Hexacorn
@hexacorn.bsky.social
1.7K followers 280 following 190 posts
Red Brain, Blue Fingers Malware Analysis, Reverse Engineering, Threat Hunting, Detection Engineering, DFIR, Security Research, Programming, Curiosities, Software Archaeology, Puzzles, Bad dad jokes https://www.hexacorn.com/blog/ [email protected]
Posts Media Videos Starter Packs
hexacorn.bsky.social
> DLL_PROCESS_VERIFIER_TABLE

ah, that's the one!

and yeah, that's where I saw it and got curious

thanks!
hexacorn.bsky.social
@sixtyvividtails.bsky.social any idea what fdwReason=5 stands for? you can find it inside verifier.dll / AVrfpMiniLoadAttach call - lots of LdrQueryImageFileKeyOption checks
Reposted by Hexacorn
sixtyvividtails.bsky.social
Close your eyes and ✨imagine:

From a low-integrity process (from LPAC even), you can inject your data anywhere you want:
privileged tasks, PPL/protected processes, the OS kernel itself, and VTL1 trustlets.

Now open your eyes. It is not hypothetical.
It is the reality. Read it on page 33.
pagedout.bsky.social
pagedout.institute ← we've just released Paged Out! zine Issue #7
pagedout.institute/download/Pag... ← direct link
lulu.com/search?page=... ← prints for zine collectors
pagedout.institute/download/Pag... ← issue wallpaper
Enjoy!

Please please please share to spread the news - thank you!
hexacorn.bsky.social
sounds like you have a reverse Prisencolinensinainciusol moment :)
hexacorn.bsky.social
have to keep them to myself, so can write a few more posts about it to milk this potentially fertile subject :-P
hexacorn.bsky.social
Enter Sandbox 30: Static Analysis gone wrong

www.hexacorn.com/blog/2025/09...
hexacorn.bsky.social
no idea :(
but it does include this:
hexacorn.bsky.social
found one unsigned from Reaqltek

www.virustotal.com/gui/file/011...

testker -> kerberos.Spinitialize
hexacorn.bsky.social
haha right? and I want to know, for sure!
hexacorn.bsky.social
DLL ForwardSideloading

www.hexacorn.com/blog/2025/08...

using forwarded DLL functions for sideloading purposes
hexacorn.bsky.social
Life of a blogger
Reposted by Hexacorn
volexity.com
@volexity.com has released updates to its #opensource GoResolver project and more! This work was part of a project for one of our #summerinternship students. Read more details about Volexity’s updated GoResolver projects + other #golang tools in our special blog post!
Go Get 'Em: Updates to Volexity Golang Tooling
Volexity’s GoResolver tool was released in April 2025 to help with analysis of these samples, reducing analyst load when working with obfuscated Golang binaries. However, there are still some difficul...
www.volexity.com
hexacorn.bsky.social
feels like security research -- ideas, hypothesis, lots of digging in code, only to find out it's impossible due to some unforeseen conditions blocking the execution path we hoped to exploit; or gathering large data set (TBs) hoping to find something cool, only to discover it's very uninteresting
hexacorn.bsky.social
I bert they are just throwing some nuanced Rust references at you :)
hexacorn.bsky.social
CVE-2005-4560 and Windows Macros + all exploit packs roll in their graves when they see ClickFix and FileFix...