Internet Storm Center
Sign In
Sign Up
Handler on Duty:
Jan Kopriva
Threat Level:
green
Date
Author
Title
QUASAR RAT
2019-09-25
Brad Duncan
Malspam pushing Quasar RAT
QUASAR
2023-11-18/a>
Xavier Mertens
Quasar RAT Delivered Through Updated SharpLoader
2023-06-16/a>
Xavier Mertens
Another RAT Delivered Through VBS
2022-03-11/a>
Xavier Mertens
Keep an Eye on WebSockets
2019-09-25/a>
Brad Duncan
Malspam pushing Quasar RAT
RAT
2024-11-05/a>
Xavier Mertens
Python RAT with a Nice Screensharing Feature
2024-08-14/a>
Xavier Mertens
Multiple Malware Dropped Through MSI Package
2024-06-17/a>
Xavier Mertens
New NetSupport Campaign Delivered Through MSIX Packages
2024-05-31/a>
Xavier Mertens
"K1w1" InfoStealer Uses gofile.io for Exfiltration
2024-03-28/a>
Xavier Mertens
From JavaScript to AsyncRAT
2023-12-23/a>
Xavier Mertens
Python Keylogger Using Mailtrap.io
2023-12-20/a>
Guy Bruneau
How to Protect your Webserver from Directory Enumeration Attack ? Apache2 [Guest Diary]
2023-11-18/a>
Xavier Mertens
Quasar RAT Delivered Through Updated SharpLoader
2023-08-20/a>
Guy Bruneau
SystemBC Malware Activity
2023-08-18/a>
Xavier Mertens
From a Zalando Phishing to a RAT
2023-08-11/a>
Xavier Mertens
Show me All Your Windows!
2023-06-29/a>
Brad Duncan
GuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT
2023-06-16/a>
Xavier Mertens
Another RAT Delivered Through VBS
2023-05-30/a>
Brad Duncan
Malspam pushes ModiLoader (DBatLoader) infection for Remcos RAT
2023-05-20/a>
Xavier Mertens
Phishing Kit Collecting Victim's IP Address
2023-05-19/a>
Xavier Mertens
When the Phisher Messes Up With Encoding
2023-05-14/a>
Guy Bruneau
VMware Aria Operations addresses multiple Local Privilege Escalations and a Deserialization issue
2023-05-07/a>
Didier Stevens
Quickly Finding Encoded Payloads in Office Documents
2023-05-03/a>
Xavier Mertens
Increased Number of Configuration File Scans
2023-03-12/a>
Guy Bruneau
AsynRAT Trojan - Bill Payment (Pago de la factura)
2023-03-11/a>
Xavier Mertens
Overview of a Mirai Payload Generator
2022-10-21/a>
Brad Duncan
sczriptzzbn inject pushes malware for NetSupport RAT
2022-09-22/a>
Xavier Mertens
RAT Delivered Through FODHelper
2022-07-28/a>
Johannes Ullrich
Exfiltrating Data With Bookmarks
2022-06-16/a>
Xavier Mertens
Houdini is Back Delivered Through a JavaScript Dropper
2022-06-04/a>
Guy Bruneau
Spam Email Contains a Very Large ISO file
2022-05-20/a>
Xavier Mertens
A 'Zip Bomb' to Bypass Security Controls & Sandboxes
2022-05-05/a>
Brad Duncan
Password-protected Excel spreadsheet pushes Remcos RAT
2022-05-03/a>
Rob VandenBrink
Finding the Real "Last Patched" Day (Interim Version)
2022-03-11/a>
Xavier Mertens
Keep an Eye on WebSockets
2022-03-09/a>
Xavier Mertens
Infostealer in a Batch File
2022-02-18/a>
Xavier Mertens
Remcos RAT Delivered Through Double Compressed Archive
2022-02-11/a>
Xavier Mertens
CinaRAT Delivered Through HTML ID Attributes
2022-01-07/a>
Xavier Mertens
Custom Python RAT Builder
2021-12-01/a>
Xavier Mertens
Info-Stealer Using webhook.site to Exfiltrate Data
2021-11-04/a>
Brad Duncan
October 2021 Forensic Contest: Answers and Analysis
2021-09-01/a>
Brad Duncan
STRRAT: a Java-based RAT that doesn't care if you have Java
2021-06-21/a>
Rick Wanner
Mitre CWE - Common Weakness Enumeration
2021-04-09/a>
Xavier Mertens
No Python Interpreter? This Simple RAT Installs Its Own Copy
2021-03-31/a>
Xavier Mertens
Quick Analysis of a Modular InfoStealer
2021-03-04/a>
Xavier Mertens
From VBS, PowerShell, C Sharp, Process Hollowing to RAT
2021-02-24/a>
Brad Duncan
Malspam pushes GuLoader for Remcos RAT
2021-02-04/a>
Bojan Zdrnja
Abusing Google Chrome extension syncing for data exfiltration and C&C
2020-10-14/a>
Xavier Mertens
Nicely Obfuscated Python RAT
2020-09-30/a>
Johannes Ullrich
Scans for FPURL.xml: Reconnaissance or Not?
2020-09-28/a>
Xavier Mertens
Some Tyler Technologies Customers Targeted with The Installation of a Bomgar Client
2020-08-25/a>
Xavier Mertens
Keep An Eye on LOLBins
2020-08-18/a>
Xavier Mertens
Using API's to Track Attackers
2020-08-10/a>
Bojan Zdrnja
Scoping web application and web service penetration tests
2020-08-04/a>
Johannes Ullrich
Internet Choke Points: Concentration of Authoritative Name Servers
2020-05-14/a>
Rob VandenBrink
Patch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe
2020-04-17/a>
Xavier Mertens
Weaponized RTF Document Generator & Mailer in PowerShell
2020-02-05/a>
Brad Duncan
Fake browser update pages are "still a thing"
2020-01-10/a>
Xavier Mertens
More Data Exfiltration
2019-10-29/a>
Xavier Mertens
Generating PCAP Files from YAML
2019-09-27/a>
Xavier Mertens
New Scans for Polycom Autoconfiguration Files
2019-09-25/a>
Brad Duncan
Malspam pushing Quasar RAT
2019-09-19/a>
Xavier Mertens
Agent Tesla Trojan Abusing Corporate Email Accounts
2019-09-19/a>
Xavier Mertens
Blocklisting or Whitelisting in the Right Way
2019-04-26/a>
Rob VandenBrink
Pillaging Passwords from Service Accounts
2019-04-24/a>
Rob VandenBrink
Where have all the Domain Admins gone? Rooting out Unwanted Domain Administrators
2019-03-06/a>
Xavier Mertens
Keep an Eye on Disposable Email Addresses
2018-11-27/a>
Rob VandenBrink
Data Exfiltration in Penetration Tests
2018-09-19/a>
Rob VandenBrink
Certificates Revisited - SSL VPN Certificates 2 Ways
2018-09-05/a>
Rob VandenBrink
Where have all my Certificates gone? (And when do they expire?)
2018-08-24/a>
Xavier Mertens
Microsoft Publisher Files Delivering Malware
2018-06-15/a>
Lorna Hutcheson
SMTP Strangeness - Possible C2
2018-05-19/a>
Xavier Mertens
Malicious Powershell Targeting UK Bank Customers
2018-05-10/a>
Bojan Zdrnja
Exfiltrating data from (very) isolated environments
2017-12-13/a>
Xavier Mertens
Tracking Newly Registered Domains
2017-11-03/a>
Xavier Mertens
Simple Analysis of an Obfuscated JAR File
2017-08-17/a>
Xavier Mertens
Maldoc with auto-updated link
2017-06-08/a>
Tom Webb
Summer STEM for Kids
2017-05-10/a>
Johannes Ullrich
Read This If You Are Using a Script to Pull Data From This Site
2017-04-20/a>
Xavier Mertens
DNS Query Length... Because Size Does Matter
2016-09-04/a>
Russ McRee
Kali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/
2016-07-26/a>
Johannes Ullrich
Command and Control Channels Using "AAAA" DNS Records
2016-06-15/a>
Richard Porter
Warp Speed Ahead, L7 Open Source Packet Generator: Warp17
2016-04-02/a>
Russell Eubanks
Why Can't We Be Friends?
2015-12-24/a>
Xavier Mertens
Unity Makes Strength
2015-11-09/a>
John Bambenek
Protecting Users and Enterprises from the Mobile Malware Threat
2015-09-03/a>
Xavier Mertens
Querying the DShield API from RTIR
2014-08-22/a>
Richard Porter
OCLHashCat 1.30 Released
2014-08-09/a>
Adrien de Beaupre
Complete application ownage via Multi-POST XSRF
2014-07-19/a>
Russ McRee
Keeping the RATs out: the trap is sprung - Part 3
2014-07-18/a>
Russ McRee
Keeping the RATs out: **it happens - Part 2
2014-07-16/a>
Russ McRee
Keeping the RATs out: an exercise in building IOCs - Part 1
2014-03-13/a>
Daniel Wesemann
Identification and authentication are hard ... finding out intention is even harder
2013-06-18/a>
Russ McRee
Volatility rules...any questions?
2013-04-25/a>
Adam Swanger
Guest Diary: Dylan Johnson - A week in the life of some Perimeter Firewalls
2013-04-17/a>
John Bambenek
UPDATEDx1: Boston-Related Malware Campaigns Have Begun - Now with Waco Plant Explosion Fun
2013-04-16/a>
John Bambenek
Fake Boston Marathon Scams Update
2013-04-15/a>
John Bambenek
Please send any spam (full headers), URLs or other suspicious content scamming off Boston Marathon explosions to handlers@sans.org
2013-03-03/a>
Richard Porter
Uptick in MSSQL Activity
2013-02-06/a>
Johannes Ullrich
Are you losing system logging information (and don't know it)?
2012-10-30/a>
Mark Hofman
Cyber Security Awareness Month - Day 30 - DSD 35 mitigating controls
2012-05-22/a>
Johannes Ullrich
nmap 6 released
2012-01-03/a>
Rick Wanner
Analysis of the Stratfor Password List
2011-12-25/a>
Deborah Hale
Another Company Falls Victim
2011-10-26/a>
Rick Wanner
Critical Control 17:Penetration Tests and Red Team Exercises
2010-10-03/a>
Adrien de Beaupre
Canada's Cyber Security Strategy released today
2010-08-23/a>
Manuel Humberto Santander Pelaez
Firefox plugins to perform penetration testing activities
2010-08-16/a>
Raul Siles
Blind Elephant: A New Web Application Fingerprinting Tool
2010-07-08/a>
Kyle Haugsness
Pirate Bay account database compromised
2010-06-06/a>
Manuel Humberto Santander Pelaez
Nice OS X exploit tutorial
2010-04-13/a>
Adrien de Beaupre
Web App Testing Tools
2010-03-06/a>
Tony Carothers
Integration and the Security of New Technologies
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
2009-07-27/a>
Raul Siles
New Hacker Challenge: Prison Break - Breaking, Entering & Decoding
2009-04-21/a>
Bojan Zdrnja
Web application vulnerabilities
2009-01-20/a>
Adrien de Beaupre
Obamamania
2008-11-25/a>
Andre Ludwig
The beginnings of a collaborative approach to IDS
2008-09-20/a>
Rick Wanner
New (to me) nmap Features
2008-07-18/a>
Adrien de Beaupre
Exit process?
2008-03-30/a>
Mark Hofman
Mail Anyone?
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Contact Us
Contact Us
About Us
Handlers
About Us
Slack Channel
Mastodon
Bluesky
X
Learn
about the Internet Storm Center
and our
volunteer InfoSec handlers