22 Followers
9 Following
12 Posts
admin. windows, linux. cybersecurity and open source enthusiast.
@Gargron done!
@Gargron or will it be closed and I should submit on huntr.dev?
@Gargron alright, thanks for checking. any ETA?
@Gargron it seems to open/suspend every other day, even had the status „closing“ yesterday
@Gargron it‘s still suspended
@Gargron I found a bug but can't report via intigriti, what's up with the program?
@seb oops, yes, to your toot about mastodon administration
i‘m thinking about hosting one but mailing cost made me not to. what do you use?
i‘m interested in collaborating on cybersecurity projects / threat research / etc. hit me up!
#emotet now uses #powershell commands in .lnk files, the string is obfuscated with nulls/blank spaces so the target is not shown
some #Indicatorofcompromise #ioc :
- .ps1 files in %tmp%
- focusmedica[.]in
- demo34[.]ckg[.]hk
- colegiounamuno[.]es
- cipro[.]mx
- filmmogzivota[.]rs
- creemo[.]pl
command for checking %tmp%:
 dir C:\users\%username%\AppData\Local\Temp\*.ps1