<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ronnie&apos;s Blog</title>
    <description>root@PandorasBox:~#</description>
    <link>https://blog.spookysec.net//</link>
    <atom:link href="https://blog.spookysec.net//feed.xml" rel="self" type="application/rss+xml"/>
    <pubDate>Fri, 23 Jan 2026 06:25:03 +0000</pubDate>
    <lastBuildDate>Fri, 23 Jan 2026 06:25:03 +0000</lastBuildDate>
    <generator>Jekyll v3.10.0</generator>
    
      <item>
        <title>Analyzing the Rondodox Botnet from a DShield Sensor</title>
        <description>&lt;p&gt;&lt;strong&gt;This post was written as part of my internship with SANS Internet Storm Center.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Through November 20 and November 21, 2025, automated vulnerability scanning was identified against the DShield Honeypot from 192[.]159[.]99[.]95 with the goal of gaining remote code execution against potential victims. These probing and scanning activities stood out as interesting as some POST requests were observed attempting to pull down a stage to execute code on the system from a second server (74[.]194[.]191[.]52). A shell script that would have been executed on the system was successfully recovered, and the second stage x86 binary that would be executed on...</description>
        <pubDate>Fri, 23 Jan 2026 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//RondoDox-Botnet/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//RondoDox-Botnet/</guid>
        
        <category>Analysis</category>
        
        <category>Botnet</category>
        
        <category>Web</category>
        
        <category>DFIR</category>
        
        
      </item>
    
      <item>
        <title>Analyzing an American Express Phishing Campaign</title>
        <description>&lt;p&gt;&lt;strong&gt;This post was written as part of my internship with SANS Internet Storm Center.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;To stay in tune with current threats in the cybersecurity landscape, it’s important to periodically review the various threat actors attacking organizations. Having a good working relationship with your Cyber Threat Intelligence (CTI) team can certainly help educate you on the current landscape, but nothing quite beats looking at an actual phishing campaign itself. Phishing is a massive threat to organizations of all sizes, from small businesses to large enterprises. The severity and impact of these campaigns vary, ranging from the execution of malware to the...</description>
        <pubDate>Tue, 20 Jan 2026 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//amex-phish-analysis/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//amex-phish-analysis/</guid>
        
        <category>Analysis</category>
        
        <category>Phishing</category>
        
        <category>DFIR</category>
        
        
      </item>
    
      <item>
        <title>2024 CISA ICS CTF - Register the Dots</title>
        <description>&lt;p&gt;We’re onto the next competition category in the CISA ICS CTF - This time we’re taking a look at a challenge in Driftveil City; Register the Dots. This CTF has some infrastructure setup for the players to use; &lt;a href=&quot;https://github.com/cisagov/Malcolm&quot;&gt;Malcolm&lt;/a&gt;, &lt;a href=&quot;https://arkime.com/&quot;&gt;Arkime&lt;/a&gt;, &lt;a href=&quot;https://github.com/netbox-community/netbox&quot;&gt;NetBox&lt;/a&gt; and &lt;a href=&quot;https://github.com/gchq/CyberChef&quot;&gt;CyberChef&lt;/a&gt;. We probably won’t be using any of these services, but I’m putting this disclaimer in there just in case so we’re all on the same page if you see me use any of the tools.&lt;/p&gt; &lt;p&gt;&lt;img src=&quot;https://blog.spookysec.net/img/Pasted image 20240903211847.png&quot; alt=&quot;[Pasted image 20240903211847.png]&quot; /&gt;&lt;/p&gt; &lt;h3 id=&quot;registering-the-dots-1-2a-2b&quot;&gt;Registering the Dots 1, 2a, 2b&lt;/h3&gt; &lt;p&gt;The challenge starts...</description>
        <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//CISA-ICS-CTF-Reg-the-Dots.md/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//CISA-ICS-CTF-Reg-the-Dots.md/</guid>
        
        <category>CTF</category>
        
        <category>CISA</category>
        
        
      </item>
    
      <item>
        <title>2024 CISA ICS CTF - Read Askew Manuscripts</title>
        <description>&lt;p&gt;I’d like to think this forensics challenge is word play for RAM (Random Access Memory &amp;amp;&amp;amp; Read Askew Manuscripts), with a little bit of hinting at future challenges to come. This was a great one, so buckle up and let’s get on into it. After this last challenge set in Virbank, it’s Potpourri.&lt;/p&gt; &lt;h3 id=&quot;read-askew-manuscripts-1&quot;&gt;Read Askew Manuscripts 1&lt;/h3&gt; &lt;p&gt;Virbank Medical has recieved a call from Driftveil Police with news. Patient data x-ray data was stolen. Our task is to identify who dunnit! First of all, we need to identify the Serial Number of the X-Ray machine to verify our memory...</description>
        <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//CISA-ICS-CTF-RAM.md/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//CISA-ICS-CTF-RAM.md/</guid>
        
        <category>CTF</category>
        
        <category>CISA</category>
        
        
      </item>
    
      <item>
        <title>2024 CISA ICS CTF - Mission Inconceivable</title>
        <description>&lt;p&gt;Onto the next challenge category in the CISA ICS CTF - Virbank City. This time we’re going to be taking a look at the Mission Inconceivable challenge set. There was a ton to learn from this one, so I’m excited to take a shot at this one next.&lt;/p&gt; &lt;p&gt;This CTF has some infrastructure setup for the players to use; &lt;a href=&quot;https://github.com/cisagov/Malcolm&quot;&gt;Malcolm&lt;/a&gt;, &lt;a href=&quot;https://arkime.com/&quot;&gt;Arkime&lt;/a&gt;, &lt;a href=&quot;https://github.com/netbox-community/netbox&quot;&gt;NetBox&lt;/a&gt; and &lt;a href=&quot;https://github.com/gchq/CyberChef&quot;&gt;CyberChef&lt;/a&gt;. Some of these services we’ll be using in this challenge, some won’t. I’ll probably put this brief little introduction in each post so we’re all on the same page. Anyways, onto the...</description>
        <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//CISA-ICS-CTF-Mission-Inconceivable.md/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//CISA-ICS-CTF-Mission-Inconceivable.md/</guid>
        
        <category>CTF</category>
        
        <category>CISA</category>
        
        
      </item>
    
      <item>
        <title>2024 CISA ICS CTF - Modeling Trains</title>
        <description>&lt;p&gt;Well, another year has passed, which means its time for my annual CTF competition. This year I’m doing CISA’s ICS CTF solo-mode. This CTF has some infrastructure setup for the players to use; &lt;a href=&quot;https://github.com/cisagov/Malcolm&quot;&gt;Malcolm&lt;/a&gt;, &lt;a href=&quot;https://arkime.com/&quot;&gt;Arkime&lt;/a&gt;, &lt;a href=&quot;https://github.com/netbox-community/netbox&quot;&gt;NetBox&lt;/a&gt; and &lt;a href=&quot;https://github.com/gchq/CyberChef&quot;&gt;CyberChef&lt;/a&gt;. Some of these services we’ll be using in this challenge, some won’t. I’ll probably put this brief little introduction in each post so we’re all on the same page.&lt;/p&gt; &lt;p&gt;Today we’re going to start off with the Modeling Trains challenges. This is under the Anville category, so all of these are Rail/Transport themed challenges, one of the important...</description>
        <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//CISA-ICS-CTF-Mdl-Trains.md/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//CISA-ICS-CTF-Mdl-Trains.md/</guid>
        
        <category>CTF</category>
        
        <category>CISA</category>
        
        
      </item>
    
      <item>
        <title>2024 CISA ICS CTF - Follow the Charts</title>
        <description>&lt;p&gt;Another challenge from Virbank city - this time Virbank employees have been spotted installing unauthorized software. An FTP server was recently setup on one of the hospital’s servers (yikes) and has been used for hosting video games and such! They identified an interesting executable of interest that is stored in &lt;strong&gt;malcolm&lt;/strong&gt;. Our task is to find it and retrieve the hash.&lt;/p&gt; &lt;p&gt;This CTF has some infrastructure setup for the players to use; &lt;a href=&quot;https://github.com/cisagov/Malcolm&quot;&gt;Malcolm&lt;/a&gt;, &lt;a href=&quot;https://arkime.com/&quot;&gt;Arkime&lt;/a&gt;, &lt;a href=&quot;https://github.com/netbox-community/netbox&quot;&gt;NetBox&lt;/a&gt; and &lt;a href=&quot;https://github.com/gchq/CyberChef&quot;&gt;CyberChef&lt;/a&gt;. Some of these services we’ll be using in this challenge, some won’t. I’ll probably put this brief little introduction...</description>
        <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//CISA-ICS-CTF-Follow-the-Charts.md/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//CISA-ICS-CTF-Follow-the-Charts.md/</guid>
        
        <category>CTF</category>
        
        <category>CISA</category>
        
        
      </item>
    
      <item>
        <title>2024 CISA ICS CTF - Extend Your Stay</title>
        <description>&lt;p&gt;Oh boy, we’re down to the final few challenges! We’re back in the Verbank category with “Extend Your Stay”. This time Virbank Medical has detected a suspicious browser add-on installed on a users device; The question is to RE the extension and identify the flag. Let’s dive into it!&lt;/p&gt; &lt;h3 id=&quot;extend-your-stay-1&quot;&gt;Extend Your Stay 1&lt;/h3&gt; &lt;p&gt;Okay, so we’re given a Chrome Extension (.crx) and we now need to do some analytical work on it. Like most things in live, proprietary file extensions are a fancy archive of sorts. There’s an awesome website out there &lt;a href=&quot;https://www.ezyzip.com/open-extract-crx-file.html&quot;&gt;ezyZip&lt;/a&gt; that allows us to extract...</description>
        <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//CISA-ICS-CTF-Extend-Your-Stay.md/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//CISA-ICS-CTF-Extend-Your-Stay.md/</guid>
        
        <category>CTF</category>
        
        <category>CISA</category>
        
        
      </item>
    
      <item>
        <title>ROP Emporium - Split</title>
        <description>&lt;p&gt;After a short nap and an Obsidian update, I’m back! This time we’re going to tackle Split32. We’re going to dive right into this guy and not spend as much time on initial theory unless relevant.&lt;/p&gt; &lt;h3 id=&quot;initial-program-usage--static-reing&quot;&gt;Initial Program Usage &amp;amp; Static REing&lt;/h3&gt; &lt;p&gt;We should always initially use the program like an actual user before we dive into any behavior so we get a solid understanding of how the application actually works.&lt;/p&gt; &lt;p&gt;&lt;img src=&quot;https://blog.spookysec.net/img/Pasted image 20240629201433.png&quot; alt=&quot;[https://blog.spookysec.net/img/Pasted image 20240629201433.png]&quot; /&gt; &lt;em&gt;Much like ret2win, it simply asks the user for input.&lt;/em&gt;&lt;/p&gt; &lt;p&gt;Great, now that we’re totally 100% sure that’s all the...</description>
        <pubDate>Sat, 29 Jun 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//ROP-Emporium-Split32/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//ROP-Emporium-Split32/</guid>
        
        <category>Linux</category>
        
        <category>Cyber</category>
        
        <category>Security</category>
        
        <category>Exploitation</category>
        
        
      </item>
    
      <item>
        <title>ROP Emporium - Ret2Win</title>
        <description>&lt;p&gt;Wow, it’s been a long while since I’ve written one of these things. Just over 7 months to be exact, going forward into ‘24, I should really be better about that.&lt;/p&gt; &lt;p&gt;Anyways, I’m traveling this weekend and just finished up SANS SEC660/GXPN (I passed btw!). One of my major weakpoints in offensive ops is Binary Exploitation - I really truly suck at it and this is kinda my last ditch effort to try to be good at it. After failing OSED last year, I kinda went into crisis mode and had a moment of clarity.&lt;/p&gt; &lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;It&apos;s...</description>
        <pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate>
        <link>https://blog.spookysec.net//ROP-Emporium-ret2win/</link>
        <guid isPermaLink="true">https://blog.spookysec.net//ROP-Emporium-ret2win/</guid>
        
        <category>Linux</category>
        
        <category>Cyber</category>
        
        <category>Security</category>
        
        <category>Exploitation</category>
        
        
      </item>
    
  </channel>
</rss>
