• No Holiday Season for Attackers, (Tue, Dec 31st)

    Updated: 2024-12-31 07:09:10
    While most of us are preparing the switch to a new year (If it's already the case for you: Happy New Year!), Attackers never stop and implement always new tricks to defeat our security controls. For a long time now, we have been flooded by sextortion emails. This is a kind of blackmail where someone threatens to share explicit images or videos unless the victim meets their demands. Even today, I receive regularly some of them.

  • Phishing for Banking Information, (Fri, Dec 27th)

    Updated: 2024-12-27 10:25:02
    It is again the time of the year when scammers are asking to verify banking information, whether it is credit cards, bank card, package shipping information, winning money, etc. Last night I received a text message to verify a credit card, it is case a Bank of Montreal (BMO) credit card.

  • Capturing Honeypot Data Beyond the Logs, (Thu, Dec 26th)

    Updated: 2024-12-26 00:14:28
    By default, DShield Honeypots [1] collect firewall, web and cowrie (telnet/ssh) [2] data and log them on the local filesystem. A subset of this data is reported to the SANS Internet Storm Center (ISC) where it can be used by anyone [3]. A common question that comes up from new users is whether there is any benefit to collecting PCAP data from the honeypots if the active services are already being logged. One example I often give of a useful benefit of having PCAPs is HTTP POST data. This data is not currently captured within the web honeypot logs, but can be seen within the PCAP data.

  • Compiling Decompyle++ For Windows, (Wed, Dec 25th)

    Updated: 2024-12-25 07:58:25
    Occasionaly I decompile Python code, with decompilers written in Python. Recently I discovered Decompyle++, a Python disassembler & decompiler written in C++.

  • Modiloader From Obfuscated Batch File, (Mon, Dec 23rd)

    Updated: 2024-12-23 06:25:57
    My last investigation is a file called “Albertsons_payment.GZ”, received via email. The file looks like an archive but is identified as a picture by TrID:

  • Christmas "Gift" Delivered Through SSH, (Fri, Dec 20th)

    Updated: 2024-12-20 11:01:29
    Christmas is at our doors and Attackers use the holiday season to deliver always more and more gifts into our mailboxes&#;x26;#;x21; I found this interesting file this morning: "christmas&#;x26;#;x5f;slab.pdf.lnk"&#;x26;#;x5b;1&#;x26;#;x5d;. Link files (.lnk) are a classic way to execute something malicious on the victim&#;x26;#;39;s computer but the technique used here is interesting.

  • ISC Stormcast For Friday, December 20th, 2024 https://isc.sans.edu/podcastdetail/9264, (Fri, Dec 20th)

    Updated: 2024-12-20 02:00:02
    Christmas is at our doors and Attackers use the holiday season to deliver always more and more gifts into our mailboxes&#;x26;#;x21; I found this interesting file this morning: "christmas&#;x26;#;x5f;slab.pdf.lnk"&#;x26;#;x5b;1&#;x26;#;x5d;. Link files (.lnk) are a classic way to execute something malicious on the victim&#;x26;#;39;s computer but the technique used here is interesting.

Previous Months Items

Dec 2024 | Nov 2024 | Oct 2024 | Sep 2024 | Aug 2024 | Jul 2024