<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://forensicitguy.github.io/</id><title>Tony Lambert</title><subtitle>Tony's blog about malware analysis and other security topics</subtitle> <updated>2026-05-16T04:22:42+00:00</updated> <author> <name>Tony Lambert</name> <uri>https://forensicitguy.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://forensicitguy.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://forensicitguy.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Tony Lambert </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Squeezing Cobalt Strike Threat Intelligence from Shodan</title><link href="https://forensicitguy.github.io/squeezing-cobalt-strike-intel-from-shodan/" rel="alternate" type="text/html" title="Squeezing Cobalt Strike Threat Intelligence from Shodan" /><published>2025-05-18T00:00:00+00:00</published> <updated>2025-05-19T01:31:42+00:00</updated> <id>https://forensicitguy.github.io/squeezing-cobalt-strike-intel-from-shodan/</id> <content type="text/html" src="https://forensicitguy.github.io/squeezing-cobalt-strike-intel-from-shodan/" /> <author> <name>Tony Lambert</name> </author> <category term="threat-intelligence" /> <summary>One of my favorite Twitter accounts from the last several years was @cobaltstrikebot, mainly because it was an awesome source of threat intelligence for Cobalt Strike beacons in the wild. The account went dark in June 2023, but its tweets are still around. Today&amp;#39;s 5 most common Spawn_to values:%windir%\sysnative\rundll32.exec:\windows\system32\rundll32.exe%windir%\system32\rundll32.exe%win...</summary> </entry> <entry><title>Exploring VenomRAT Metadata and Encryption with YARA - #100DaysOfYara</title><link href="https://forensicitguy.github.io/exploring-venomrat-metadata-encryption-with-yara/" rel="alternate" type="text/html" title="Exploring VenomRAT Metadata and Encryption with YARA - #100DaysOfYara" /><published>2025-01-02T00:00:00+00:00</published> <updated>2025-01-02T00:00:00+00:00</updated> <id>https://forensicitguy.github.io/exploring-venomrat-metadata-encryption-with-yara/</id> <content type="text/html" src="https://forensicitguy.github.io/exploring-venomrat-metadata-encryption-with-yara/" /> <author> <name>Tony Lambert</name> </author> <category term="malware" /> <summary>It’s that time of year again - 100 Days of YARA! In this post I want to walk through how I use YARA to document malware analysis findings. YARA has loads of different use cases: Detecting malicious file contents Estimating malware capabilities Showing how files can be similar to known documentation My favorite use case is that last one. In my day job I often encounter malware that doe...</summary> </entry> <entry><title>Decompiling a JPHP Loader with binwalk and cfr</title><link href="https://forensicitguy.github.io/decompiling-jphp-loader-binwalk-cfr/" rel="alternate" type="text/html" title="Decompiling a JPHP Loader with binwalk and cfr" /><published>2024-07-20T00:00:00+00:00</published> <updated>2024-07-20T00:00:00+00:00</updated> <id>https://forensicitguy.github.io/decompiling-jphp-loader-binwalk-cfr/</id> <content type="text/html" src="https://forensicitguy.github.io/decompiling-jphp-loader-binwalk-cfr/" /> <author> <name>Tony Lambert</name> </author> <category term="malware" /> <summary>It’s not unusual for adversaries to explore new and unusual ways to implement loader malware, and lately I’ve been looking at JPHP-based loader malware. This kind of loader doesn’t get a lot of attention from antimalware providers, likely because of its nature as a weird hybrid language. In this post, I dive into unpacking the loader (which I suspect is “d3f@ck” loader) and statically decompili...</summary> </entry> <entry><title>Dissecting a Java Pikabot Dropper</title><link href="https://forensicitguy.github.io/dissecting-java-pikabot-dropper/" rel="alternate" type="text/html" title="Dissecting a Java Pikabot Dropper" /><published>2024-03-03T00:00:00+00:00</published> <updated>2024-03-03T00:00:00+00:00</updated> <id>https://forensicitguy.github.io/dissecting-java-pikabot-dropper/</id> <content type="text/html" src="https://forensicitguy.github.io/dissecting-java-pikabot-dropper/" /> <author> <name>Tony Lambert</name> </author> <category term="malware" /> <summary>In mid-February, TA577 experimented with a Java Archive (JAR) dropper to deliver Pikabot to their victims. In this post I’ll explore some static analysis of that dropper to show how we can get information from it. If you want to follow along, I’m working with this sample in MalwareBazaar: https://bazaar.abuse.ch/sample/0a0e0d2f9daa0bad25c3defd69a3a6d96a6ac5f325a369761807c06887d3bd9f/. Triage t...</summary> </entry> <entry><title>Timelining a Malicious VHD for More Intelligence</title><link href="https://forensicitguy.github.io/timelining-malware-vhd-intelligence/" rel="alternate" type="text/html" title="Timelining a Malicious VHD for More Intelligence" /><published>2023-08-04T00:00:00+00:00</published> <updated>2023-08-04T00:00:00+00:00</updated> <id>https://forensicitguy.github.io/timelining-malware-vhd-intelligence/</id> <content type="text/html" src="https://forensicitguy.github.io/timelining-malware-vhd-intelligence/" /> <author> <name>Tony Lambert</name> </author> <category term="malware" /> <category term="tools" /> <summary>In a previous blog post I mentioned how adversaries using VHD files to distribute malware can leave around a lot more data than they intend, including identifiable data for tracking. In this post I want to break out the best friend everyone made during SANS FOR508, Plaso, so I can process the filesystem data for a malicious VHD and illustrate how we can establish a timeline of operations for th...</summary> </entry> </feed>
