Sign in

Squiblydoo

@squiblydoo.bsky.social
300 followers 199 following 257 posts

Malware Analyst; creator of debloat, certReport, CertCentral.org Debloat Discord: discord.gg/dvGXKaY5qr squiblydoo.blog

PostsRepliesMedia
Squiblydoo @squiblydoo.bsky.social · 17/09/2026
During a fake IT vish targeting Germany, the attackers drop a signed file, currently one signed by "YOUR CHANCE j.d.o.o". The tool pulls the user's name and validates their credentials when entered. Credentials are saved for the attackers. github.security.tele...
010
Squiblydoo @squiblydoo.bsky.social · 01/07/2026
FUD HijackLoader 9c0a88ea53c4e0324157542385a1d342101feb51cf7b8cf76e9441376f1f522a Signature: ELH Palkehituse OÜ C2: web-telegram[.]ug Was disguised as a Franz Messenger installer.
020
Squiblydoo @squiblydoo.bsky.social · 30/06/2026
This is how I like my FUD malware: So many detections that I can't get the engines on the page. 2143baefd0b108fa1f6cfcfa3eb31d87578c6014117768f06bd8544dd02c8adf Signer:"F & P PARTNERS LIMITED" Gets payload from insharedata[.]org/check.php/api/launcher/14/payload?direct=1
000
Squiblydoo @squiblydoo.bsky.social · 27/06/2026
Every time I look at the EV cert "Alabama Technology USA, LLC" I grow less confident it is legit. Used to sign Pulse Browser. "Alabama" company registered through a registered agent in New Mexico. Certificate chain includes a dummy cert (?) Image from pkilab.certgraveyard...
032
Squiblydoo @squiblydoo.bsky.social · 22/06/2026
FUD CastleLoader SHA256: b0a6f7afa4877eab5085d49207e26d1d2461d2d61d71a4d406e81e9f30711c5e C2: goldmanadv[.]com Right now, I open in #malcat, save the CAB file to disk, extract the CAB; ripgrep for the C2. Works but could be better, right? 1/2
100
Squiblydoo @squiblydoo.bsky.social · 08/06/2026
Low detection CastleLoader signed "SOFTWARE ANALYTICS LIMITED": f50f825a64cb9c0435bc11db9225445687f8d1a44dba972a50ffa4dff600e72f They changed from EXE to MSI C2: arqeluno[.]com
000
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
We're seeing these regularly though our monitoring of MalwareBazaar. Bitsight is uploading them when they are observed being dropped by GCleaner. The certificates follow patterns that we are already tracking and seeing be used for malware later. 2/4
100
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
We report certificates for revocation when they sign malware. What about before they sign malware? I've started adding certificates to Cert Graveyard that are being used to "warm" the certificate and improve it's score before being sign malware. 1/4
141
Squiblydoo @squiblydoo.bsky.social · 05/05/2026
For a bit more detail, I ran one of the files through my AI analysis lab and gave it the Kaspersky report: github.com/Squiblydo... Oh hm. I guess a binary randomly having 1 VMProtected section does feel pretty suspicious (Image from malcat.) 2/2
020
Squiblydoo @squiblydoo.bsky.social · 04/05/2026
CryptoCharger/CryptoVisa reaches out to 666777228[.]com which has been used by other payloads too. Notably Signer:"TRUST & SIGN POLAND SP Z O O" 045f583cb7f46ae38ea65fc25d4c7678f306a589ab599dda7d9da404ee91d2f9 which we reported in March 2026. 3/3
000
Squiblydoo @squiblydoo.bsky.social · 04/05/2026
In November "Soft Insanity Oy" received a code-signing certificate from Certum and GoGetSSL. The Certum cert signed CastleLoader, but what about the GoGetSSL? "CryptoChanger.exe" / "node.exe" a54f626f130c36709857215122d6ceb16e5fab7047316afc31a83dfa620cf292 2/3
110
Squiblydoo @squiblydoo.bsky.social · 04/05/2026
FUD #CastleLoader being distributed via malvertizing. 785ba9c42deca8cfc69f1aafb371802782d01bc8156a67c5c0d412c5fb3b4e33 C2: astroflightvision[.]com The signer, "Soft Insanity Oy" led us to find other FUD malware from November. 1/3
121
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
Relatedly, I added functionality to PKILab to extract and highlight the Authenticode Publisher for Windows Hardware drivers. I had hardly noticed these details before, so I'm glad PKILab can make it easy to find. 3/3
000
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
We see so many abused certificates, that we can't dig deep. If ya'll ever want to get in on the front lines of it, be sure to join the Debloat Discord where we monitor and chat about abused certificates. 2/3
100
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
Update to pkilab.certgraveyard... - I originally hadn't planned for the analysis reports to be sharable, but it turned out people liked sharing them. They are now permanent. - Added P7X support, which was omitted by accident
000
Squiblydoo @squiblydoo.bsky.social · 24/04/2026
CertGraveyard's PKI Lab is available now. Want to better understand code-signing certificates? The site allows you to extract and view certificates. The Cert Inspection tool parses out all of the bits and flags anomalies. 1/2
153
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
One recent first stage was signed "Xiamen Xianghe Information Technology Co., Ltd." The second stage consists of the following: NvBackend.exe used the leaked 2018 Nvidia cert. detoured.dll was the Lenovo signed binary. NvBackend.log is a shellcode loader 5/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
The name Zhong Stealer seems to be a misnomer. Based on my analysis, it seems to be a RAT. They send a fake image/screenshot in a phishing email. When ran by a user, it displays a JPEG of an error, and pulls down the second stage from a CDN like AWS. 4/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
These certificates are unlike the other 2,100 we've tracked. They are new certificates issued to existing customers and only used to sign malware. To be clear, they aren't supply chain poisoning. We've seen 12 issued like this, 69 for this same malware: Zhong Stealer 3/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
What do Lenovo, Kingston, Shuttle Inc, and Palit Microsystems have in common? EV Certificates from these companies were issued and used by a Chinese crime group, #GoldenEyeDog (#APT-Q-27)! Thanks @malwrhunterteam and @g0njxa for your contributions 1/7
2123
Squiblydoo @squiblydoo.bsky.social · 19/04/2026
VirusTotal's maximum size is 650MB; potential victims can't upload it there. The certificate has been reported and revoked. A subcomponent of the file was uploaded to VirusTotal: b531ee0e453c6a514daa09a4e7d6e8fae8f433269afba59035d84e68a5ff42a2. MB: bazaar.abuse.ch/samp... 2/2
010
Squiblydoo @squiblydoo.bsky.social · 19/04/2026
AnchorWallet[.]org is fake. The real place to download the wallet is Greymass[.]com. If you download the Windows app from the fake, you get a 680MB remote access tool signed by PIXEL PLAY PRIVATE LIMITED. Not an app signed by Greymass. h/t @malwrhunterteam 1/2
110
Squiblydoo @squiblydoo.bsky.social · 17/04/2026
There is garbage text and then some Python. Highlight the base64. Right-click -> Transform. Cyberchef like interface; base64 decode, change text encoding. "Open in New file" lets us open it in a separate analysis. Theres our C2: fillenmore[.]com bazaar.abuse.ch/samp... 3/3
000
Squiblydoo @squiblydoo.bsky.social · 17/04/2026
Opening it up in malcat, we can see it identified the compressed Nullsoft Installer bits (Image 1). Double clicking unpacks it. We then have new files to look at. A few are .txt files, we can doubleclick to open them. This first one actually happens to be what we want. 2/3
100
Squiblydoo @squiblydoo.bsky.social · 17/04/2026
FUD CastleLoader signed "INFOTECK SOLUTIONS PRIVATE LIMITED" The 40MB exe makes it hard for detection engines to see the 1 important line of python it will execute. Short #malcat investigation though. 62a6e64a7233f4a756d01c54840ff703a620a416929d57eebc0bdac3b9ed2019 1/3
100
Squiblydoo @squiblydoo.bsky.social · 15/04/2026
Orange Cyberdefence recently published their research on SmokedHam. We're glad to see Cert Graveyard and the code-signing certs mentioned. While CertGraveyard tracks the campaigns, we can't investigate them to their full depth (due to capacity), so this is great to see. 1/2
110
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
I don't know how to feel about this domain: maybedontbanplease[.]com What to do? Chat, can you help me out? (CastleLoader 4ba0d3ae41a0ae3143e8c2c3307c24b0d548593f97c79a30c0387b3d62504c31 signed "SERPENTINE SOLAR LIMITED" NSIS -> Python execution -> loads remote resource)
010
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
These are just a small subset of what we track. Over time, we've tracked 91 certificates we associate with Golden eye dog; signing both Zhong Stealer and ValleyRAT. You can get the whole list of certs from CertGraveyard's lookup page. 4/4
000
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
The main malware we're seeing via CertGraveyard is tracked as Zhong Stealer. They host the 2nd stage on legitimate CDN, one of the files they host is a picture of a 505 error this is used as a decoy. 2/4
100
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
Golden Eye Dog (APT-Q-27) seems to have come back from break. We've seen 6 unique EV code-signing certs for campaigns in April already. All of these get reported and all get revoked. More about them in the thread. h/t @g0njxa, @malwrhunterteam 1/4
100
Squiblydoo @squiblydoo.bsky.social · 01/04/2026
The history of BumbleBee's relationship with certificates can be viewed a few ways with CertGraveyard. You can review via a table, a graph, or download the whole database to transform the data yourself. 4/4
031
Squiblydoo @squiblydoo.bsky.social · 01/04/2026
We saw NovaViewer being signed with a new EV certificate "Xiamen Duohanbeiwei Network Co., Ltd". This certificate was reported and revoked before the certificate was used in a BumbleBee campaign. 6d6a861c133ff3e1aa09c8744de52413 Special thanks to @luke92881 and @g0njxa 1/4
110
Squiblydoo @squiblydoo.bsky.social · 26/03/2026
Our database is one of the blocklists used by MagicSword. Files with certificates issued to cybercriminals are actually stopped from impacting systems: whether the cert provider revokes the certificate or not. 6/6
000
Squiblydoo @squiblydoo.bsky.social · 26/03/2026
Our end user downloaded it from a < 30day old domain "im-image[.]ing" and downloaded the file named "MAGE_IM_[94 char here].SCR". (Site and downloads are still active.) MD5: 006a0eb2ae8fa181c7a7ac972055f03f 4/6
100
Squiblydoo @squiblydoo.bsky.social · 26/03/2026
I'm not buying it. The last file reported was disguised as an invoice. The desktop icon displays what looks like a receipt and the metadata claims it is a 2FA login authenticator. 3/6
100
Squiblydoo @squiblydoo.bsky.social · 26/03/2026
The most recent file (eca5383f73e19e587c03a472d0559d95) makes no effort to hide what it is. This suggests the actor convinced the certificate provider that their previous files were legit and the current detection of QuasarRAT is a consequence of using it legitimately. 2/6
100
Squiblydoo @squiblydoo.bsky.social · 26/03/2026
QuasarRAT signed by "北京谷云达吉商贸有限公司" This signer previously signed GhostRAT. Cert was revoked. They received new certificate. Revoked. New certificate. Revoked. If I didn't have a database with records, I'd think I was insane. h/t @malwrhunterteam 1/6
131
Squiblydoo @squiblydoo.bsky.social · 25/03/2026
#Hijackloader "SettlePay - Billing Report.exe" signed by "广州杜倾科技有限公司" 02cbc77d52e12aea6a6c9db36c07d2eccd1af9d39b88b3802b40cb10d088b30c MB: bazaar.abuse[.]ch/sample/02cbc77d52…
000
Squiblydoo @squiblydoo.bsky.social · 24/03/2026
Fake Microsoft Teams, "MTSetup_v15.3.7191.msi" signed by "Tryphena Lewis" 18c5b7a39be2f4a4b2fd45f0f273874f5efcc8751d4e592e5f2bcf6dbf781277 FUD-lite Uploaded to MalwareBazaar here bazaar.abuse[.]ch/sample/18c5b7a39b…
000
Squiblydoo @squiblydoo.bsky.social · 17/03/2026
Reported to CertGraveyard: 143fa9567ebbccacceb58201dd85b7206fdf22882ff2cea0da994a513572f14e signed by "Mann Technologies LLC" Fake Citrix installer, FUD on VirusTotal, installs Zoho Meeting.
110
Squiblydoo @squiblydoo.bsky.social · 03/03/2026
While it already had a high VirusTotal score, it is often unclear to whether it is PUP or malware. Using REMnux MCP helps solve this problem with lower effort from me. See full generated report here: github.com/Squiblydo... 2/2
000
Squiblydoo @squiblydoo.bsky.social · 03/03/2026
"Zipmate.exe" signed by OR KAHOL LTD Cert reported for revocation. MD5: d5d411d61b089d5761838138e7eb484a Hijacks Firefox See REMnux MCP generated report in comment below. Claude opened the .NET using ILSpy and deobfuscated all the crap so I didn't have to. 1/2
100
Squiblydoo @squiblydoo.bsky.social · 03/03/2026
The report isn't perfect (it thought it was a game instead of a PDF editor), however, everything else seems to line up despite poor sandbox execution. The VT score is 22/70, but analysis is needed to prove it isn't PUP. See the full report here: github.com/Squiblydo... 2/2
000
Squiblydoo @squiblydoo.bsky.social · 03/03/2026
"NotAWord.exe" signed "Astro Bright LTD" MD5: 7be1f9a968c5b1567570e12738392d7c Yet Another PDF Application (YAPA) App contains reversed and chunked domains. I'm now using Remnux MCP to generate reports for these apps and confirming the findings. 1/2
110
Squiblydoo @squiblydoo.bsky.social · 27/02/2026
Ah yes, "Hubei Da'e Zhidao Food Technology Co., Ltd." is well known for their Google Chrome product. Valid cert. Will trust. 099d63e692457bfccc2cf59278ae6a268cb03964f18d0d27f536027b43c89896 h/t @g0njxa
020
Squiblydoo @squiblydoo.bsky.social · 24/02/2026
"CaseArchiveViewer.exe" signed with "Flagship Promotion s. r. o." EV cert. Flagged for deploying NetSupport RAT and Vidar 8099e85c4aa05f50ff299a130dc26a67b45aed519668e8b1ee1692e0034196c2 Certificate reported. tria[.]ge/260223-z2lj3abx8f/behavio… h/t MalwareHunterTeam
010
Squiblydoo @squiblydoo.bsky.social · 22/02/2026
See the YARA rule here (it has Claude's annotations): github.com/Squiblydo... Samples on MalwareBazaar: bazaar.abuse.ch/brow... 5/5
000
Squiblydoo @squiblydoo.bsky.social · 22/02/2026
I then performed a YARA hunt using @unpacme to check my rule. It hit 40 samples, which are ones I uploaded to MalwareBazaar. Nice. 4/5
100
Squiblydoo @squiblydoo.bsky.social · 22/02/2026
I let Claude know my intent to create a YARA rule based on the results, and it created one for me. The rule actually didn't work right away, but it gave me plenty to go off of. With malcat, I can also see the bytes in the executable by clicking the rule match 3/5
100
Squiblydoo @squiblydoo.bsky.social · 22/02/2026
The MCP has access to all the tools installed on REMnux. I tried a few YARA rules based on manual analysis, but no easy wins. But since it was able to find the encrypted payload and then extract the payload using emulation (Speakeasy), I used that for the rule 2/5
100