![neeraj Profile](https://pbs.twimg.com/profile_images/1850421914541719552/daG513IG_x96.jpg)
neeraj
@knight0x07
Followers
1K
Following
99
Statuses
182
Security Researcher | Malware Loving Homo Sapien | I do xchg eax,eax | Tweets are my own
Hell
Joined March 2019
Wanna analyze Malicious #OneNote documents? Check out my new C# based tool "OneNoteAnalyzer" for analyzing malicious OneNote documents Link: #malwareanalysis #reverseengineering #threathunting #infosec #cybersecurity #threatintel #threathunt #malware
2
72
206
Initial infection chain of the new #Lazarus Willo Video Interview campaign is outlined in detail within the infographic Releasing an in-depth blog abt the campaign soon. Happy New Year! @banthisguy9349
#cyber #dfir #infosec #cybersecurity #malware #threatintel #cti #dprk #apt
3
28
103
@banthisguy9349 @cyberwar_15 @Cyber0verload @Gi7w0rm @0xmh1 @StrikeReadyLabs @TuringAlex @RakeshKrish12 @k3yp0d @Jane_0sint @RexorVc0 @byrne_emmy12099 @suyog41 @lontze7 @bofheaded Thankyou so much this means a lot :) Love your research as well! Cheers
1
0
2
#APT maldoc utilizes TryCloudFlare to download a LNK, which loads a Rust-based DLL backdoor via rundll32, the backdoor then leverages VSCode Remote Tunnel for gaining remote access to the compromised machine #cyber #dfir #infosec #cybersecurity #malware #threatintel #cti
1
49
114
The persistent #XSS vuln (CVE-2023-43770) I reported in RoundCube was successfully exploiting by #APT28 💀 Anybody having the XSS payload please send it across =) #cyber #dfir #infosec #informationsecurity #cybersecurity #malware #threatintel #cti
0
2
5
Identified additional #BlackSuit #Ransomware related #CobaltStrike infrastructure based on the recent @TheDFIRReport report. Infra: #dfir #cyber #infosec #informationsecurity #cybersecurity #malware #threatintel #cti
0
13
52
A PoC video demonstrating the use of TryCloudflare reverse proxy tunnel, which is abused by TAs globally in recent campaigns to conceal their C2 servers, distribute payloads and more. #cyber #redteam #dfir #infosec #informationsecurity #cybersecurity #malware #threatintel #cti
4
4
18
#Kimsuky employs anti-forensics by deleting the PowerShell "ConsoleHost_history.txt" file which stores the PS console command history. #apt #apt43 #cyber #dfir #infosec #cybersecurity #malware #threatintel #cti #malwareanalysis #malwareresearch #threathunting
0
1
9
Wrote a PoC for OnMouseMove #HTML file used in the #Russian #APT group campaign targeting Ukraine. A classic Anti-Sandbox technique =) #apt #cyber #dfir #infosec
#cybersecurity #malware #threatintel #cyberthreatintelligence #cti #malwareanalysis
0
10
33
Forest Blizzard (#APT28) GooseEgg's help command. Use the command line arguments "-?" or "--help" #APT #GooseEgg #cyber #dfir #infosec #cybersecurity #malware #threatintel #russia #security #cyberthreatintelligence #cti #malwareanalysis #malwareresearch #threathunting
1
3
21
Forest Blizzard's (#APT28) GooseEgg batch script dumps SAM and LSA secrets, it also contains a remark indicating future script updates might include #LSASS Dumping. #apt #cyber #dfir #infosec
#cybersecurity #malware #threatintel #cyberthreatintelligence #cti #malwareanalysis
3
14
37
Legitimate binaries patched with #ArguePatch loader by #Sandworm aka #APT44 Patched func vs Original func shown in image. #cyber #dfir #infosec #apt #intel #cybersecurity #malware #threatintel #cti #malwareanalysis #malwareresearch #threathunting #reverseengineering #analysis
8
7
22
The tool I developed to analyze #OneNote documents - "OneNoteAnalyzer" is now a part of the #Flare VM. Flare VM: GitHub: #cyber #dfir #infosec #cybersecurity #malware #threatintel #malwareanalysis #malwareresearch #threathunting
1
4
30
RT @RustyNoob619: #100DaysofYARA Day87: Detecting OCEANMAP Backdoor used by Russian APT28 Checkout @knight0x07 Te…
0
20
0
Analyzed the #Kimsuky PowerShell Backdoor & published the commented enum detailing the backdoor commands & few notes. Link: #APT #APT43 #cyber #dfir #infosec #cybersecurity #malware #threatintel #cti #malwareanalysis #malwareresearch #threathunting
2
11
39