Security Awareness? How do you keep your staff safe?, (Thu, May 7th)
If youve been following recent diaries from my fellow handlers Brad and Manuel, they peel the covers back on a couple current malicious emails campaigns. Many of the readers of the Storm Center diaries...
View ArticleISC StormCast for Friday, May 8th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMalicious Word Document: This Time The Maldoc Is A MIME File, (Sat, May 9th)
Bart Blaze Tweeted me a malicious Word document sample (MD5 23a2d596d927ceab01918cc1dfd5db68) that can not be analyzed with my oledump tool. It turns out to be a MIME file that contains a MSO file,...
View ArticleWireshark TCP Flags: How To Install On Windows Video, (Sun, May 10th)
I was asked how to install on Windows the Wireshark TCP Flags dissector I wrote about in a diary entry a month ago. To help these persons, I made a video. Didier Stevens Microsoft MVP Consumer Security...
View ArticleSOC Analyst Pyramid, (Mon, May 11th)
Introduction Last weekend, I did a 10 minute fireside chat during lunch at BSidesSATX 2015 [1]. It was an informal presentation, where I discussed some of the issues facing security analysts working at...
View ArticleISC StormCast for Monday, May 11th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Tuesday, May 12th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleAngler exploit kit pushes new variant of ransomware, (Tue, May 12th)
Introduction The Angler exploit kit (EK) is being used to push a new variant of TeslaCrypt/AlphaCrypt ransomware. Ive been documenting cases of Angler EK pushing AlphaCrypt in recent weeks [1][2][3]....
View ArticleRecent Dridex activity, (Wed, May 13th)
Introduction Botnet-based Dridex malspam is like the Energizer Bunny. It just wont quit. We see it almost every day. Since last year, botnet hosts pushing Dridex have been using macros in Microsoft...
View ArticleMay 2015 Microsoft Patch Tuesday Summary, (Tue, May 12th)
Overview of the May 2015 Microsoft patches and their status. # Affected Contra Indications - KB Known Exploits Microsoft rating(**) ISC rating(*) clients servers MS15-043 Cumulative Security Update for...
View ArticleISC StormCast for Wednesday, May 13th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleOh Bloat!, (Thu, May 14th)
I recently installed a new printer. Windows didnt seem to know its driver, so I had to supply the CD-ROM that came with the printer. Of course, being a device driver, it asked for admin privileges to...
View ArticleWireshark updates - check https://www.wireshark.org/download.html, (Thu, May...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Thursday, May 14th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Friday, May 15th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleAnother Maldoc? I'm Afraid So..., (Fri, May 15th)
Guess what? Yep, theres yet another type of malicious document going around. Like last time, it" /> Didier Stevens Microsoft MVP Consumer Security blog.DidierStevens.com DidierStevensLabs.com (c)...
View ArticleVENOM - Does it live up to the hype?, (Sat, May 16th)
Unless you have been hiding under a rock this week you have heard about VENOM. The first article that I saw was fromZDNet with the headline of Bigger than Heartbleed, Venom security vulnerability...
View ArticleISC StormCast for Monday, May 18th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleAddress spoofing vulnerability in Safari Web Browser, (Mon, May 18th)
A new vulnerability arised in Safari Web Browser that can lead to an address spoofing allowing attackers to show any URL address while loading a different web page. While this proof of concept is not...
View ArticleISC StormCast for Tuesday, May 19th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article