0xlibris

infosec drama

2025-05-21

I ended an article a couple of months ago with:
> I may analyze the final payload in a future post.

And finally the day has come.
Spoiler: it was not the final payload.

Dissecting PureCrypter: A Technical Malware Analysis
0xlibris.net/posts/infection_c

#PureCrypter #malware #infosec #reversing #cybersecurity #infostealer #malwareanalysis

dnspy screenshot of the main function of PureCrypter, a .NET-based loader malware. It shows functions like bypass_amsi, setup_persistence, or run_loader among others.
2025-05-18

Is like postponing another hour the time to go to sleep

2025-05-18

An expired vm that restarts every hour is the only notion of time

2025-05-10

Yet Another Ridiculous headAche

2025-05-10

I'm pretty good at identifying types of headaches

0xlibris boosted:
eri :floofMischief:eri@mk.moth.zone
2025-04-01

why does like half of all @vncresolver@fedi.computernewb.com screenshots look like this

a bunch of random factory elements and video game GUI parts edited together haphazardly
2025-03-31

Paranoia level like: receive a message from a random person on Telegram saying Hi without context and automatically block and reboot the phone

0xlibris boosted:
Foone🏳️‍⚧️foone@digipres.club
2025-03-27

on a day with no ADHD meds, my roommate knocks on the door and is like "a friend got their discord hacked but before I knew it they sent me an EXE and I ran it. am I hacked?"

2025-03-26

@JohnHammond I gave up reversing the obfuscated .net binary too :ageblobcat:

0xlibris boosted:
2025-03-26

An MP3 file as malware!?! Actually an HTA polyglot -- with some clever error handling tricks, slick PowerShell sub sessions, and an annoyingly obfuscated C# .NET assembly across like seven stages of payloads. The song has a good beat, too! youtu.be/25NvCdFSkA4

2025-03-26

@JohnHammond lol it's the same campaign I analyzed a couple of weeks ago
0xlibris.net/posts/infection_c

2025-03-18

@mixic Thx! Gimme more layers :ablobcatnomcookie:

2025-03-11

At this point, all WordPress sites are just cdns for malware distribution, right?

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst