransomware has the following properties: MD5 ; 25dee2e70c931f3fa832a5b189117ce8 SHA1 ; a01294ffd541229718948e17f791694efb596123 SHA256 ; ef25bdbcf05fa478df3ddc5f4f717c070e443da04cfc590d44409c815f237cb3 Compilation timestamp : 2018-01-19 20:36:44 VirusTotal report…

CryptoWire ransomware not dead

CryptoWire is an "open-source" ransomware based on the AutoIT scripting language, and has been around since 2016. For some background, read the following post on Bleeping Computer: "Proof of Concept" CryptoWire Ransomware Spawns Lomix and UltraLocker Families I already encountered a CryptoWire variant last year, when it was used to target users in Brazil: Ransomware, fala sério! In this blog post,…

Maktub ransomware: possibly rebranded as Iron

In this post, we'll take a quick look at a possible new ransomware variant, which appears to be the latest version of Maktub ransomware, also known as Maktub Locker. Hasherazade from Malwarebytes has, as per usual, written an excellent blog on Maktub Locker in the past, if you wish to learn more: Maktub Locker – Beautiful And Dangerous Update - 2018-04-14 : Read the conclusion at the end of this…

Fake Steam Desktop Authenticator steals account details

In this blog post, we'll have a quick look at fake versions of Steam Desktop Authenticator (SDA), which is a "desktop implementation of Steam's mobile authenticator app". Lava from SteamRep brought me to the attention of a fake version of SDA floating around, which may be attempting to steal your Steam credentials. Indeed, there are some fake versions - we'll discuss two of them briefly. Fake…

Malware Analysis, Threat Intelligence and Reverse Engineering: workshop slides

Last month I gave a workshop for a group of 20-25 enthusiastic women, all either starting in infosec, or with an interest to start in this field. For that purpose, I had created a full workshop: slides or a presentation introducing the concepts of Malware Analysis, Threat Intelligence and Reverse Engineering. The idea was to convey these topics in a clear and approachable manner, both theory and…