Paul Melson
pmelson@infosec.exchange
<p>Blue Team by day, Blue Team by night. Opinions, typos, and awful code do not represent my employer. Author/Operator of <a href="https://infosec.exchange/@ScumBots" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">infosec.exchange/@ScumBots</span><span class="invisible"></span></a> </p>
Posts
-
View post
It’s that time again. Apparently.
-
View post
Don’t miss the use of ngrok for tunneling here. Continue to see malicious actors use this service to hide C2 and phising site origin servers. Ngrok uses AWS IPs across multiple zones for egress NAT. I recommend sinkholing their domains across your network. ngrok[.]com ngrok[.]io ngrok-free[.]app https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/
-
View post
@da_667 Xfce’s better, but… 😉 Here ya go: https://www.redbubble.com/i/sticker/FluxBox-by-manyroads/41042704.EJUG5
-
View post
Cats out here charging for RATs that anyone can download for free from GitHub. Good thing there&#39;s a money-back guarantee..? 🙄
-
View post
If you’re not alreadyalerting on CONHOST.EXE spawning CMD.EXE spawning WGET.EXE or CONHOST.EXE spawning CONHOST.EXE spawning CONHOST.EXE you’re gonna want to close that gap today.
-
View post
RE: https://infosec.exchange/@ScumBots/115850383845467081 This Meterpreter reverse shell was part of an intrusion set tied to an actor claiming to be a KeyGroup777 member and this HiddenTear ransomware payload: https://www.virustotal.com/gui/file/62ecd3ec595452e7f01a9eeab6ae619f61648e5b6cb01c23c5ca2c03f59ec778/summary
-
View post
Ugh, why does this work?! (I mean, I know how it works, but what was the thought process behind what’s essentially executing the stdout of a command? We’ve come so far and learned so little from our past mistakes.)
-
View post
@krypt3ia I have this shirt in white on black. Gets lots of comments, but zero folks have actually recognized it yet. 😂