• 1 Post
  • 30 Comments
Joined 2 years ago
cake
Cake day: October 24th, 2023

help-circle

  • I agree with you in principle but that doesn’t really help us much when poorly wrought digital devices get compromised en masse. I can say “Mirai” and way too much of the population knows that it’s an IoT botnet.

    Those default passwords and superfluous software packages are cut corners, and directly translate to risk in your own home. Maybe you don’t feel that 2025 has been enough years of neglect to start calling it malfeasance , but if they’re tired of shit breaking and getting hacked and losing support I can definitely see the point of keeping more analog devices to minimize those risks.

    Opportunity makes the thief, right?






  • Your soulmate’s extension is Joint Photographic Experts Group. So sad!

    JPEGs tend to put very little effort into relationships. They focus on keeping up appearances rather than forming meaningful connections and are not known for their fidelity. Their lackadaisical attitude and refusal to contribute or communicate make them poor long term partners. They have a tendency to disappoint with their shallow personalities and are consistently absent when support is needed, but can attain great popularity on social media!













  • Typosquat domain for sure! In a sandbox I’m seeing that all the download links point to the same HTML page on a .ink domain that cloudflare is now refusing to serve.

    But our buddy joe already got a copy for us so we can at least view that report for fun: https://www.joesandbox.com/analysis/1763244/1/html

    Edit: It pulls down an MSI installer or something it runs with msiexec but disguised with a PDF file extension. It seems to want a copy of cmd.exe to exist in an AutoIT installation (SearchPathW vs “C:\Program Files (x86)\AutoIt3\cmd.exe”) as well as pointing toward the multilanguage (.exe.mui) and other cmd variants. I suspect we’re one step away from a real payload with this report and that’s what we’d see the “Invoke-Obfuscation” powershell the sandbox spotted used for (if that wasn’t a false positive due to the base64 offset string).