@_FirehaK Profile picture

Stephan (@[email protected])

@_FirehaK

Malware reverse engineer, Cryptolaemus member Mastodon: @[email protected]

Similar User
Squiblydoo photo

@SquiblydooBlog

Myrtus photo

@Myrtus0x0

Max_Malyutin photo

@Max_Mal_

Bryce photo

@bryceabdo

CAPE Sandbox photo

@CapeSandbox

Fred HK photo

@fr3dhk

Zach photo

@svch0st

tooManyOpenThreats photo

@9823f_

sysopfb photo

@sysopfb

The Haag™ photo

@M_haggis

avallach (@xorhex@infosec.exchange) photo

@xorhex

Assetnote photo

@assetnote

Corsin Camichel 🌻 photo

@cocaman

herm1t photo

@vx_herm1t

dao ming si photo

@dms1899

Pinned

I finally did a thing and put some #YARA rules in a public GitHub repository now that some of the ransomware I looked at is no longer relevant. Hope to do more and add an eventual analysis repo one day as well. Check it out! github.com/FirehaK/YARA


Stephan (@[email protected]) Reposted

We've preserved (yet another) lot of eleven test cartridges for the Nintendo DS, DSi, and 3DS! Included are some never-before-seen pieces of test software, as well as new versions of previously discovered ones! Thanks to those who contributed: March42, Kc57, Haifisch, and XX_75.

Tweet Image 1
Tweet Image 2
Tweet Image 3

Stephan (@[email protected]) Reposted

Check out my latest blog post about Cova loader and Nosu stealer. These two went unnoticed... but only until now :) bitsight.com/blog/cova-and-…


Wish I knew why my @analogue pocket order has been "processing" at the fullment partner for more than a month now while others who have ordered at the exact same time have gotten theirs a while ago now 😔


Stephan (@[email protected]) Reposted

The whole neighborhood comes outside to watch when a house is burning down

And … we just hit another all-time high in Twitter usage lol



Stephan (@[email protected]) Reposted

Everyone: Signs in every day to watch Elon slowly running Twitter into the ground. Elon:

Tweet Image 1

Stephan (@[email protected]) Reposted

Bankrupting Twitter is not an eligible run submission for the second submission period.


Stephan (@[email protected]) Reposted

I've joined the cool kids club @Kc57@infosec.exchange Leave your handle below 👇 #mastodonmigration #Mastodon


Stephan (@[email protected]) Reposted

We are also hunting mealybugs(emotet) and other crimeware actors on Mastodon. Come say hello and give us more things to eat. infosec.exchange/@cryptolaemus


Stephan (@[email protected]) Reposted

Any infosec professional will tell you the greatest threat to security is speed. The fact Elon is pressuring Twitter engineers to roll out his new verification system in 10 days, to meet his day before the election deadline—under threat of firing— is about as bad as this gets.


Stephan (@[email protected]) Reposted

Main concern w/ the new Twitter Blue offering is the verified logo has been a marker of trust I.e., “we’ve confirmed the person is who they say they are.” Now it’s “we’re taking their $ & their word for it.” On the cusp of election where source of info is critical, a major risk.

To think that simple payment verifying will pose any sort of meaningful barrier to sophisticated actors on the platform is just not anchored in reality. Agree w/ @ianbremmer



Stephan (@[email protected]) Reposted

To think that simple payment verifying will pose any sort of meaningful barrier to sophisticated actors on the platform is just not anchored in reality. Agree w/ @ianbremmer

russian govt buying a few thousand verified twitter accounts at $8/pop to promote disinfo feels like a no-brainer.



Not if I don't subscribe it won't 😂

Trash me all day, but it’ll cost $8



Stephan (@[email protected]) Reposted

You can self-host a Mastodon server


Thanks Pokémon Red and @_Kc57 😉

Video games are a gateway drug to hacking, reverse engineering, and malware development



Stephan (@[email protected]) Reposted

Reminder: We are constantly pushing new C2s/Distro URLs/Payload URL/samples to the abuse.ch ecosystem. Please see our submissions at bazaar.abuse.ch feodotracker.abuse.ch threatfox.abuse.ch urlhaus.abuse.ch for more details and info.


Stephan (@[email protected]) Reposted

We have been busy and improved MalwareBazaar's archive parsing 🆕⬇️ The password of PW protected archives is now guessed from the tag list provided 🔐 E.g.: 👉 bazaar.abuse.ch/sample/ddfdea4… We have also implemented a feature to de-pump pumped files 📄 E.g.: 👉 bazaar.abuse.ch/sample/0819fa0…

Tweet Image 1
Tweet Image 2

Stephan (@[email protected]) Reposted

Okay, so a few people have asked how you spot the where your Trust Thermocline is, and how to avoid hitting it. I'll give you the same answer I give senior execs: I don't know. But the people working on the ground level in the customer-facing sections of your company do. /1

There's a large and obvious risk Elon will screw up and wreck twitter. But how actionable is this information in general? If the tipping point isn't obvious and there are few signs of trouble before reaching it, how can companies avoid it?



Stephan (@[email protected]) Reposted

One of the things I occasionally get paid to do by companies/execs is to tell them why everything seemed to SUDDENLY go wrong, and subs/readers dropped like a stone. So, with everything going on at Twitter rn, time for a thread about the Trust Thermocline /1


Loading...

Something went wrong.


Something went wrong.