KongTuke activity, (Tue, Nov 18th)
Introduction Today’s diary is an example of KongTuke activity using fake CAPTCHA pages for a...
Read MoreIntroduction Today’s diary is an example of KongTuke activity using fake CAPTCHA pages for a...
Read MoreIn diary entry “Formbook Delivered Through Multiple Scripts”, Xavier mentions that the following line: Nestlers= array(79+1,79,80+7,60+9,82,83,72,69,76,76) decodes to the string POWERSHELL. My tool numbers-to-hex.py...
Read MoreThe finger.exe command is used in ClickFix attacks. finger is a very old UNIX command, that was converted to a Windows executable years ago, and is part of Windows since then. In the ClickFix attacks, it is used to retrieve a...
Read MoreThe SANS Holiday Hack Challenge™ 2025 is available. (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Read MoreLike many have reported, we too noticed exploit attempts for CVE-2025-64446 in our honeypots. These are POST requests to this path: With this User Agent String: And this is the data of the POST request: This creates a new admin...
Read MoreYou probably know what are the Russian or Matryoshka dolls. It’s a set of wooden dolls of...
Read MoreWhen I’m teachning FOR610[1], I always say to my students that reverse engineering does not only...
Read MoreIntroduction This diary describes a NetSupport RAT infection I generated in my lab from the...
Read MoreToday’s Microsoft Patch Tuesday offers fixes for 80 different vulnerabilities. One of the vulnerabilities is already being exploited, and five are rated as critical. Notable Vulnerabilities: %%cve:2025-62215%%: This...
Read MoreToday, I noticed scans using the username “FTP_3cx” showing up in our logs. 3CX is a well-known maker of business phone system software [1]. My first guess was that this was a default user for one of their systems....
Read MoreThis is just a quick diary entry to report that I saw requests on my honeypot for (code) repositories: /.git/logs/refs/remotes/origin/main /.git/objects/info /.github /.github/dependabot.yml /.github/funding.yml...
Read More[This is a Guest Diary by David Hammond, an ISC intern as part of the SANS.edu BACS program] My...
Read More