![MalasadaTech Profile](https://pbs.twimg.com/profile_images/1837743700224757764/yzPXFuCP_x96.jpg)
MalasadaTech
@MalasadaTech
Followers
36
Following
261
Statuses
214
Aloha World! This is my "Independent Researcher" persona. I post about things that I enjoy researching during my personal time. Views are my own...
808
Joined September 2024
RT @SquiblydooBlog: Cert Central .org is live! We track and report abused code-signing certs. By submitting to the website, you contribute…
0
28
0
That TA2726 popped out. I took a look. The domain newgoodfoodmarket[.]com uses the IP (185.218.137[.]129) that the domains blacksaltys[.]com and packedbrick[.]com used. Those were previously tracked as Keitaro TDS. Just in case anyone else was wondering.
66 new OPEN, 95 new PRO (66 + 29) Lumma Stealer, TA2726, LandUpdate808, Soc Gholish, ZPHP, CVE-CVE-2025-0626, 2024-45607, 2024-57727, 2024-37397 and more.
0
0
1
Last year's SLEUTHCON was great! Looking forward to this next one!
📆 IT’S CRIME TIME! #SLEUTHCON is coming to Arlington, VA on Friday, June 6th, 2025! 🎉 Stay tuned for more information.
0
1
2
@emilstahl @craiu Concur, a lot of the time you can find other unique properties that can be used to attribute to an actor.
0
0
3
Very cool, repeatable workflow to find associated infrastructure!
🤠Hunting #Tycoon2FA Infra with BurpSuite, @ValidinLLC & @virustotal: 1️⃣ Intercept the POST request in BurpSuite to identify the domain storing credentials. 2️⃣ Use Validin to retrieve the mail.<domain> banner hash, revealing server fingerprints. 🧵1/2
0
0
0
RT @RecordedFuture: TAG-124 is an advanced Traffic Distribution System (TDS) linked to Rhysida ransomware, Interlock ransomware, SocGholish…
0
5
0
Feeling super stoked to have my most recent LandUpdate808 analysis referenced in @RecordedFuture's research! Thanks!
0
0
3
RT @Gi7w0rm: Released my new blogpost: "A beginner(s) guide to hunting web-based credit card skimmers" My experience on how to detect and a…
0
80
0
Howzit! Very nice guide! Thanks for sharing! I've got a bunch of questions about your use with Claude if you have time. For the websocket client, about how long did it take you to get a working solution from Claude? Did it take a lot of tweaking? Do you use Claude as a plugin in an IDE or are you using the regular prompt?
1
0
1