Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Diaries by Keyword - SANS Internet Storm Center Diaries by Keyword


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title
2019-02-26Russ McReeAd Blocking With Pi Hole
2018-08-19Didier StevensVideo: Peeking into msg files - revisited
2018-08-11Didier StevensPeeking into msg files - revisited
2018-02-19Didier StevensAnalyzing MSI files
2016-06-12Guy BruneauDNS Sinkhole ISO Version 2.0
2016-03-07Xavier MertensAnother Malicious Document, Another Way to Deliver Malicious Code
2015-07-12Didier StevensJump List Files Are OLE Files
2015-07-04Didier StevensA .BUP File Is An OLE File
2015-05-15Didier StevensAnother Maldoc? I'm Afraid So...
2015-05-09Didier StevensMalicious Word Document: This Time The Maldoc Is A MIME File
2015-02-20Tom WebbFast analysis of a Tax Scam
2015-02-19Daniel WesemannMacros? Really?!
2013-11-18Johannes UllrichAm I Sending Traffic to a "Sinkhole"?
2013-05-04Kevin ShorttThe Zero-Day Pendulum Swings
2013-04-30Russ McReeApache binary backdoor adds malicious redirect to Blackhole
2013-04-23Russ McReeMicrosoft's Security Intelligence Report (SIRv14) released
2012-11-16Guy BruneauVMware security updates for vSphere API and ESX Service Console - http://www.vmware.com/security/advisories/VMSA-2012-0016.html
2012-09-01Russ McReeBlackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish
2012-06-26Daniel WesemannRun, Forest! (Update)
2012-04-25Daniel WesemannBlacole's obfuscated JavaScript
2012-04-25Daniel WesemannBlacole's shell code
2012-01-21Guy BruneauDNS Sinkhole Scripts Fixes/Update
2011-12-06Pedro BuenoThe RedRet connection...
2011-11-22Pedro BuenoUpdates on ZeroAccess and BlackHole front...
2011-10-15Guy BruneauDNS Sinkhole Parser Script Update
2011-09-09Guy BruneauIPv6 and DNS Sinkhole
2010-10-28Tony CarothersCyber Security Awareness Month - Day 28 - Role of the employee
2010-06-19Guy BruneauDNS Sinkhole ISO Available for Download
2010-01-10Guy BruneauEasy DNS BIND Sinkhole Setup
2006-12-18Toby KohlenbergORDB Shutting down