Hexacorn
banner
hexacorn.bsky.social
Hexacorn
@hexacorn.bsky.social
Red Brain, Blue Fingers

Malware Analysis, Reverse Engineering, Threat Hunting, Detection Engineering, DFIR, Security Research, Programming, Curiosities, Software Archaeology, Puzzles, Bad dad jokes

https://www.hexacorn.com/blog/
hexacorn@infosec.exchange
less known way to calculate sha256 of files on Windows

disksnapshot -c -k -v c:\test

will print out file info including sha256 for every file in the directory
November 14, 2025 at 7:35 PM
no idea :(
but it does include this:
August 20, 2025 at 10:52 PM
found one unsigned from Reaqltek

www.virustotal.com/gui/file/011...

testker -> kerberos.Spinitialize
August 20, 2025 at 9:23 PM
Life of a blogger
August 14, 2025 at 1:50 PM
clever carding page

hxxps://gov[.]comsitebab[.]life/gov

when you visit from the desktop, it's just a regular website (although compromised)

when you visit from a smartphone, you get a fake gov web site that harvests your CC details
June 16, 2025 at 2:07 PM
Glad Skype data deletion works
May 6, 2025 at 12:03 PM
I broke the window(s)!
February 20, 2025 at 11:35 AM
a sign like this would lead to questions

what about the weekends?
February 3, 2025 at 3:30 PM
How to deal with Gemini, totally random attempt lulz
January 31, 2025 at 5:45 PM
the new, upgrded bundle coming to 3 billion devices
January 26, 2025 at 10:18 AM
come to think of it, it's actually pretty easy; probably can be simplified but I wanted 4 chars as anchors at the front
December 8, 2024 at 3:19 PM
1 little known secret of ShellExec_RunDLL

www.hexacorn.com/blog/2024/11...

#lolbin
November 30, 2024 at 10:41 AM
I had a facebook account for a very short time in 2011 or so; then I deleted the account; only to receive this 13 years later

I guess nothing ever gets deleted
November 26, 2024 at 11:15 AM
Beyond good ol’ Run key, Part 144

www.hexacorn.com/blog/2024/11...
November 15, 2024 at 10:17 PM
Beyond good ol’ Run key, Part 143

www.hexacorn.com/blog/2024/10...
October 19, 2024 at 10:24 PM
advpack.dll and IEAdvpack.dll logging capability

www.hexacorn.com/blog/2024/10...
October 19, 2024 at 9:10 PM
Just a new #lolbin - sweet16 I mean, setup16

c:\windows\SysWOW64\setup16.exe

blog post to follow
October 12, 2024 at 6:54 AM
Rundll32 goes to hell...

www.hexacorn.com/blog/2024/09...
September 21, 2024 at 10:44 PM
September 11, 2024 at 10:09 PM
Technical debt of C:\Windows\System path

www.hexacorn.com/blog/2024/09...
September 5, 2024 at 9:10 PM
Rundll32 and Phantom DLL lolbins, 32-bit version

www.hexacorn.com/blog/2024/09...

#lolbin
September 4, 2024 at 9:02 PM
Rundll32 and Phantom DLL lolbins

hexacorn.com/blog/2024/09...

a kinda novelty lolbin-phantom DLL combo

#lolbin
September 3, 2024 at 9:42 PM
1 little known secret of forfiles.exe

www.hexacorn.com/blog/2023/12...

#lolbin
December 31, 2023 at 10:22 AM
1 little known secret of regsvr32.exe, take three

www.hexacorn.com/blog/2023/12...

aka regsvr32.exe bomb

#lolbin #dolbin
December 28, 2023 at 11:16 PM
1 little known secret of regsvr32.exe, take two

www.hexacorn.com/blog/2023/12...

#lolbin
December 27, 2023 at 12:10 AM