![Squiblydoo Profile](https://pbs.twimg.com/profile_images/1454647931831832577/rDgfQlxf_x96.png)
Squiblydoo
@SquiblydooBlog
Followers
3K
Following
6K
Statuses
725
Malware Analysis (mostly SolarMarker) Creator of Debloat and certReport Want to chat? Join the Debloat discord: https://t.co/ZcWIqa6ZA9
Joined November 2020
@JAMESWT_MHT @salmanvsf @1ZRR4H @VirITeXplorer @marsomx_ @ffforward @0xToxin @Max_Mal_ @pr0xylife @guelfoweb @malwrhunterteam @AndreaDraghetti Thank you for your report. The code-signing certificate has been reported.
0
0
5
@malwrhunterteam @globalsign Certificate has been reported for revocation. Thank you for the report.
0
0
4
@smica83 @malwrhunterteam Awesome. Thanks for the tag. The certificate has been reported for abuse.
0
0
1
RT @SquiblydooBlog: @g0njxa @deepseek_ai Thanks for the tag, the certificate has been reported. Apparently DeepSeek and OpenAI aren't mad…
0
4
0
@g0njxa @deepseek_ai Thanks for the tag, the certificate has been reported. Apparently DeepSeek and OpenAI aren't made by a Vietnamese construction company. Who knew? Currently low detection. @JAMESWT_MHT @malwrhunterteam
4
4
13
@malcat4ever @smica83 Nice. Thanks for digging into it. Posting the IPs for convenience for others but there are some domains in there for anyone interested (see image). 216.245.184.181 212.237.217.182 168.119.96.41 @johnk3r for vis, looks like you both were digging in at the same time.
0
0
4
I am working on a public platform to make it even easier for people to report code-signing certificates. My goal is to continue to raise awareness on the abuse and the impact revocation has on malware distributors. Keep an eye on my socials for more news.
This is what happens when you revoke certs on malware builds and report the builds distribution system, like @SquiblydooBlog does Temporary but complete disruption of the malware campaign Welcome to the "NoLog January" Challenge 😃
1
7
38
@JAMESWT_MHT @500mk500 @guelfoweb @James_inthe_box @AndreaDraghetti @ffforward @VirITeXplorer @0xToxin @pr0xylife @RussianPanda9xx @c_APT_ure @Max_Mal_ Certificate "MANH THAO NGUYEN COMPANY LIMITED" has been reported. Thanks for tagging me.
0
1
6
Signer "DRSSOFT INC" is pushing a lot of fake meeting software. Teams, Wechat, Zoom, etc RemcosRAT 185.42.12.75, 90MB "calc" 🥲 Their files use a CloudFlare CAPTCHA before unpacking.
wechat[.]com[.]do/en/meeting-48IHQ8 deliverycloudnetwork[.]com WeChat Launcher[.]exe : 72b53da3b8596ea64041a541fcb4fca3b5b10b1ff16adb0f2bf115ed796d7549 185[.]193[.]126[.]8 AS39287 ab stract ltd 🇫🇮 @Weixin_WeChat #apt
1
9
35
@skocherhan @Weixin_WeChat Why do you say "APT"? I reviewed the other files from this code-signer "DRSSOFT INC" and have reported it for revocation. Their files all show a CAPTCHA, which may account for the low VT score. At least one was RemcosRat: 185.42.12.75
2
3
13
@smica83 @abuse_ch @JAMESWT_MHT Thanks for your report. The certificate has been reported for revocation.
0
1
4
@smica83 @abuse_ch @JAMESWT_MHT Thanks for tagging me. The certificate has been reported for revocation.
0
0
2
@smica83 @abuse_ch @JAMESWT_MHT Thanks for tagging me. The certificate has been reported for revocation.
0
0
3
@dez_ Nice. Definitely an interesting attack technique. And you reported the code-signing cert, right? 😉 cc. @JAMESWT_MHT @malwrhunterteam
0
0
5