SquiblydooBlog's profile picture. Malware Analysis
Creator of Debloat, certReport, and http://CertCentral.org
Want to chat? Join the Debloat discord: http://discord.gg/dvGXKaY5qr

Squiblydoo

@SquiblydooBlog

Malware Analysis Creator of Debloat, certReport, and http://CertCentral.org Want to chat? Join the Debloat discord: http://discord.gg/dvGXKaY5qr

I got to demo MalBeacon's DeceptionPro and love it. Summary: "DeceptionPro allows you to monitor cybercrime by creating realistic environments, allowing front row seat to attacker behaviors and post-exploitation activity." squiblydoo.blog/2025/10/14/dec…


"Harmony_Impact_Campaign_Brief_PDF.exe" Signed "Universal Vision Limited" f470ab8df8dc7764cb726c85d9a6f5daadca98d45f34bff992a563754b484b93 Refuses to run in sandboxes PDF icon, Decoy PDF Malcat's Kesakode suggests high probability of "QuirkyLoader" h/t @malwrhunterteam

SquiblydooBlog's tweet image. "Harmony_Impact_Campaign_Brief_PDF.exe"
Signed "Universal Vision Limited"
f470ab8df8dc7764cb726c85d9a6f5daadca98d45f34bff992a563754b484b93

Refuses to run in sandboxes
PDF icon, Decoy PDF

Malcat's Kesakode suggests high probability of "QuirkyLoader"

h/t @malwrhunterteam
SquiblydooBlog's tweet image. "Harmony_Impact_Campaign_Brief_PDF.exe"
Signed "Universal Vision Limited"
f470ab8df8dc7764cb726c85d9a6f5daadca98d45f34bff992a563754b484b93

Refuses to run in sandboxes
PDF icon, Decoy PDF

Malcat's Kesakode suggests high probability of "QuirkyLoader"

h/t @malwrhunterteam
SquiblydooBlog's tweet image. "Harmony_Impact_Campaign_Brief_PDF.exe"
Signed "Universal Vision Limited"
f470ab8df8dc7764cb726c85d9a6f5daadca98d45f34bff992a563754b484b93

Refuses to run in sandboxes
PDF icon, Decoy PDF

Malcat's Kesakode suggests high probability of "QuirkyLoader"

h/t @malwrhunterteam
SquiblydooBlog's tweet image. "Harmony_Impact_Campaign_Brief_PDF.exe"
Signed "Universal Vision Limited"
f470ab8df8dc7764cb726c85d9a6f5daadca98d45f34bff992a563754b484b93

Refuses to run in sandboxes
PDF icon, Decoy PDF

Malcat's Kesakode suggests high probability of "QuirkyLoader"

h/t @malwrhunterteam

Squiblydoo 님이 재게시함

"LONG SOUND TLD" has now been reported. It is also the trojan CrystalPDF, but seems to be an older version. Domains: flt.cntrlclient[.]com/v6 sih.cntrlclient[.]com/r Same functionality.

SquiblydooBlog's tweet image. "LONG SOUND TLD" has now been reported.
It is also the trojan CrystalPDF, but seems to be an older version.

Domains:
flt.cntrlclient[.]com/v6
sih.cntrlclient[.]com/r

Same functionality.

Certificate has been reported. Thanks.

SquiblydooBlog's tweet image. Certificate has been reported. Thanks.

CrystalPDF.exe is another one of these malicious PDF editors. Written in F#. 0/73 on VT. virustotal.com/gui/file/598da… Signer: VAST LAKE LTD Downloaded from: crystalpdf(dot)com

struppigel's tweet image. CrystalPDF.exe is another one of these malicious PDF editors. Written in F#. 0/73 on VT.

virustotal.com/gui/file/598da…

Signer: VAST LAKE LTD
Downloaded from: crystalpdf(dot)com


Loading...

Something went wrong.


Something went wrong.