securechicken Profile Banner
Secure Chicken 🐣 Profile
Secure Chicken 🐣

@securechicken

Followers
435
Following
66
Media
2
Statuses
57

Rural cybersecurity practitioner and seasoned brewer. Opinions are my own, I work @HarfangLab (former GREAT, CISO and FR Gov).

France
Joined February 2020
Don't wanna be here? Send us removal request.
@securechicken
Secure Chicken 🐣
1 month
I have never heard about the "XDSpy" threat actor 👾 before, but it turns out I tripped over a Windows shortcut in March and. 🤷‍♂️ we had to "take a look".
Tweet card summary image
harfanglab.io
Identifier: TRR250601. Summary This report examines recent activities we attribute to the XDSpy threat actor, focusing on an ongoing campaign targeting Eastern European and Russian governmental...
0
1
4
@securechicken
Secure Chicken 🐣
5 months
I like a vulnerability analysis 🔬 as I like a scotch 🥃: old enough to order its own scotch. Ivanti CVE-2024-8963 vuln analysis + unique report of malicious activities after exploitation:
Tweet card summary image
harfanglab.io
Identifier: TRR250201. Summary Between October 2024 and late January 2025, public reports described the exploitation of Ivanti CSA vulnerabilities which started Q4 2024. We share analysis results...
0
2
3
@securechicken
Secure Chicken 🐣
1 year
Did our bit on #Doppelgänger: standalone paper w/ new infra, ongoing activity inc. Paris #Olympics, tech details, content analysis, links to grey SEO. BTW we're a 3-people show @ArielJT @JusticeRage
harfanglab.io
1
1
8
@securechicken
Secure Chicken 🐣
1 year
Turns out it is now explicitly detected as #FrostyGoop by some vendors, so might actually be it.
@Now_on_VT
Is Now on VT!
1 year
A few AV detections are starting to appear for the #FrostyGoop samples found by @securechicken
Tweet media one
1
0
1
@securechicken
Secure Chicken 🐣
1 year
Not sure it's any of them though. They all contain the "/CleintTCP" typo string, which does not appear to belong to the modbus library repository, and that I could only find in 7 Golang binaries. 4/4.
0
1
5
@securechicken
Secure Chicken 🐣
1 year
Searching for those strings in public files repositories, maybe using #Yara , you would find 5d2e4fd08f81e3b2eb2f3eaae16eb32ae02e760afc36fa17f4649322f6da53fb and a63ba88ad869085f1625729708ba65e87f5b37d7be9153b3db1a1b0e3fed309c 3/4.
4
3
13
@securechicken
Secure Chicken 🐣
1 year
From reference Page 4 ("use a Go Modbus library") + logs screenshot Page 5, one could infer some strings that should be FrostyGoop: "/rolfl/modbus", "proc.go", "executeCommand" and "TaskList" 2/4.
1
0
5
@securechicken
Secure Chicken 🐣
1 year
You went through marketing form to read about #FrostyGoop ( from @DragosInc, then are disappointed to find ZERO IOC, like @craiu and me? 1/4.
1
3
10
@securechicken
Secure Chicken 🐣
1 year
closermag[.]eu.conspiracywatch[.]in.mensjournal[.]day.mynaszlaku[.]in.dzieckowpodrozy[.]in.bibelbund[.]cfd. Also, new Doppelgänger tracker (July 15) we got from our monitoring: gatoogeef[.]info - 2/2.
1
2
3
@securechicken
Secure Chicken 🐣
1 year
6 suspicious domains impersonating 🇺🇲, 🇩🇪, 🇵🇱 and 🇫🇷 websites, found while hunting for #Doppelgänger activities, registered in July. I believe they are made ready for ongoing (but not retrieved) or future fabricated content publication - 1/2.
1
4
6
@securechicken
Secure Chicken 🐣
3 years
RT @jeffespo: A look at how #SOC analysts can use the IOC that are commonly shared in #infosec Twitter and also TI reports from @securechic….
0
1
0
@securechicken
Secure Chicken 🐣
4 years
RT @Kaspersky_Gov: JOIN us virtually to discuss the cross-border cooperation to protect critical infrastructure at @igf_2021 ➡️ https://t.….
0
2
0
@securechicken
Secure Chicken 🐣
4 years
RT @vkamluk: @TheSAScon sets new standards every year. This time it’s a new standard of remote participation in a conference: bring your co….
0
3
0
@securechicken
Secure Chicken 🐣
4 years
RT @vkamluk: @r00tbsd @TheSAScon Welcome to Fabulous Las Vegas! 😄
Tweet media one
0
1
0
@securechicken
Secure Chicken 🐣
4 years
RT @e_kaspersky: Planning for #TheSAS2021. ☑️ Agenda.🛫 nope. next year.☑️APT research.☑️ Sign up. I feel like something is missing. ….
0
8
0
@securechicken
Secure Chicken 🐣
4 years
Verifying myself: I am securechicken on dsx0C_AIGAvAV0YsWMSkWy07JWo-1lUk-XqS /
0
0
0
@securechicken
Secure Chicken 🐣
4 years
Pff, I don’t need no SIEM, I have checklogs :D Humble effort at making Pi-hole logs grep a bit easier, to search for IOCs. #Pihole #IOC #DNS
Tweet card summary image
github.com
An helper script to check Pi-hole logs for given network IOCs (domains/FQDNs, or IPs) - securechicken/pihole-checklogs
0
6
13