Date Author Title

NETSUPPORT RAT

2020-02-05Brad DuncanFake browser update pages are "still a thing"

NETSUPPORT

2024-06-17/a>Xavier MertensNew NetSupport Campaign Delivered Through MSIX Packages
2023-08-18/a>Xavier MertensFrom a Zalando Phishing to a RAT
2022-10-21/a>Brad Duncansczriptzzbn inject pushes malware for NetSupport RAT
2020-02-05/a>Brad DuncanFake browser update pages are "still a thing"

RAT

2024-11-05/a>Xavier MertensPython RAT with a Nice Screensharing Feature
2024-08-14/a>Xavier MertensMultiple Malware Dropped Through MSI Package
2024-06-17/a>Xavier MertensNew NetSupport Campaign Delivered Through MSIX Packages
2024-05-31/a>Xavier Mertens"K1w1" InfoStealer Uses gofile.io for Exfiltration
2024-03-28/a>Xavier MertensFrom JavaScript to AsyncRAT
2023-12-23/a>Xavier MertensPython Keylogger Using Mailtrap.io
2023-12-20/a>Guy BruneauHow to Protect your Webserver from Directory Enumeration Attack ? Apache2 [Guest Diary]
2023-11-18/a>Xavier MertensQuasar RAT Delivered Through Updated SharpLoader
2023-08-20/a>Guy BruneauSystemBC Malware Activity
2023-08-18/a>Xavier MertensFrom a Zalando Phishing to a RAT
2023-08-11/a>Xavier MertensShow me All Your Windows!
2023-06-29/a>Brad DuncanGuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT
2023-06-16/a>Xavier MertensAnother RAT Delivered Through VBS
2023-05-30/a>Brad DuncanMalspam pushes ModiLoader (DBatLoader) infection for Remcos RAT
2023-05-20/a>Xavier MertensPhishing Kit Collecting Victim's IP Address
2023-05-19/a>Xavier MertensWhen the Phisher Messes Up With Encoding
2023-05-14/a>Guy BruneauVMware Aria Operations addresses multiple Local Privilege Escalations and a Deserialization issue
2023-05-07/a>Didier StevensQuickly Finding Encoded Payloads in Office Documents
2023-05-03/a>Xavier MertensIncreased Number of Configuration File Scans
2023-03-12/a>Guy BruneauAsynRAT Trojan - Bill Payment (Pago de la factura)
2023-03-11/a>Xavier MertensOverview of a Mirai Payload Generator
2022-10-21/a>Brad Duncansczriptzzbn inject pushes malware for NetSupport RAT
2022-09-22/a>Xavier MertensRAT Delivered Through FODHelper
2022-07-28/a>Johannes UllrichExfiltrating Data With Bookmarks
2022-06-16/a>Xavier MertensHoudini is Back Delivered Through a JavaScript Dropper
2022-06-04/a>Guy BruneauSpam Email Contains a Very Large ISO file
2022-05-20/a>Xavier MertensA 'Zip Bomb' to Bypass Security Controls & Sandboxes
2022-05-05/a>Brad DuncanPassword-protected Excel spreadsheet pushes Remcos RAT
2022-05-03/a>Rob VandenBrinkFinding the Real "Last Patched" Day (Interim Version)
2022-03-11/a>Xavier MertensKeep an Eye on WebSockets
2022-03-09/a>Xavier MertensInfostealer in a Batch File
2022-02-18/a>Xavier MertensRemcos RAT Delivered Through Double Compressed Archive
2022-02-11/a>Xavier MertensCinaRAT Delivered Through HTML ID Attributes
2022-01-07/a>Xavier MertensCustom Python RAT Builder
2021-12-01/a>Xavier MertensInfo-Stealer Using webhook.site to Exfiltrate Data
2021-11-04/a>Brad DuncanOctober 2021 Forensic Contest: Answers and Analysis
2021-09-01/a>Brad DuncanSTRRAT: a Java-based RAT that doesn't care if you have Java
2021-06-21/a>Rick WannerMitre CWE - Common Weakness Enumeration
2021-04-09/a>Xavier MertensNo Python Interpreter? This Simple RAT Installs Its Own Copy
2021-03-31/a>Xavier MertensQuick Analysis of a Modular InfoStealer
2021-03-04/a>Xavier MertensFrom VBS, PowerShell, C Sharp, Process Hollowing to RAT
2021-02-24/a>Brad DuncanMalspam pushes GuLoader for Remcos RAT
2021-02-04/a>Bojan ZdrnjaAbusing Google Chrome extension syncing for data exfiltration and C&C
2020-10-14/a>Xavier MertensNicely Obfuscated Python RAT
2020-09-30/a>Johannes UllrichScans for FPURL.xml: Reconnaissance or Not?
2020-09-28/a>Xavier MertensSome Tyler Technologies Customers Targeted with The Installation of a Bomgar Client
2020-08-25/a>Xavier MertensKeep An Eye on LOLBins
2020-08-18/a>Xavier MertensUsing API's to Track Attackers
2020-08-10/a>Bojan ZdrnjaScoping web application and web service penetration tests
2020-08-04/a>Johannes UllrichInternet Choke Points: Concentration of Authoritative Name Servers
2020-05-14/a>Rob VandenBrinkPatch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe
2020-04-17/a>Xavier MertensWeaponized RTF Document Generator & Mailer in PowerShell
2020-02-05/a>Brad DuncanFake browser update pages are "still a thing"
2020-01-10/a>Xavier MertensMore Data Exfiltration
2019-10-29/a>Xavier MertensGenerating PCAP Files from YAML
2019-09-27/a>Xavier MertensNew Scans for Polycom Autoconfiguration Files
2019-09-25/a>Brad DuncanMalspam pushing Quasar RAT
2019-09-19/a>Xavier MertensBlocklisting or Whitelisting in the Right Way
2019-09-19/a>Xavier MertensAgent Tesla Trojan Abusing Corporate Email Accounts
2019-04-26/a>Rob VandenBrinkPillaging Passwords from Service Accounts
2019-04-24/a>Rob VandenBrinkWhere have all the Domain Admins gone? Rooting out Unwanted Domain Administrators
2019-03-06/a>Xavier MertensKeep an Eye on Disposable Email Addresses
2018-11-27/a>Rob VandenBrinkData Exfiltration in Penetration Tests
2018-09-19/a>Rob VandenBrinkCertificates Revisited - SSL VPN Certificates 2 Ways
2018-09-05/a>Rob VandenBrinkWhere have all my Certificates gone? (And when do they expire?)
2018-08-24/a>Xavier MertensMicrosoft Publisher Files Delivering Malware
2018-06-15/a>Lorna HutchesonSMTP Strangeness - Possible C2
2018-05-19/a>Xavier MertensMalicious Powershell Targeting UK Bank Customers
2018-05-10/a>Bojan ZdrnjaExfiltrating data from (very) isolated environments
2017-12-13/a>Xavier MertensTracking Newly Registered Domains
2017-11-03/a>Xavier MertensSimple Analysis of an Obfuscated JAR File
2017-08-17/a>Xavier MertensMaldoc with auto-updated link
2017-06-08/a>Tom WebbSummer STEM for Kids
2017-05-10/a>Johannes UllrichRead This If You Are Using a Script to Pull Data From This Site
2017-04-20/a>Xavier MertensDNS Query Length... Because Size Does Matter
2016-09-04/a>Russ McReeKali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/
2016-07-26/a>Johannes UllrichCommand and Control Channels Using "AAAA" DNS Records
2016-06-15/a>Richard PorterWarp Speed Ahead, L7 Open Source Packet Generator: Warp17
2016-04-02/a>Russell EubanksWhy Can't We Be Friends?
2015-12-24/a>Xavier MertensUnity Makes Strength
2015-11-09/a>John BambenekProtecting Users and Enterprises from the Mobile Malware Threat
2015-09-03/a>Xavier MertensQuerying the DShield API from RTIR
2014-08-22/a>Richard PorterOCLHashCat 1.30 Released
2014-08-09/a>Adrien de BeaupreComplete application ownage via Multi-POST XSRF
2014-07-19/a>Russ McReeKeeping the RATs out: the trap is sprung - Part 3
2014-07-18/a>Russ McReeKeeping the RATs out: **it happens - Part 2
2014-07-16/a>Russ McReeKeeping the RATs out: an exercise in building IOCs - Part 1
2014-03-13/a>Daniel WesemannIdentification and authentication are hard ... finding out intention is even harder
2013-06-18/a>Russ McReeVolatility rules...any questions?
2013-04-25/a>Adam SwangerGuest Diary: Dylan Johnson - A week in the life of some Perimeter Firewalls
2013-04-17/a>John BambenekUPDATEDx1: Boston-Related Malware Campaigns Have Begun - Now with Waco Plant Explosion Fun
2013-04-16/a>John BambenekFake Boston Marathon Scams Update
2013-04-15/a>John BambenekPlease send any spam (full headers), URLs or other suspicious content scamming off Boston Marathon explosions to handlers@sans.org
2013-03-03/a>Richard PorterUptick in MSSQL Activity
2013-02-06/a>Johannes UllrichAre you losing system logging information (and don't know it)?
2012-10-30/a>Mark HofmanCyber Security Awareness Month - Day 30 - DSD 35 mitigating controls
2012-05-22/a>Johannes Ullrichnmap 6 released
2012-01-03/a>Rick WannerAnalysis of the Stratfor Password List
2011-12-25/a>Deborah HaleAnother Company Falls Victim
2011-10-26/a>Rick WannerCritical Control 17:Penetration Tests and Red Team Exercises
2010-10-03/a>Adrien de BeaupreCanada's Cyber Security Strategy released today
2010-08-23/a>Manuel Humberto Santander PelaezFirefox plugins to perform penetration testing activities
2010-08-16/a>Raul SilesBlind Elephant: A New Web Application Fingerprinting Tool
2010-07-08/a>Kyle HaugsnessPirate Bay account database compromised
2010-06-06/a>Manuel Humberto Santander PelaezNice OS X exploit tutorial
2010-04-13/a>Adrien de BeaupreWeb App Testing Tools
2010-03-06/a>Tony CarothersIntegration and the Security of New Technologies
2010-02-22/a>Rob VandenBrinkNew Risks in Penetration Testing
2009-07-27/a>Raul SilesNew Hacker Challenge: Prison Break - Breaking, Entering & Decoding
2009-04-21/a>Bojan ZdrnjaWeb application vulnerabilities
2009-01-20/a>Adrien de BeaupreObamamania
2008-11-25/a>Andre LudwigThe beginnings of a collaborative approach to IDS
2008-09-20/a>Rick WannerNew (to me) nmap Features
2008-07-18/a>Adrien de BeaupreExit process?
2008-03-30/a>Mark HofmanMail Anyone?