Ddark3v3iniluvblue.hashnode.dev·4d ago · 8 min readFollowing the OLE TrailThe sample for this investigation can be found on Samplepedia In this investigation, I analyze a suspicious Microsoft Office document that contains multiple embedded objects and several layers of Offi00
Ddark3v3iniluvblue.hashnode.dev·Aug 18 · 6 min readMalware Traffic Analysis 2026-01-31 - TRAFFIC ANALYSIS EXERCISE: LUMMA IN THE ROOM-AHTask Questions What is the IP address of the infected Windows client? Answer: 10.1.21.58 I usually start by looking at Statistics > Conversations and Statistics > Endpoints tabs in Wireshark to get a 00
Ddark3v3iniluvblue.hashnode.dev·Sep 12, 2025 · 10 min readC2 Mini Series : Empire to MimikatzPowerShell Empire → Mimikatz This blog post will be part of my mini purple team series of deploying and detecting malicious activities using various C2 infrastructures. PowerShell Empire → Mimikatz: My Lab Notes, Facepalms, and Detections Intro I use...00