f0wL

854 posts

f0wL banner
f0wL

f0wL

@f0wlsec

REsearch/DFIR @SI_FalconTeam

Katılım Temmuz 2018
2.2K Takip Edilen3K Takipçiler
f0wL
f0wL@f0wlsec·
@jamieantisocial @_mattata I agree with Remy. One additional nuance: Removing traces of Exfil makes it harder for IR folks to determine ad-hoc which and how much data was taken. Most orgs don’t have Zeek or Sysmon data to refer to. This may influence the victim orgs decision whether to pay (👎) or not.
English
0
1
2
453
f0wL
f0wL@f0wlsec·
@evstykas Dang, that sucks :( With your track record and this title, I would find it hard to pass up. Might be a good fit for the @CYBERWARCON CFP? 👀
English
1
0
3
1.8K
Vangelis tix Stykas
Vangelis tix Stykas@evstykas·
Unfortunately 1500 hours of research was not enough to get accepted on defcon or black hat this year…
Vangelis tix Stykas tweet media
English
11
7
215
24.7K
f0wL retweetledi
SECUINFRA FALCON TEAM
SECUINFRA FALCON TEAM@SI_FalconTeam·
☑️#ClickFix / Fake Captchas posing as Cloudflare Verification pages We stumbled upon a web page that closely resembles Cloudfare's Anti-DoS Verification pages. Upon clicking the verification button, the familiar ClickFix verification dialogue is presented. 1/7🧵
GIF
English
2
2
7
2.1K
f0wL
f0wL@f0wlsec·
meme.png
f0wL tweet media
Indonesia
8
135
1.7K
50.6K
Alexander Leslie
Alexander Leslie@aejleslie·
🇷🇺 🇩🇪 - New @RecordedFuture report! This report examines malign influence operations linked to Russia and Russia-based actors (e.g. Doppelgänger, Operation Overload, CopyCop, Operation Undercut) ahead of the upcoming German elections. Blog: recordedfuture.com/research/stimm…
Alexander Leslie tweet media
English
3
11
32
3.4K
f0wL retweetledi
SECUINFRA FALCON TEAM
SECUINFRA FALCON TEAM@SI_FalconTeam·
🚨Malware distributed via Steam Fancy a bit of after work gaming? Beware of infostealer malware distributed via the Steam store! Using @steamdb we managed to visually identify a very suspicious file in the game files. Luckily, we managed to retrieve a sample for analysis, which will follow in this thread.
SECUINFRA FALCON TEAM tweet media
SteamDB@SteamDB

A game called PirateFi released on Steam last week and it contained malware. Valve have removed the game two days ago. Users that played the game have received the following email:

English
1
24
90
19.2K
f0wL
f0wL@f0wlsec·
@cyb3rops That list is very long these days… Fortinet? SonicWall? Citrix?
GIF
English
2
1
13
1.3K
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
During the initial meeting with a customer on an IR case, if they mention they don’t know the threat actor’s entry vector, ask if they own an Ivanti device. If they ask why, simply tell them they’ll find out soon. While it’s not guaranteed that this is the actual entry vector, they’ll be impressed if your guess turns out to be correct.
CISA Cyber@CISACyber

#Ivanti released security updates to address CVE-2025-0282—being actively exploited—and CVE-2025-0283, affecting Connect Secure, Policy Secure, and ZTA Gateways. See our Alert for mitigation guidance to help reduce your exposure: bit.ly/4fYrMqQ

English
9
47
239
41.9K
f0wL retweetledi
Anthony Bourdain Fan Club
Anthony Bourdain Fan Club@BourdainFanClub·
Happy new year! Where are you planning to travel this year? What are you planning to eat?
Anthony Bourdain Fan Club tweet media
English
0
5
73
3.3K
f0wL
f0wL@f0wlsec·
@d4rksystem Thanks 😃 It’s an Ooni Kona propane oven
English
0
0
1
93
Kyle Cucci
Kyle Cucci@d4rksystem·
@f0wlsec Nice. What kind of stove/oven is that?
English
1
0
0
176
f0wL
f0wL@f0wlsec·
I cooka da pizza 🍕 2024+1 edition
f0wL tweet media
English
2
0
9
951
vx-underground
vx-underground@vxunderground·
> get call at 10pm > weird long number > answer > people speaking Mandarin > ??? > they say theyre from alibaba > ask how vx-underground is going > tell them its 10pm > "is that a problem?" > tell them we stopped using alibaba > "is that a problem?" > mfw
vx-underground tweet media
English
20
22
824
29K
Myrtus
Myrtus@Myrtus0x0·
wrote a quick disassembler for some bytecode I've been analyzing. Wasn't too bad. But taking that understanding and turning it into a full VM is quite a bit more difficult 😅. Have restarted 5 times so far due to not being happy with how I've attempted to replicate.
English
1
0
25
2K
J⩜⃝mie Williams
J⩜⃝mie Williams@jamieantisocial·
hear me out.... Wine grape varietals would be an EXCELLENT naming convention for TAs 🤌🍇
J⩜⃝mie Williams tweet media
English
5
3
27
4.1K