Skip to content

khairulazam.net

Just my simple blog.

khairulazam.net

Just my simple blog.

  • Home
  • About Me
  • Hall of Shame
Analysis Write-Ups

From ClickFix/ClickVerify to Lumma Stealer – The Rise of Self-Pwn Techniques

zam 26/08/2024 No Comments

Recently, we observed a high number of users been infected by Lumma Stealer. Upon investigating, we observed that the user been infected thru same vector; “Clickfix” infection chain. The attack…

Analysis Write-Ups

Malcore.io Challenge – Stacy

zam 19/08/2024 No Comments

The Challenger Recently Malcore.io post at X/Twitter a reversing challenges. The is related to script that is hosted here – https://raw.githubusercontent.com/Internet-2-0/file-samples/master/scripts/powershell/stacy.ps1 Dive! Dive! Dive! At first glance, we saw what…

Analysis Write-Ups

Deobfuscating Malicious PowerShell Script – ClickFix PowerShell

zam 14/08/2024 No Comments

Dealing with obfuscated scripts is an everyday challenge as an Incident Handler/Responder. These scripts, often looks like gibberish/unrecognize strings is actually codes wrapped in layers of encryption and obfuscation, aim…

Analysis Write-Ups

Deobfuscating PHP Webshell

zam 09/05/2024 No Comments

It started with a person in one of Telegram group that I’ve joined; asking help to reverse the code given & explains what the code does. The code as follow:…

Cybersecurity

Wargames.MY 2023 CTF – Compromised

zam 17/12/2023 No Comments

As usual, start your CTF by read the question/description that indeed “very helpful” XD Download the “evidence.zip” & extract it. You’ll get the folders like below: So I randomly checked…

Cybersecurity

Wargames.MY 2023 CTF – SeeYou

zam 17/12/2023 No Comments

As usual, real the description given. It says that “a file” been “transferred” to another “internal computer“. So we know that this might involving traffic between 2 internal IPs. Download…

Analysis Write-Ups

Extracting Quarantine Files from Windows Defender

zam 12/12/2023 1 Comment

Recently, I got an incident related to Windows Defender detected & quarantined file related to some backdoor. The MDE alert details show something like this: Usually, we go with the…

Analysis Write-Ups

Interesting Request – Log4J JNDI Exploit

zam 08/08/2023 No Comments

Recently, I saw a person asking question on one of Telegram group that I’ve joined. The person said that if anyone know what kind of request is this. The person…

Analysis Write-Ups

Decrypting QBot/QakBot Registry

zam 03/10/2022 No Comments

Recently, we have host machine that been infected with QBot/QakBot. Upon investigation, we found that it added a registry with some random name. Based on Googling, I found this article…

Analysis Write-Ups

Windows Credentials Manager – Looking for cached Zip Passwords

zam 23/03/2022 No Comments

Intro When you open a password protected zip archive using Windows Explorer (“Extract All…”); in Windows 8.x/10, the password is automatically cached in the Credentials Manager for the life of…

Posts pagination

1 2 … 13

Ads

Recent Posts

  • From ClickFix/ClickVerify to Lumma Stealer – The Rise of Self-Pwn Techniques
  • Malcore.io Challenge – Stacy
  • Deobfuscating Malicious PowerShell Script – ClickFix PowerShell
  • Deobfuscating PHP Webshell
  • Wargames.MY 2023 CTF – Compromised

Recent Comments

  • Marnik on Extracting Quarantine Files from Windows Defender
  • Hunting for Log4j RCE (CVE-2021-44228) using RSA Netwitness | khairulazam.net on Hunting for Log4j RCE (CVE-2021-44228) using Splunk & Excel
  • Rickk on Wifi Pineapple Mark V MR3020 – Bypass verify_pineapple LED pattern
  • Joe the hash cat on Extracting password from data leaks dump files
  • Lakshminarayanan Sethumadhavan on Recover bricked TL-MR3020 via serial console

Archives

Tags

analysis apache apple bash bsd coding configure ctf cygwin debian firewall forensic hack hackthebox honeypot hunting ios linux logfile macos malware metasploit microsoft mongo mybb mysql network&hacking nginx opensource openvz openwrt pcap perl pineapple powershell pwn python ssh tplink ubuntu vmware vps windows wireshark wordpress

Categories

Analysis Write-Ups Cybersecurity Offensive Tutorials

khairulazam.net

Just my simple blog.

Copyright © All rights reserved | Blogus by Themeansar.