Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: Diaries by Keyword Diaries by Keyword

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

EXCEL 4

2020-04-05Guy BruneauMaldoc XLS Invoice with Excel 4 Macros
2019-03-17Didier StevensVideo: Maldoc Analysis: Excel 4.0 Macro
2019-03-16Didier StevensMaldoc: Excel 4.0 Macros

EXCEL

2020-06-12/a>Xavier MertensMalicious Excel Delivering Fileless Payload
2020-06-01/a>Didier StevensXLMMacroDeobfuscator: An Update
2020-04-24/a>Xavier MertensMalicious Excel With a Strong Obfuscation and Sandbox Evasion
2020-04-05/a>Guy BruneauMaldoc XLS Invoice with Excel 4 Macros
2020-03-29/a>Didier StevensObfuscated Excel 4 Macros
2020-03-09/a>Didier StevensMalicious Spreadsheet With Data Connection and Excel 4 Macros
2020-03-06/a>Xavier MertensA Safe Excel Sheet Not So Safe
2020-02-24/a>Didier StevensMaldoc: Excel 4 Macros and VBA, Devil and Angel?
2020-02-23/a>Didier StevensMaldoc: Excel 4 Macros in OOXML Format
2019-11-08/a>Xavier MertensMicrosoft Apps Diverted from Their Main Use
2019-03-25/a>Didier Stevens"VelvetSweatshop" Maldocs: Shellcode Analysis
2019-03-23/a>Didier Stevens"VelvetSweatshop" Maldocs
2019-03-17/a>Didier StevensVideo: Maldoc Analysis: Excel 4.0 Macro
2019-03-16/a>Didier StevensMaldoc: Excel 4.0 Macros
2018-10-10/a>Xavier MertensNew Campaign Using Old Equation Editor Vulnerability
2018-09-28/a>Xavier MertensMore Excel DDE Code Injection
2018-05-22/a>Xavier MertensMalware Distributed via .slk Files
2018-02-02/a>Xavier MertensSimple but Effective Malicious XLS Sheet
2018-01-14/a>Didier StevensPeeking into Excel files
2017-04-19/a>Xavier MertensHunting for Malicious Excel Sheets
2015-05-15/a>Didier StevensAnother Maldoc? I'm Afraid So...
2010-03-09/a>John BambenekMarch 2010 - Microsoft Patch Tuesday Diary
2009-07-13/a>Adrien de BeaupreVulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution

4

2020-08-04/a>Johannes UllrichReminder: Patch Cisco ASA / FTD Devices (CVE-2020-3452). Exploitation Continues
2020-06-30/a>Russ McReeISC Snapshot: SpectX IP Hitcount Query
2020-06-27/a>Didier StevensVideo: YARA's BASE64 Strings
2020-06-14/a>Didier StevensYARA's BASE64 Strings
2020-06-08/a>Didier StevensTranslating BASE64 Obfuscated Scripts
2020-06-01/a>Didier StevensXLMMacroDeobfuscator: An Update
2020-05-30/a>Didier StevensYARA v4.0.1
2020-05-19/a>Rick WannerWhat is up on Port 62234?
2020-05-14/a>Rob VandenBrinkPatch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe
2020-05-10/a>Didier StevensYARA v4.0.0: BASE64 Strings
2020-04-21/a>Russ McReeSpectX: Log Parser for DFIR
2020-04-05/a>Guy BruneauMaldoc XLS Invoice with Excel 4 Macros
2020-03-29/a>Didier StevensObfuscated Excel 4 Macros
2020-03-09/a>Didier StevensMalicious Spreadsheet With Data Connection and Excel 4 Macros
2020-02-24/a>Didier StevensMaldoc: Excel 4 Macros and VBA, Devil and Angel?
2020-02-23/a>Didier StevensMaldoc: Excel 4 Macros in OOXML Format
2019-10-27/a>Guy BruneauUnusual Activity with Double Base64 Encoding
2019-08-01/a>Johannes UllrichWhat is Listening On Port 9527/TCP?
2019-07-26/a>Kevin ShorttDVRIP Port 34567 - Uptick
2019-06-03/a>Didier StevensTip: BASE64 Encoded PowerShell Scripts are Recognizable by the Amount of Letter As
2019-03-30/a>Didier Stevens"404" is not Malware
2019-03-17/a>Didier StevensVideo: Maldoc Analysis: Excel 4.0 Macro
2019-03-16/a>Didier StevensMaldoc: Excel 4.0 Macros
2018-08-20/a>Didier StevensOpenSSH user enumeration (CVE-2018-15473)
2018-07-18/a>Kevin ListonRequest for Packets: Port 15454
2018-02-02/a>Xavier MertensSimple but Effective Malicious XLS Sheet
2017-08-24/a>Bojan ZdrnjaFree Bitcoins? Why not?
2017-07-19/a>Xavier MertensBots Searching for Keys & Config Files
2017-07-08/a>Xavier MertensA VBScript with Obfuscated Base64 Data
2017-03-19/a>Xavier MertensSearching for Base64-encoded PE Files
2017-02-28/a>Johannes UllrichMy Catch Of 4 Months In The Amazon IP Address Space
2016-11-24/a>Didier StevensExtracting Shellcode From JavaScript
2016-10-22/a>Guy BruneauRequest for Packets TCP 4786 - CVE-2016-6385
2016-05-16/a>Rick WannerAn oldie but a goodie - 419 Death Scam
2016-02-13/a>Guy BruneauVMware VMSA-2015-0007.3 has been Re-released
2015-07-05/a>Didier StevensWorking with base64
2015-06-16/a>John BambenekCVE-2014-4114 and an Interesting AV Bypass Technique
2015-04-15/a>Johannes UllrichMS15-034: HTTP.sys (IIS) DoS And Possible Remote Code Execution. PATCH NOW
2014-10-09/a>Johannes UllrichCSAM: My servers started speaking IRC, and that is when I started to listen!
2014-10-06/a>Johannes UllrichCSAM: Patch and get pw0ned (not OR).
2014-10-03/a>Johannes UllrichCSAM: The Power of Virustotal to Turn Harmless Binaries Malicious
2014-10-02/a>Johannes UllrichCSAM: My Storage Array SSHs Outbound!
2014-09-25/a>Johannes UllrichUpdate on CVE-2014-6271: Vulnerability in bash (shellshock)
2014-09-24/a>Pedro BuenoAttention *NIX admins, time to patch!
2014-09-22/a>Johannes UllrichCyber Security Awareness Month: What's your favorite/most scary false positive
2014-08-17/a>Rick WannerPart 2: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-07-07/a>Johannes UllrichMulti Platform *Coin Miner Attacking Routers on Port 32764
2014-06-30/a>Johannes UllrichShould I setup a Honeypot? [SANSFIRE]
2014-06-12/a>Johannes UllrichMetasploit now includes module to exploit CVE-2014-0195 (OpenSSL DTLS Fragment Vuln.)
2014-05-23/a>Richard PorterHighlights from Cisco Live 2014 - The Internet of Everything
2014-05-21/a>John BambenekNew, Unpatched IE 0 Day published at ZDI
2014-04-08/a>Guy BruneauOpenSSL CVE-2014-0160 Fixed
2014-03-24/a>Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-02/a>Stephen HallSymantec goes yellow
2014-02-07/a>Rob VandenBrinkNew ISO Standards on Vulnerability Handling and Disclosure
2013-12-06/a>Guy BruneauVMware ESX 4.x Security Advisory
2013-11-14/a>Johannes UllrichiOS 7.0.4 released. Fixes issue with unauthorized in App purchases http://lists.apple.com/archives/security-announce/2013/Nov/msg00000.html
2013-06-20/a>Guy BruneauHP iLO3/iLO4 Remote Unauthorized Access with Single-Sign-On
2013-05-09/a>Johannes UllrichMicrosoft released a Fix-it for the Internet Explorer 8 Vulnerability http://support.microsoft.com/kb/2847140
2013-03-25/a>Johannes UllrichIPv6 Focus Month: IPv6 over IPv4 Preference
2013-03-18/a>Kevin ShorttCisco IOS Type 4 Password Issue: http://tools.cisco.com/security/center/content/CiscoSecurityResponse/cisco-sr-20130318-type4
2013-03-09/a>Guy BruneauIPv6 Focus Month: IPv6 Encapsulation - Protocol 41
2013-02-22/a>Chris MohanPHP 5.4.12 and PHP 5.3.22 released http://www.php.net/ChangeLog-5.php
2013-01-19/a>Guy BruneauJava 7 Update 11 Still has a Flaw
2013-01-04/a>Guy Bruneau"FixIt" Patch for CVE-2012-4792 Bypassed
2012-09-21/a>Guy BruneauIE Cumulative Updates MS12-063 - KB2744842
2012-07-18/a>Rob VandenBrinkVote NO to Weak Keys!
2012-06-25/a>Guy BruneauIssues with Windows Update Agent
2012-04-12/a>Guy BruneauHP ProCurve 5400 zl Switch, Flash Cards Infected with Malware
2012-01-12/a>Rob VandenBrinkPHP 5.39 was release on the 10th, amongst other things, it addresses CVE-2011-4885 (prevents attacks based on hash collisions) and CVE-2011-4566 (integer overflow when parsing invalid exif header)
2011-08-11/a>Johannes UllrichAs part of this weeks patch tuesday, microsoft also re-release MS11-043 to address stability issues.
2011-08-05/a>Johannes UllrichCommon Web Attacks. A quick 404 project update
2011-07-28/a>Johannes UllrichAnnouncing: The "404 Project"
2011-07-02/a>Pedro BuenoBootkits, they are back at full speed...
2011-06-01/a>Johannes UllrichEnabling Privacy Enhanced Addresses for IPv6
2011-04-28/a>Chris MohanGathering and use of location information fears - or is it all a bit too late
2011-04-25/a>Rob VandenBrinkWhat's Your (IP) Address Worth?
2011-04-21/a>Guy BruneauSilverlight Update Available
2011-04-10/a>Raul SilesRecent security enhancements in web browsers (e.g. Google Chrome)
2011-03-23/a>Johannes UllrichFirefox 4 Security Features
2011-02-23/a>Manuel Humberto Santander PelaezBind DOS vulnerability (CVE-2011-0414)
2011-02-01/a>Johannes UllrichThe End Of IP As We Know It
2010-11-16/a>Guy Bruneau OpenSSL TLS Extension Parsing Race Condition
2010-10-28/a>Manuel Humberto Santander PelaezCVE-2010-3654 - New dangerous 0-day authplay library adobe products vulnerability
2010-09-17/a>Robert DanfordCirca 2007 Linux Kernel Vulnerability Resurfaces (Was CVE-2007-4573, Now CVE-2010-3301)
2010-03-24/a>Kyle HaugsnessWax nostalgic - commodore64 updated to present time
2010-02-23/a>Mark HofmanWhat is your firewall telling you and what is TCP249?
2010-02-21/a>Tony CarothersTCP Port 12174 Request For Packets
2010-01-19/a>Jim ClausingThe IE saga continues, out-of-cycle patch coming soon
2010-01-19/a>Jim Clausing49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-15/a>Kevin ListonExploit code available for CVE-2010-0249
2010-01-04/a>Bojan ZdrnjaSophisticated, targeted malicious PDF documents exploiting CVE-2009-4324
2009-12-29/a>Rick WannerWhat's up with port 12174? Possible Symantec server compromise?
2009-11-11/a>Rob VandenBrinkApple Safari 4.0.4 Released
2009-10-30/a>Rob VandenBrinkNew version of NIST 800-41, Firewalls and Firewall Policy Guidelines
2009-10-28/a>Johannes UllrichSniffing SSL: RFC 4366 and TLS Extensions
2009-10-25/a>Lorna HutchesonCyber Security Awareness Month - Day 25 - Port 80 and 443
2009-10-15/a>Deborah HaleCyber Security Awareness Month - Day 15 - Ports 995, 465, and 993 - Secure Email
2009-09-07/a>Jim ClausingRequest for packets
2009-05-27/a>donald smithWebDAV write-up
2009-03-28/a>Rick WannerNew Beta release of Nmap
2009-03-05/a>Mark HofmanWhat's up with port 445?
2008-06-10/a>Swa FrantzenRansomware keybreaking
2006-10-05/a>Swa FrantzenMS06-053 revisited ?
2006-09-15/a>Swa FrantzenMSIE DirectAnimation ActiveX 0-day update
2006-08-31/a>Joel EslerMS06-040 Worm