PinnedGi7w0rm·Jun 2, 2025HuluCaptcha — An example of a FakeCaptcha frameworkHello and welcome back to another blog post. After some time of absence due to a lot of changes in my personal life ( finished university…A response icon1A response icon1
PinnedGi7w0rm·Jan 23, 2025A beginner(s) guide to hunting web-based credit card skimmersHello everyone, and welcome back to another blog post. Today, I will show you my approaches to hunting credit card skimmers.A response icon2A response icon2
Gi7w0rm·Mar 2Amos Stealer “malext” variant spread in a global malvertising campaign using free text-sharing…Hello and welcome back to another blog post. It has been a minute and I am happy I am finally finding the time to write down something for…
Gi7w0rm·Mar 19, 2024VexTrio’s Browser FingerprintingHey everyone, welcome back to the first blog post in 2024. Today, we are going to have a look at something I came across while looking at…
Gi7w0rm·Jan 6, 2024Gi7w0rm’s personal year review — 2023Disclaimer: The following article will highlight my work and achievements in 2023. I am not sure if this is going to be worth reading, but…A response icon1A response icon1
Gi7w0rm·Oct 19, 2023The curious case of the 7777-BotnetHello there and welcome back again to yet another blog post. Today, I am reporting on something I have been investigating for a while now…A response icon2A response icon2
Gi7w0rm·Sep 8, 2023Uncovering DDGroup — A long-time threat actorSometimes when investigating malware, you come across something that calls your attention. Something that seems odd, something that seems…
Gi7w0rm·Jul 9, 2023CloudEyE — From .lnk to ShellcodeHello and welcome back to another blog post. Today, we will look at the infection chain of a well-known malware loader called CloudEye…A response icon1A response icon1
Gi7w0rm·Jun 8, 2023DynamicRAT — A full-fledged Java RatHello everyone, welcome back to one of my sporadical blog posts. Due to some fortunate circumstances, I finally have the honor to name my…A response icon1A response icon1
Gi7w0rm·Jan 18, 2023A long way to SectopRatInvestigating a highly obfuscated stealer sampleA response icon1A response icon1