When Prevention Fails, Incident Response Begins, (Mon, Apr 27th)
Ive been asked a few times this year ($dayjob) to discuss and review incident handling practices with some of our clients. This topic seems to have come up to the surface again, and with some breaches...
View ArticleISC StormCast for Tuesday, April 28th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleActor using Fiesta exploit kit, (Tue, Apr 28th)
An Enduring Adversary This diary entry documents a criminal group using the Fiesta exploit kit (EK) to infect Windows computers. I previously wrote a guest diary about this group on 2014-12-26 [1] and...
View ArticleScammy Nepal earthquake donation requests, (Tue, Apr 28th)
Predictably, like after every major hurricane or earthquake, the miscreants around the globe are currently scurrying to set up their fake charities and web pages, in order to solicit donations. The...
View ArticleISC StormCast for Wednesday, April 29th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleUDP/3478 to Amazon 54.84.9.242 -- got packets? (solved), (Wed, Apr 29th)
Several readers are reporting UDP/3478 (STUN) traffic to Amazon AWS address 54.84.9.242. If you got packets or know what it is, please share below. Update Apr 29 19:30 UTC: Thanks everyone for pitching...
View ArticleDalexis/CTB-Locker malspam campaign, (Thu, Apr 30th)
MalwareEvery Day Malicious spam (malspam) is by sent by botnets every day. These malspam campaigns send malware designed to infect Windows computers. Ill see Dridex or Upatre/Dyre campaigns a daily...
View ArticleISC StormCast for Thursday, April 30th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Friday, May 1st 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMassive malware spam campain to corporate domains in Colombia, (Fri, May 1st)
There was a massive malware spam campain directed to corporate domains in Colombia. The following was the e-mail received: Now this e-mail has two interesting aspects: It is tracking if the user reads...
View ArticleNew release of Samurai Web Testing Framework...
----------- Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleVolDiff, for memory image differential analysis, (Sun, May 3rd)
VolDiff is a bash script that runs Volatility plugins against memory images captured before and after malware execution providing a differential analysis, helping identify IOCs and understand advanced...
View ArticleISC StormCast for Monday, May 4th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleTraffic pattern change noted in Fiesta exploit kit, (Mon, May 4th)
A few hours ago, Jerome Segura, Senior Security Researcher at Malwarebytes, tweeted about a change in traffic patterns from Fiesta exploit kit (EK) [1]. What had been semi-colons in the URLs from...
View ArticleUpatre/Dyre - the daily grind of botnet-based malspam, (Tue, May 5th)
Malicious spam (malspam) delivering Upatre/Dyre has been an ongoing issue for quite some time. Many organizations have posted articles about this malware. Ive read good information on Dyre last year...
View ArticleISC StormCast for Tuesday, May 5th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Wednesday, May 6th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleOUCH! May '15 Newseletter: Securing the Cyber Generation Gap -...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleThe Art of Logging, (Thu, May 7th)
[This is a Guest Diary by Xavier Mertens] Handling log files is not a new topic. For a long time, people should know that taking care of your logs is a must have. They are very valuable when you need...
View ArticleISC StormCast for Thursday, May 7th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article