Internet Storm Center
Sign In
Sign Up
Participate: Learn more about our honeypot network
https://isc.sans.edu/tools/honeypot/
Handler on Duty:
Didier Stevens
Threat Level:
green
Date
Author
Title
NETSUPPORT RAT
2020-02-05
Brad Duncan
Fake browser update pages are "still a thing"
NETSUPPORT
2022-10-21/a>
Brad Duncan
sczriptzzbn inject pushes malware for NetSupport RAT
2020-02-05/a>
Brad Duncan
Fake browser update pages are "still a thing"
RAT
2023-03-12/a>
Guy Bruneau
AsynRAT Trojan - Bill Payment (Pago de la factura)
2023-03-11/a>
Xavier Mertens
Overview of a Mirai Payload Generator
2022-10-21/a>
Brad Duncan
sczriptzzbn inject pushes malware for NetSupport RAT
2022-09-22/a>
Xavier Mertens
RAT Delivered Through FODHelper
2022-07-28/a>
Johannes Ullrich
Exfiltrating Data With Bookmarks
2022-06-16/a>
Xavier Mertens
Houdini is Back Delivered Through a JavaScript Dropper
2022-06-04/a>
Guy Bruneau
Spam Email Contains a Very Large ISO file
2022-05-20/a>
Xavier Mertens
A 'Zip Bomb' to Bypass Security Controls & Sandboxes
2022-05-05/a>
Brad Duncan
Password-protected Excel spreadsheet pushes Remcos RAT
2022-05-03/a>
Rob VandenBrink
Finding the Real "Last Patched" Day (Interim Version)
2022-03-11/a>
Xavier Mertens
Keep an Eye on WebSockets
2022-03-09/a>
Xavier Mertens
Infostealer in a Batch File
2022-02-18/a>
Xavier Mertens
Remcos RAT Delivered Through Double Compressed Archive
2022-02-11/a>
Xavier Mertens
CinaRAT Delivered Through HTML ID Attributes
2022-01-07/a>
Xavier Mertens
Custom Python RAT Builder
2021-12-01/a>
Xavier Mertens
Info-Stealer Using webhook.site to Exfiltrate Data
2021-11-04/a>
Brad Duncan
October 2021 Forensic Contest: Answers and Analysis
2021-09-01/a>
Brad Duncan
STRRAT: a Java-based RAT that doesn't care if you have Java
2021-06-21/a>
Rick Wanner
Mitre CWE - Common Weakness Enumeration
2021-04-09/a>
Xavier Mertens
No Python Interpreter? This Simple RAT Installs Its Own Copy
2021-03-31/a>
Xavier Mertens
Quick Analysis of a Modular InfoStealer
2021-03-04/a>
Xavier Mertens
From VBS, PowerShell, C Sharp, Process Hollowing to RAT
2021-02-24/a>
Brad Duncan
Malspam pushes GuLoader for Remcos RAT
2021-02-04/a>
Bojan Zdrnja
Abusing Google Chrome extension syncing for data exfiltration and C&C
2020-10-14/a>
Xavier Mertens
Nicely Obfuscated Python RAT
2020-09-30/a>
Johannes Ullrich
Scans for FPURL.xml: Reconnaissance or Not?
2020-09-28/a>
Xavier Mertens
Some Tyler Technologies Customers Targeted with The Installation of a Bomgar Client
2020-08-25/a>
Xavier Mertens
Keep An Eye on LOLBins
2020-08-18/a>
Xavier Mertens
Using API's to Track Attackers
2020-08-10/a>
Bojan Zdrnja
Scoping web application and web service penetration tests
2020-08-04/a>
Johannes Ullrich
Internet Choke Points: Concentration of Authoritative Name Servers
2020-05-14/a>
Rob VandenBrink
Patch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe
2020-04-17/a>
Xavier Mertens
Weaponized RTF Document Generator & Mailer in PowerShell
2020-02-05/a>
Brad Duncan
Fake browser update pages are "still a thing"
2020-01-10/a>
Xavier Mertens
More Data Exfiltration
2019-10-29/a>
Xavier Mertens
Generating PCAP Files from YAML
2019-09-27/a>
Xavier Mertens
New Scans for Polycom Autoconfiguration Files
2019-09-25/a>
Brad Duncan
Malspam pushing Quasar RAT
2019-09-19/a>
Xavier Mertens
Agent Tesla Trojan Abusing Corporate Email Accounts
2019-09-19/a>
Xavier Mertens
Blocklisting or Whitelisting in the Right Way
2019-04-26/a>
Rob VandenBrink
Pillaging Passwords from Service Accounts
2019-04-24/a>
Rob VandenBrink
Where have all the Domain Admins gone? Rooting out Unwanted Domain Administrators
2019-03-06/a>
Xavier Mertens
Keep an Eye on Disposable Email Addresses
2018-11-27/a>
Rob VandenBrink
Data Exfiltration in Penetration Tests
2018-09-19/a>
Rob VandenBrink
Certificates Revisited - SSL VPN Certificates 2 Ways
2018-09-05/a>
Rob VandenBrink
Where have all my Certificates gone? (And when do they expire?)
2018-08-24/a>
Xavier Mertens
Microsoft Publisher Files Delivering Malware
2018-06-15/a>
Lorna Hutcheson
SMTP Strangeness - Possible C2
2018-05-19/a>
Xavier Mertens
Malicious Powershell Targeting UK Bank Customers
2018-05-10/a>
Bojan Zdrnja
Exfiltrating data from (very) isolated environments
2017-12-13/a>
Xavier Mertens
Tracking Newly Registered Domains
2017-11-03/a>
Xavier Mertens
Simple Analysis of an Obfuscated JAR File
2017-08-17/a>
Xavier Mertens
Maldoc with auto-updated link
2017-06-08/a>
Tom Webb
Summer STEM for Kids
2017-05-10/a>
Johannes Ullrich
Read This If You Are Using a Script to Pull Data From This Site
2017-04-20/a>
Xavier Mertens
DNS Query Length... Because Size Does Matter
2016-09-04/a>
Russ McRee
Kali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/
2016-07-26/a>
Johannes Ullrich
Command and Control Channels Using "AAAA" DNS Records
2016-06-15/a>
Richard Porter
Warp Speed Ahead, L7 Open Source Packet Generator: Warp17
2016-04-02/a>
Russell Eubanks
Why Can't We Be Friends?
2015-12-24/a>
Xavier Mertens
Unity Makes Strength
2015-11-09/a>
John Bambenek
Protecting Users and Enterprises from the Mobile Malware Threat
2015-09-03/a>
Xavier Mertens
Querying the DShield API from RTIR
2014-08-22/a>
Richard Porter
OCLHashCat 1.30 Released
2014-08-09/a>
Adrien de Beaupre
Complete application ownage via Multi-POST XSRF
2014-07-19/a>
Russ McRee
Keeping the RATs out: the trap is sprung - Part 3
2014-07-18/a>
Russ McRee
Keeping the RATs out: **it happens - Part 2
2014-07-16/a>
Russ McRee
Keeping the RATs out: an exercise in building IOCs - Part 1
2014-03-13/a>
Daniel Wesemann
Identification and authentication are hard ... finding out intention is even harder
2013-06-18/a>
Russ McRee
Volatility rules...any questions?
2013-04-25/a>
Adam Swanger
Guest Diary: Dylan Johnson - A week in the life of some Perimeter Firewalls
2013-04-17/a>
John Bambenek
UPDATEDx1: Boston-Related Malware Campaigns Have Begun - Now with Waco Plant Explosion Fun
2013-04-16/a>
John Bambenek
Fake Boston Marathon Scams Update
2013-04-15/a>
John Bambenek
Please send any spam (full headers), URLs or other suspicious content scamming off Boston Marathon explosions to handlers@sans.org
2013-03-03/a>
Richard Porter
Uptick in MSSQL Activity
2013-02-06/a>
Johannes Ullrich
Are you losing system logging information (and don't know it)?
2012-10-30/a>
Mark Hofman
Cyber Security Awareness Month - Day 30 - DSD 35 mitigating controls
2012-05-22/a>
Johannes Ullrich
nmap 6 released
2012-01-03/a>
Rick Wanner
Analysis of the Stratfor Password List
2011-12-25/a>
Deborah Hale
Another Company Falls Victim
2011-10-26/a>
Rick Wanner
Critical Control 17:Penetration Tests and Red Team Exercises
2010-10-03/a>
Adrien de Beaupre
Canada's Cyber Security Strategy released today
2010-08-23/a>
Manuel Humberto Santander Pelaez
Firefox plugins to perform penetration testing activities
2010-08-16/a>
Raul Siles
Blind Elephant: A New Web Application Fingerprinting Tool
2010-07-08/a>
Kyle Haugsness
Pirate Bay account database compromised
2010-06-06/a>
Manuel Humberto Santander Pelaez
Nice OS X exploit tutorial
2010-04-13/a>
Adrien de Beaupre
Web App Testing Tools
2010-03-06/a>
Tony Carothers
Integration and the Security of New Technologies
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
2009-07-27/a>
Raul Siles
New Hacker Challenge: Prison Break - Breaking, Entering & Decoding
2009-04-21/a>
Bojan Zdrnja
Web application vulnerabilities
2009-01-20/a>
Adrien de Beaupre
Obamamania
2008-11-25/a>
Andre Ludwig
The beginnings of a collaborative approach to IDS
2008-09-20/a>
Rick Wanner
New (to me) nmap Features
2008-07-18/a>
Adrien de Beaupre
Exit process?
2008-03-30/a>
Mark Hofman
Mail Anyone?
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Forums
Auditing
Diary Discussions
Forensics
General Discussions
Industry News
Network Security
Penetration Testing
Software Security
Contact Us
Contact Us
About Us
Handlers
Slack Channel
Mastodon
Twitter
Subscribe to the daily podcast via
RSS
or
iTunes