Internet Storm Center
Sign In
Sign Up
Participate: Learn more about our honeypot network
https://isc.sans.edu/tools/honeypot/
Handler on Duty:
Didier Stevens
Threat Level:
green
Date
Author
Title
DDOS EXTORTION FAKE
2017-07-07
Renato Marinho
DDoS Extortion E-mail: Yet Another Bluff?
DDOS
2022-08-10/a>
Johannes Ullrich
And Here They Come Again: DNS Reflection Attacks
2022-08-02/a>
Johannes Ullrich
A Little DDoS in the Morning - Followup
2022-08-01/a>
Johannes Ullrich
A Little DDoS In the Morning
2022-04-13/a>
Jan Kopriva
How is Ukrainian internet holding up during the Russian invasion?
2021-07-31/a>
Guy Bruneau
Unsolicited DNS Queries
2020-09-01/a>
Johannes Ullrich
Exposed Windows Domain Controllers Used in CLDAP DDoS Attacks
2019-08-14/a>
Brad Duncan
Recent example of MedusaHTTP malware
2017-10-20/a>
Rick Wanner
One year Anniversary of Dyn DDOS
2017-07-07/a>
Renato Marinho
DDoS Extortion E-mail: Yet Another Bluff?
2016-12-29/a>
Rick Wanner
More on Protocol 47 denys
2016-12-19/a>
John Bambenek
UPDATED x1: Mirai Scanning for Port 6789 Looking for New Victims / Now hitting tcp/23231
2016-12-09/a>
Rick Wanner
Mirai - now with DGA
2016-05-29/a>
Guy Bruneau
Analysis of a Distributed Denial of Service (DDoS)
2016-02-07/a>
Rick Wanner
DDOS is down, but still a concern for ISPs
2015-06-23/a>
Kevin Shortt
XOR DDOS Mitigation and Analysis
2015-02-27/a>
Rick Wanner
DDOS are way down? Why?
2015-02-19/a>
Daniel Wesemann
DNS-based DDoS
2014-08-31/a>
Rick Wanner
1900/UDP (SSDP) Scanning and DDOS
2014-08-17/a>
Rick Wanner
Part 1: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-08-17/a>
Rick Wanner
Part 2: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-06-24/a>
Kevin Shortt
NTP DDoS Counts Have Dropped
2014-06-02/a>
Rick Wanner
Using nmap to scan for DDOS reflectors
2014-04-30/a>
Russ McRee
UltraDNS DDOS
2014-03-12/a>
Johannes Ullrich
Wordpress "Pingback" DDoS Attacks
2014-02-17/a>
Chris Mohan
NTP reflection attacks continue
2013-11-22/a>
Rick Wanner
Port 0 DDOS
2013-06-05/a>
Richard Porter
BIND 9 Update fixing CVE-2013-3919
2013-04-21/a>
John Bambenek
A Chargen-based DDoS? Chargen is still a thing?
2013-03-28/a>
John Bambenek
Where Were You During the Great DDoS Cybergeddon of 2013?
2013-03-18/a>
Kevin Shortt
Spamhaus DDOS
2012-09-20/a>
Russ McRee
Financial sector advisory: attacks and threats against financial institutions
2012-03-30/a>
Daniel Wesemann
Tomorrow, the world will end
2012-01-22/a>
Johannes Ullrich
Javascript DDoS Tool Analysis
2011-05-20/a>
Guy Bruneau
Distributed Denial of Service Cheat Sheet
2011-04-05/a>
Mark Hofman
Sony DDOS
2011-04-05/a>
Mark Hofman
DNS.be DDOS
2011-03-04/a>
Mark Hofman
DDOS, the new black?
2011-02-12/a>
Kevin Liston
DDoS Analysis Process
2011-01-29/a>
Mark Hofman
Sourceforge attack
2010-12-09/a>
Mark Hofman
Having a look at the DDOS tool used in the attacks today
2010-12-08/a>
Rob VandenBrink
Interesting DDOS activity around Wikileaks
2010-09-14/a>
Adrien de Beaupre
BlackEnergy DDoS
2010-08-16/a>
Raul Siles
DDOS: State of the Art
2010-08-07/a>
Stephen Hall
DnsMadeEasy under a "quite large and unique" ddos.
2010-02-02/a>
Johannes Ullrich
Pushdo Update
2010-01-19/a>
Jim Clausing
49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-06/a>
Johannes Ullrich
Denial of Service Attack Aftermath (and what did Iran have to do with it?)
2009-09-09/a>
Mark Hofman
Possible DDOS on gov.au sites starting tonight?
2009-07-09/a>
John Bambenek
Latest Updates on Ongoing DDoS on Governmental/Commercial Websites in USA and S. Korea
2009-07-08/a>
Marcus Sachs
RFI: DDoS Against Government and Civilian Web Sites
2009-06-23/a>
Bojan Zdrnja
Slowloris and Iranian DDoS attacks
2009-03-08/a>
Marcus Sachs
Behind the Estonia Cyber Attacks
2009-01-31/a>
Swa Frantzen
DNS DDoS - let's use a long term solution
2008-12-03/a>
Andre Ludwig
New ISC Poll! Has your organization suffered a DDoS (Distributed Denial of Service) attack in the last year?
2008-07-20/a>
Kevin Liston
Denial of Service Attack Against Georgia-- Are You Participating?
2008-04-10/a>
Deborah Hale
DSLReports Being Attacked Again
EXTORTION
2021-07-28/a>
Jan Kopriva
A sextortion e-mail from...IT support?!
2020-07-20/a>
Rick Wanner
Sextortion Update: The Final Final Chapter
2020-06-16/a>
Xavier Mertens
Sextortion to The Next Level
2019-09-22/a>
Didier Stevens
Video: Encrypted Sextortion PDFs
2019-09-16/a>
Didier Stevens
Encrypted Sextortion PDFs
2019-08-05/a>
Rick Wanner
Sextortion: Follow the Money - The Final Chapter
2019-03-24/a>
Didier Stevens
Decoding QR Codes with Python
2019-03-21/a>
Xavier Mertens
New Wave of Extortion Emails: Central Intelligence Agency Case
2019-02-25/a>
Didier Stevens
Sextortion Email Variant: With QR Code
2019-02-01/a>
Rick Wanner
Sextortion: Follow the Money Part 3 - The cashout begins!
2019-01-18/a>
John Bambenek
Sextortion Bitcoin on the Move
2018-12-14/a>
Rick Wanner
Bombstortion?? Boomstortion??
2018-08-13/a>
Didier Stevens
New Extortion Tricks: Now Including Your (Partial) Phone Number!
2018-07-12/a>
Johannes Ullrich
New Extortion Tricks: Now Including Your Password!
2017-07-07/a>
Renato Marinho
DDoS Extortion E-mail: Yet Another Bluff?
2016-03-13/a>
Guy Bruneau
A Look at the Mandiant M-Trends 2016 Report
2014-07-02/a>
Johannes Ullrich
Simple Javascript Extortion Scheme Advertised via Bing
2014-04-21/a>
Daniel Wesemann
Allow us to leave!
2011-09-05/a>
Bojan Zdrnja
Bitcoin – crypto currency of future or heaven for criminals?
FAKE
2022-03-02/a>
Johannes Ullrich
The More Often Something is Repeated, the More True It Becomes: Dealing with Social Media
2022-01-03/a>
Xavier Mertens
McAfee Phishing Campaign with a Nice Fake Scan
2021-08-04/a>
Yee Ching Tok
Pivoting and Hunting for Shenanigans from a Reported Phishing Domain
2020-04-18/a>
Guy Bruneau
Maldoc Falsely Represented as DOCX Invoice Redirecting to Fake Apple Store
2020-02-05/a>
Brad Duncan
Fake browser update pages are "still a thing"
2019-04-07/a>
Guy Bruneau
Fake Office 365 Payment Information Update
2019-04-02/a>
Johannes Ullrich
Fake AV is Back: LaCie Network Drives Used to Spread Malware
2019-03-21/a>
Xavier Mertens
New Wave of Extortion Emails: Central Intelligence Agency Case
2017-07-07/a>
Renato Marinho
DDoS Extortion E-mail: Yet Another Bluff?
2016-05-12/a>
Xavier Mertens
Another Day, Another Wave of Phishing Emails
2015-09-28/a>
Johannes Ullrich
"Transport of London" Malicious E-Mail
2014-02-21/a>
Johannes Ullrich
UPS Malware Spam Using Fake SPF Headers
2013-04-29/a>
Adam Swanger
Report Fake Tech Support Calls submission form reminder
2013-04-16/a>
John Bambenek
Fake Boston Marathon Scams Update
2013-01-03/a>
Manuel Humberto Santander Pelaez
New year and new CA compromised
2012-12-06/a>
Daniel Wesemann
Fake tech support calls - revisited
2012-10-03/a>
Kevin Shortt
Fake Support Calls Reported
2012-06-19/a>
Daniel Wesemann
Vulnerabilityqueerprocessbrittleness
2011-07-25/a>
Bojan Zdrnja
When the FakeAV coder(s) fail
2011-07-21/a>
Daniel Wesemann
Down the FakeAV rabbit hole
2011-05-19/a>
Daniel Wesemann
Fake AV Bingo
2011-05-04/a>
Bojan Zdrnja
More on Google image poisoning
2011-01-18/a>
Daniel Wesemann
Yet another rogue anti-virus
2010-11-11/a>
Daniel Wesemann
Fake AV scams via Skype Chat
2010-02-27/a>
Johannes Ullrich
Search Engine Poisoning: Chile Earthquake
2010-02-15/a>
Johannes Ullrich
Various Olympics Related Dangerous Google Searches
2010-02-08/a>
Adrien de Beaupre
When is a 0day not a 0day? Fake OpenSSh exploit, again.
2010-01-08/a>
Rob VandenBrink
Microsoft OfficeOnline, Searching for Trust and Malware
2009-09-17/a>
Bojan Zdrnja
Why is Rogue/Fake AV so successful?
2009-09-04/a>
Adrien de Beaupre
Fake anti-virus
2009-02-06/a>
Adrien de Beaupre
Fake stimulus payments
2008-09-15/a>
donald smith
Fake antivirus 2009 and search engine results
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Forums
Auditing
Diary Discussions
Forensics
General Discussions
Industry News
Network Security
Penetration Testing
Software Security
Contact Us
Contact Us
About Us
Handlers
Slack Channel
Mastodon
Twitter
Make the web a better place by
sharing the SANS Internet Storm Center
with others