Squiblydoo

@squiblydoo.bsky.social

Malware Analyst; creator of debloat, certReport, CertCentral.org Debloat Discord: http://discord.gg/dvGXKaY5qr squiblydoo.blog

FUD HijackLoader 9c0a88ea53c4e0324157542385a1d342101feb51cf7b8cf76e9441376f1f522a Signature: ELH Palkehituse OÜ C2: web-telegram[.]ug Was disguised as a Franz Messenger installer.

BildBild

This is how I like my FUD malware: So many detections that I can't get the engines on the page. 2143baefd0b108fa1f6cfcfa3eb31d87578c6014117768f06bd8544dd02c8adf Signer:"F & P PARTNERS LIMITED" Gets payload from insharedata[.]org/check.php/api/launcher/14/payload?direct=1

Bild

New blogpost discussing how the Cert Graveyard can be leveraged: through @magicswordio, rss feeds, database download, API. I also share statistics on the number of web requests I see each day and ways to support the Cert Graveyard.

Using the Cert Graveyard

Summary: This post shares some key ways to leverage the Cert Graveyard database. I also share statistics on Cert Graveyard usage and share options to support my work. If you aren’t familiar w…

squiblydoo.blog

FUD CastleLoader SHA256: b0a6f7afa4877eab5085d49207e26d1d2461d2d61d71a4d406e81e9f30711c5e C2: goldmanadv[.]com Right now, I open in #malcat, save the CAB file to disk, extract the CAB; ripgrep for the C2. Works but could be better, right? 1/2

Bild

Low detection CastleLoader signed "SOFTWARE ANALYTICS LIMITED": f50f825a64cb9c0435bc11db9225445687f8d1a44dba972a50ffa4dff600e72f They changed from EXE to MSI C2: arqeluno[.]com

BildBild

We report certificates for revocation when they sign malware. What about before they sign malware? I've started adding certificates to Cert Graveyard that are being used to "warm" the certificate and improve it's score before being sign malware. 1/4

Bild

Kaspersky reports that recent files signed by EV code-signer "AVB Disc Soft, SIA" contain a backdoor. They report that the Daemon-Tools software have had a small backdoor since early April. (We've reported the certificate.) securelist.com/tr/da... 1/2

daemon tools

Targeted by threat actors: individuals and organizations across 100+ countries and territories, with the majority of victims located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.

securelist.com

The RansomISAC published regarding "Zhengzhou 403 Network Technology Co., Ltd.", a cert we reported in 2025 after it was used to sign CobaltStrike. Their investigation seemed like a wild adventure, check it out. ransom-isac.org/blog... 1/3

DragonBreath: Dragon in the Kernel

A 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an APT31 / Wuhan Xiaoruizhi personnel nexus.

ransom-isac.org

We didn't know how an actor was using EV Certificates issued to Lenovo and others. We now do. From DigiCert's incident report: "the threat actor used a compromised analyst endpoint to access DigiCert's internal support portal. he threat actor was able to use this function... 1/3

Squiblydoo@squiblydoo.bsky.social · 4mo ago

What do Lenovo, Kingston, Shuttle Inc, and Palit Microsystems have in common? EV Certificates from these companies were issued and used by a Chinese crime group, #GoldenEyeDog (#APT-Q-27)! Thanks @malwrhunterteam and @g0njxa for your contributions 1/7

CertGraveyard's PKI Lab is available now. Want to better understand code-signing certificates? The site allows you to extract and view certificates. The Cert Inspection tool parses out all of the bits and flags anomalies. 1/2

Bild

AnchorWallet[.]org is fake. The real place to download the wallet is Greymass[.]com. If you download the Windows app from the fake, you get a 680MB remote access tool signed by PIXEL PLAY PRIVATE LIMITED. Not an app signed by Greymass. h/t @malwrhunterteam 1/2

BildBild

FUD CastleLoader signed "INFOTECK SOLUTIONS PRIVATE LIMITED" The 40MB exe makes it hard for detection engines to see the 1 important line of python it will execute. Short #malcat investigation though. 62a6e64a7233f4a756d01c54840ff703a620a416929d57eebc0bdac3b9ed2019 1/3

BildBild

When I clicked on the "Bluesky Issues" trending link earlier today, every account in the first few scrolldowns was reposting the exact same text blaming the problem on AI. Each account was clearly inauthentic and was advertising video game material in its profile.

Orange Cyberdefence recently published their research on SmokedHam. We're glad to see Cert Graveyard and the code-signing certs mentioned. While CertGraveyard tracks the campaigns, we can't investigate them to their full depth (due to capacity), so this is great to see. 1/2

BildBildBild

I don't know how to feel about this domain: maybedontbanplease[.]com What to do? Chat, can you help me out? (CastleLoader 4ba0d3ae41a0ae3143e8c2c3307c24b0d548593f97c79a30c0387b3d62504c31 signed "SERPENTINE SOLAR LIMITED" NSIS -> Python execution -> loads remote resource)

BildBild

The CertGraveyard was created in 2025, but never received a proper introduction. We track abused code-signing certificates. When I created the site, we had 600 entries and now we have 2,250. See the blogpost below for a full overview. 1/3

We saw NovaViewer being signed with a new EV certificate "Xiamen Duohanbeiwei Network Co., Ltd". This certificate was reported and revoked before the certificate was used in a BumbleBee campaign. 6d6a861c133ff3e1aa09c8744de52413 Special thanks to @luke92881 and @g0njxa 1/4

Bild

QuasarRAT signed by "北京谷云达吉商贸有限公司" This signer previously signed GhostRAT. Cert was revoked. They received new certificate. Revoked. New certificate. Revoked. If I didn't have a database with records, I'd think I was insane. h/t @malwrhunterteam 1/6

Bild

#Hijackloader "SettlePay - Billing Report.exe" signed by "广州杜倾科技有限公司" 02cbc77d52e12aea6a6c9db36c07d2eccd1af9d39b88b3802b40cb10d088b30c MB: https://bazaar.abuse[.]ch/sample/02cbc77d52e12aea6a6c9db36c07d2eccd1af9d39b88b3802b40cb10d088b30c

Bild

Fake Microsoft Teams, "MTSetup_v15.3.7191.msi" signed by "Tryphena Lewis" 18c5b7a39be2f4a4b2fd45f0f273874f5efcc8751d4e592e5f2bcf6dbf781277 FUD-lite Uploaded to MalwareBazaar here https://bazaar.abuse[.]ch/sample/18c5b7a39be2f4a4b2fd45f0f273874f5efcc8751d4e592e5f2bcf6dbf781277

Bild

"gozofeliz4-guerrainfinita.exe" signed "ZHEJIANG WILLING FOREIGN TR CO MAKİNA TİCARET LİMİTED ŞİRKETİ" 808fa714b5308a813df21094c1f8e8b0 "gozofeliz4-guerrainfinita.exe" signed by "Lway Firmware" f13b26c2d4c8f1d536519b947c7300e0 what could go wrong C2: pinpadat[.]com

Reported to CertGraveyard: 143fa9567ebbccacceb58201dd85b7206fdf22882ff2cea0da994a513572f14e signed by "Mann Technologies LLC" Fake Citrix installer, FUD on VirusTotal, installs Zoho Meeting.

BildBild