Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th)
When I’m teachning FOR610[1], I always say to my students that reverse engineering does not only...
Read MoreWhen I’m teachning FOR610[1], I always say to my students that reverse engineering does not only...
Read MoreIntroduction This diary describes a NetSupport RAT infection I generated in my lab from the...
Read MoreToday’s Microsoft Patch Tuesday offers fixes for 80 different vulnerabilities. One of the vulnerabilities is already being exploited, and five are rated as critical. Notable Vulnerabilities: %%cve:2025-62215%%: This...
Read MoreToday, I noticed scans using the username “FTP_3cx” showing up in our logs. 3CX is a well-known maker of business phone system software [1]. My first guess was that this was a default user for one of their systems....
Read MoreThis is just a quick diary entry to report that I saw requests on my honeypot for (code) repositories: /.git/logs/refs/remotes/origin/main /.git/objects/info /.github /.github/dependabot.yml /.github/funding.yml...
Read More[This is a Guest Diary by David Hammond, an ISC intern as part of the SANS.edu BACS program] My...
Read MoreFor several years, we have offered a “new domain” list of recently registered (or, more accurately, recently discovered) domains. This list is offered via our API (https://isc.sans.edu/api). However, the size of the...
Read MoreApple released its expected set of operating system upgrades. This is a minor feature upgrade that also includes fixes for 110 different vulnerabilities. As usual for Apple, many of the vulnerabilities affect multiple operating...
Read MoreXWiki describes itself as “The Advanced Open-Source Enterprise Wiki” and considers...
Read MoreSensors reporting firewall logs detected a significant increase in scans for port 8530/TCP and...
Read MoreThis week, I noticed some new HTTP request headers that I had not seen before: X-Request-Purpose:...
Read MoreI’ve been doing Unix/Linux IR and Forensics for a long time. I logged into a Unix system for...
Read More