SquiblydooBlog Profile Banner
Squiblydoo Profile
Squiblydoo

@SquiblydooBlog

Followers
3K
Following
6K
Statuses
725

Malware Analysis (mostly SolarMarker) Creator of Debloat and certReport Want to chat? Join the Debloat discord: https://t.co/ZcWIqa6ZA9

Joined November 2020
Don't wanna be here? Send us removal request.
@SquiblydooBlog
Squiblydoo
3 years
Why, hello there, #solarmarker.
Tweet media one
5
19
107
@SquiblydooBlog
Squiblydoo
2 hours
Website: certReport has been updated to 3.2: you can use an API key and "-p" to submit reports to the database. Read more here: We can handle submitting your reports too. See the website for more details. :)
0
0
0
@SquiblydooBlog
Squiblydoo
2 days
@JAMESWT_MHT @salmanvsf @1ZRR4H @VirITeXplorer @marsomx_ @ffforward @0xToxin @Max_Mal_ @pr0xylife @guelfoweb @malwrhunterteam @AndreaDraghetti Thank you for your report. The code-signing certificate has been reported.
0
0
5
@SquiblydooBlog
Squiblydoo
3 days
@malwrhunterteam @globalsign Certificate has been reported for revocation. Thank you for the report.
0
0
4
@SquiblydooBlog
Squiblydoo
11 days
@smica83 @malwrhunterteam Awesome. Thanks for the tag. The certificate has been reported for abuse.
0
0
1
@SquiblydooBlog
Squiblydoo
13 days
RT @SquiblydooBlog: @g0njxa @deepseek_ai Thanks for the tag, the certificate has been reported. Apparently DeepSeek and OpenAI aren't mad…
0
4
0
@SquiblydooBlog
Squiblydoo
13 days
@g0njxa @deepseek_ai Thanks for the tag, the certificate has been reported. Apparently DeepSeek and OpenAI aren't made by a Vietnamese construction company. Who knew? Currently low detection. @JAMESWT_MHT @malwrhunterteam
Tweet media one
Tweet media two
4
4
13
@SquiblydooBlog
Squiblydoo
13 days
@malcat4ever @smica83 Nice. Thanks for digging into it. Posting the IPs for convenience for others but there are some domains in there for anyone interested (see image). 216.245.184.181 212.237.217.182 168.119.96.41 @johnk3r for vis, looks like you both were digging in at the same time.
Tweet media one
0
0
4
@SquiblydooBlog
Squiblydoo
13 days
I am working on a public platform to make it even easier for people to report code-signing certificates. My goal is to continue to raise awareness on the abuse and the impact revocation has on malware distributors. Keep an eye on my socials for more news.
@g0njxa
Who said what?
13 days
This is what happens when you revoke certs on malware builds and report the builds distribution system, like @SquiblydooBlog does Temporary but complete disruption of the malware campaign Welcome to the "NoLog January" Challenge 😃
Tweet media one
Tweet media two
Tweet media three
1
7
38
@SquiblydooBlog
Squiblydoo
13 days
@JAMESWT_MHT @500mk500 @guelfoweb @James_inthe_box @AndreaDraghetti @ffforward @VirITeXplorer @0xToxin @pr0xylife @RussianPanda9xx @c_APT_ure @Max_Mal_ Certificate "MANH THAO NGUYEN COMPANY LIMITED" has been reported. Thanks for tagging me.
0
1
6
@SquiblydooBlog
Squiblydoo
14 days
#Signed #Reported "44.211.848 NICOLAS SAMUEL DE ALMEIDA" Fake Open AI Sora downloads. User receives file "video_for_you.mp4 - openai\.com" You always know it is going to be a special time when the VT comments are stories.
Tweet media one
0
4
13
@SquiblydooBlog
Squiblydoo
14 days
Signer "DRSSOFT INC" is pushing a lot of fake meeting software. Teams, Wechat, Zoom, etc RemcosRAT 185.42.12.75, 90MB "calc" 🥲 Their files use a CloudFlare CAPTCHA before unpacking.
Tweet media one
@skocherhan
ܛܔܔܔܛܔܛܔܛ
15 days
wechat[.]com[.]do/en/meeting-48IHQ8 deliverycloudnetwork[.]com WeChat Launcher[.]exe : 72b53da3b8596ea64041a541fcb4fca3b5b10b1ff16adb0f2bf115ed796d7549 185[.]193[.]126[.]8 AS39287 ab stract ltd 🇫🇮 @Weixin_WeChat #apt
Tweet media one
1
9
35
@SquiblydooBlog
Squiblydoo
14 days
@skocherhan @Weixin_WeChat Why do you say "APT"? I reviewed the other files from this code-signer "DRSSOFT INC" and have reported it for revocation. Their files all show a CAPTCHA, which may account for the low VT score. At least one was RemcosRat: 185.42.12.75
Tweet media one
2
3
13
@SquiblydooBlog
Squiblydoo
15 days
Anyone know what is up with the stealers that someone keep uploading as "random[#]"? #Signed PREMERA LLC #Reported Talks with telegram, installs netsupport, flagged as "RustyStealer"
Tweet media one
1
6
22
@SquiblydooBlog
Squiblydoo
16 days
@smica83 @abuse_ch @JAMESWT_MHT Thanks for your report. The certificate has been reported for revocation.
0
1
4
@SquiblydooBlog
Squiblydoo
17 days
@smica83 @abuse_ch @JAMESWT_MHT Thanks for tagging me. The certificate has been reported for revocation.
0
0
2
@SquiblydooBlog
Squiblydoo
17 days
@smica83 @abuse_ch @JAMESWT_MHT Thanks for tagging me. The certificate has been reported for revocation.
0
0
3
@SquiblydooBlog
Squiblydoo
20 days
Low detection CobaltStrike masquerading as MS_Teams installer. Connects to C2: 217.148.142.17 #Signed "ANALYZER ENTERPRISES LLP" #Reported
Tweet media one
Tweet media two
1
13
41
@SquiblydooBlog
Squiblydoo
21 days
@dez_ Nice. Definitely an interesting attack technique. And you reported the code-signing cert, right? 😉 cc. @JAMESWT_MHT @malwrhunterteam
0
0
5