Gi7w0rm's Avatar

Gi7w0rm

@gi7w0rm.bsky.social

Just me, worming through the interwebs. Threat Intelligence and #URINT Analyst Other places: linktr.ee/gi7w0rm Support me: https://ko-fi.com/gi7w0rm

538 Followers  |  41 Following  |  68 Posts  |  Joined: 24.07.2023  |  2.0832

Latest posts by gi7w0rm.bsky.social on Bluesky

Post image

Got some surprise love from the @malbeacon team for beta testing a new product. Thanks a lot for this gift! Hope more people soon get to try your amazing work. TAs will fear you 😈

Cheers ❀️

05.11.2025 18:09 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image

In 2024 I reported several critical vulnerabilities in the aviation sector to @AviationISAC .

This week (after several global shipping attempts) I was honored to recieve 2 challenge coins (+ some stickers) from them πŸ”₯
Thank you!

#BeAware #Report #MakeAChange

03.10.2025 08:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Had an amazing time #FirstCon last week. Met a bunch of awesome folks from all over the industry. Around 3 hours of sleep per night and 17 hours of social interactions ^^ Was so done but also super happy on friday :) Cheers to all the awesome folks in our industry <3

02.07.2025 10:47 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Hunting bottlenecks in my infra.
For months I thought it was the MySQL server. Now that I have some stats, this does not seem to be the case. Time to check the other servers...

20.06.2025 11:36 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

At the beginning of this month i bought myself a #Steamdeck.
Must admit I am very pleasently surprised by it. Nice handling, great screen resolution, good performance. Better and more versatile than a Nintendo Switch.
Nice product @valvesoftware
#ThankGaben #gaming

19.06.2025 10:28 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
HuluCaptchaβ€Šβ€”β€ŠAn example of a FakeCaptcha framework Hello and welcome back to another blog post. After some time of absence due to a lot of changes in my personal life ( finished university…

New Blogpost: #HuluCaptcha - An example of a FakeCaptcha framework.
Started investigating this after a friend was compromised by it. Some interesting/unique techniques shown, plus analysis of the compromised server. Hope you enjoy the read! :)
medium.com/@gi7w0rm/hul...

02.06.2025 07:27 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

New #Blogpost scheduled for release tomorrow 8 a.m. (UTC+2). Analyzing a new #FakeCaptcha framework I call #HuluCaptcha. Besides codeanalysis, I also analyze 2 new #wordpress #backdoors and server logs. Hope you ll enjoy 😊

01.06.2025 14:39 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Jo @LidlUS @lidl @LidlGB, didn't knew you now also host fake versions of the New-York Times:

hxxps[:]//baustandards-qs[.]lidl[.]com

Seems a solid subdomain takeover?
Pointing to AWS: 72.144.31[.]24

#subdomaintakeover #itw

06.05.2025 03:14 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
PSA: Don’t let The Elder Scrolls Online delete your files and folders! The installer included with the on-disc version of The Elder Scrolls Online contains a bug that can potentially wipe out everything on your hard drive.

So this just happend to me:
gamerhorizon.com/2015/01/28/p...

800 Gigs of Data gone. Years of work. Because the installer for @Bethesda @Elderscrolls Online decided to wipe the complete disk upon uninstall.

22.04.2025 11:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

The website of the "Deutsche Vereinigung fΓΌr internationales Recht" (dvir[.]de) is currently compromised and spreading #Lumma #Stealer via #FakeCaptcha attack.

Compromised webfile is:
hxxp[://]www[.]dvir[.]de/wp-content/themes/Dummy/assets/js/main[.]min[.]js?ver=1[.]0

14.04.2025 17:45 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

On December 31,2024 @sourcedefense released an article about a #webskimming threat, using extensive google redirects.
securityboulevard.com/2024/12/crit...
I entered a @ThinkstCanary CC token.
April 09, 2025 morning I woke up to 6 payment attempts from Australia!
Attempts to pay @eBay and @Uber.

09.04.2025 10:28 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Message of the day:
Not every North Korean Cyber Threat is #Lazarus or related to Lazarus.
Please get this into your heads...

06.04.2025 11:19 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

"Studio Ghibli" - Gi7w0rm

#AIArt #StudioGhibli #Gi7w0rm

28.03.2025 20:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Homeoffice starting in 4 days, so after roughly 10+ years I upgraded my office desk.
Now the proud owner of an hight-adjustable desk.
Looking pretty neat!
Hope my back will thank me in some years...

27.03.2025 23:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
ArrayThisClone

Small Bugfix in gi7w0rm.github.io/ArrayThisClo...
The name field can now be empty. Previous coding prevented the user from deleting the complete input field content. Using this as a short reminder that this tool is still out there for if you ever need to convert multi-line content to an array.

23.03.2025 17:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Why It's So Hard to Stop Rising Malicious TDS Traffic Cybersecurity vendors say threat actors' abuse of traffic distribution systems (TDS) is becoming more complex and sophisticated β€” and much harder to detect and block.

Have just been notified that I am featured in:
www.darkreading.com/cyberattacks...
Thank you for the honor @DarkReading ❀️

21.03.2025 14:54 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Thank you :)

15.03.2025 00:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Happy to share that I have signed a work contract at a CTI company.
Also, today was my last work day at my old employer, since I took the remaining vacation days. Looking forward to 2 weeks of rest to prepare for whats to come.
Cheers all ❀️

14.03.2025 23:03 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Seems someone just tried to pay an Uber with my @ThinkstCanary token CreditCard which I entered into a #webskimmer.
I bet it didn't go well ^^

24.02.2025 19:07 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Please excuse the lack of content in the last weeks.
I am overhelmed by current political developments and additionally working on some topics that I can't publicly disclose. No capacity for free research :/ Hope this will get better in some months.
Cheers to all my friends and followers.❀️

22.02.2025 20:03 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Looking good on the #jobhunt. Hope to sign a contract by the end of next week.
Currently decluttering my workdesk to be prepared for a fresh start. Highly motivated for whats to come 😊 πŸ’ͺ

22.02.2025 15:39 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image

Happy to have received recognition for being a #TopContributor to the abuse_ch project in #2024. Currently ranking place 4 in the leaderboard of global #IoC sharing via #Threatfox.
Definetly planning to keep up that rank in the next years.

Cheers to the Team @abuse_ch and @spamhaus.bsky.social!

12.02.2025 00:49 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Damn, what an awesome feeling to improve the speed of your code.
From 1k documents to 16k per second using some simple coding techniques and #CursorAI.
Amazing πŸ”₯

30.01.2025 15:50 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

My pleasure :) thank you for the feedback!

29.01.2025 15:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
a white cat is standing on its hind legs on a wooden floor . ALT: a white cat is standing on its hind legs on a wooden floor .

New #challengecoin unlocked. Images as soon as received πŸ”₯

29.01.2025 15:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Here is the fixed link:
gi7w0rm.medium.com/a-beginner-s...

23.01.2025 23:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Super weird, not really sure why...

23.01.2025 23:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
A beginner(s) guide to hunting web-based credit card skimmers Hello everyone, and welcome back to another blog post. Today, I will show you my approaches to hunting credit card skimmers. This blog is…

Released my new blogpost: "A beginner(s) guide to hunting web-based credit card skimmers"
My experience on how to detect and analyze skimming campaigns using free tools like Validin, URLscan and FoFa. Includes WebSocket analysis and new IOCs!
https://gi7w0rm.medium.com/a-beginner-s-guide-to-huntin…

23.01.2025 17:09 β€” πŸ‘ 9    πŸ” 4    πŸ’¬ 2    πŸ“Œ 1
Preview
a sign that says coming soon is lit up with lights . ALT: a sign that says coming soon is lit up with lights .

Blogpost release scheduled 6 pm CET today.
Topic: How to hunt for CreditCard skimmers using free tools. (Only none free tool I use is ClaudeAI and you could use Llama or similar).
Hope you ll enjoy!

23.01.2025 12:22 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Had a productive evening yesterday :)
#skimming #magecart #hunting

20.01.2025 14:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@gi7w0rm is following 20 prominent accounts