Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Diaries by Keyword - SANS Internet Storm Center Diaries by Keyword


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

WORD MACRO

2018-12-18Brad DuncanMalspam links to password-protected Word docs that push IcedID (Bokbot)
2018-11-15Brad DuncanEmotet infection with IcedID banking Trojan

WORD

2019-01-24/a>Brad DuncanMalspam with Word docs uses macro to run Powershell script and steal system data
2018-12-18/a>Brad DuncanMalspam links to password-protected Word docs that push IcedID (Bokbot)
2018-12-17/a>Didier StevensPassword Protected ZIP with Maldoc
2018-11-15/a>Brad DuncanEmotet infection with IcedID banking Trojan
2018-10-26/a>Xavier MertensDissecting Malicious Office Documents with Linux
2018-08-22/a>Deborah HaleEmail/password Frustration
2018-07-12/a>Johannes UllrichNew Extortion Tricks: Now Including Your Password!
2018-06-13/a>Xavier MertensA Bunch of Compromized Wordpress Sites
2018-01-09/a>Jim ClausingAre you watching for brute force attacks on IPv6?
2017-11-28/a>Xavier MertensApple High Sierra Uses a Passwordless Root Account
2017-11-07/a>Xavier MertensInteresting VBA Dropper
2017-08-17/a>Xavier MertensMaldoc with auto-updated link
2017-05-17/a>Richard PorterWait What? We don?t have to change passwords every 90 days?
2017-05-05/a>Xavier MertensHTTP Headers... the Achilles' heel of many applications
2017-04-26/a>Johannes UllrichIf there are some unexploited MSSQL Servers With Weak Passwords Left: They got you now (again)
2017-04-23/a>Didier StevensMalicious Documents: A Bit Of News
2017-04-10/a>Didier StevensPassword History: Insights Shared by a Reader
2017-02-07/a>Johannes UllrichMy Password is [taco] Using Emojis for Stronger Passwords
2017-02-04/a>Xavier MertensDetecting Undisclosed Vulnerabilities with Security Tools & Features
2016-12-07/a>Xavier MertensThe Passwords You Should Never Use
2016-09-15/a>Xavier MertensIn Need of a OTP Manager Soon?
2016-07-21/a>Didier StevensPractice ntds.dit File
2016-06-20/a>Xavier MertensUsing Your Password Manager to Monitor Data Leaks
2015-12-06/a>Mark HofmanMalware SPAM a new run has started.
2015-06-26/a>Daniel WesemannCisco default credentials - again!
2015-05-09/a>Didier StevensMalicious Word Document: This Time The Maldoc Is A MIME File
2015-03-13/a>Guy BruneauBlind SQL Injection against WordPress SEO by Yoast
2015-02-20/a>Tom WebbFast analysis of a Tax Scam
2014-11-20/a>Johannes UllrichCritical WordPress XSS Update
2014-09-19/a>Guy BruneauAdded today in oclhashcat 131 Django [Default Auth] (PBKDF2 SHA256 Rounds Salt) Support - http://hashcat.net/hashcat/
2014-08-22/a>Richard PorterOCLHashCat 1.30 Released
2014-08-06/a>Johannes UllrichAll Passwords have been lost: What's next?
2014-07-22/a>Daniel Wesemann WordPress brute force attack via wp.getUsersBlogs
2014-06-19/a>Tony CarothersWordPress and Security
2014-05-22/a>Rob VandenBrinkAnother Site Breached - Time to Change your Passwords! (If you can that is)
2014-03-14/a>Richard PorterWord Press Shenanigans? Anyone seeing strange activity today?
2014-03-12/a>Johannes UllrichWordpress "Pingback" DDoS Attacks
2013-11-22/a>Rick WannerTales of Password Reuse
2013-07-21/a>Guy BruneauUbuntu Forums Security Breach
2013-06-11/a>Swa FrantzenStore passwords the right way in your application
2013-05-14/a>Jim ClausingSo what passwords are those ssh scanners trying?
2013-03-18/a>Kevin ShorttCisco IOS Type 4 Password Issue: http://tools.cisco.com/security/center/content/CiscoSecurityResponse/cisco-sr-20130318-type4
2013-01-18/a>Russ McReeInteresting reads for Friday 18 JAN 2013
2013-01-04/a>Daniel WesemannBlue for Reset?
2012-11-15/a>Jim ClausingAnother month another password disclosure breach
2012-07-16/a>Jim ClausingAn analysis of the Yahoo! passwords
2012-06-06/a>Jim ClausingPotential leak of 6.5+ million LinkedIn password hashes
2012-05-22/a>Johannes Ullrichnmap 6 released
2012-04-21/a>Guy BruneauWordPress Release Security Update
2012-01-05/a>Russ McReeWordPress 3.3.1 fixes 15 issues with WordPress 3.3 including XSS. Download 3.3.1 or visit Dashboard --> Updates in your site admin panel.
2012-01-03/a>Rick WannerAnalysis of the Stratfor Password List
2011-10-10/a>Tom ListonWhat's In A Name?
2011-08-10/a>Johannes UllrichTheoretical and Practical Password Entropy
2011-06-30/a>Guy BruneauWordPress 3.1.4 Security Update - http://wordpress.org/news/2011/06/wordpress-3-1-4/
2011-06-28/a>Johannes UllrichHashing Passwords
2011-06-22/a>Guy BruneauWordPress Forces Password Reset
2011-05-30/a>Johannes UllrichAllied Telesis Passwords Leaked
2011-04-18/a>John BambenekWordpress.com Security Breach
2011-02-08/a>Mark HofmanWordPress 3.0.5 (and 3.1 RC4) are out
2010-12-30/a>Johannes UllrichCritcal Wordpress Security Update http://wordpress.org/news/2010/12/3-0-4-update/
2010-12-28/a>John BambenekMozilla Notifies of Relatively Minor Security Breach
2010-12-15/a>Manuel Humberto Santander PelaezHP StorageWorks P2000 G3 MSA hardcoded user
2010-12-13/a>Deborah HaleGawker Media Breach of Security
2010-12-02/a>Kevin JohnsonSQL Injection: Wordpress 3.0.2 released
2010-11-26/a>Mark HofmanUsing password cracking as metric/indicator for the organisation's security posture
2010-08-27/a>Mark HofmanFTP Brute Password guessing attacks
2010-05-19/a>Kyle HaugsnessWordpress blog attacks... again
2010-05-10/a>Toby KohlenbergAnother round of WordPress Attacks
2010-03-30/a>Pedro BuenoSharing the Tools
2010-02-25/a>Chris CarboniPass The Hash
2010-02-05/a>Jim ClausingWordPress iframe injection?
2010-02-02/a>Johannes UllrichTwitter Mass Password Reset due to Phishing
2009-12-04/a>Daniel WesemannThe economics of security advice (MSFT research paper)
2009-11-30/a>Bojan ZdrnjaDistributed Wordpress admin account cracking
2009-11-02/a>Daniel WesemannPassword rules: Change them every 25 years
2009-10-23/a>Johannes UllrichLittle new tool: reversing md5/sha1 hashes http://isc.sans.org/tools/reversehash.html
2009-10-21/a>Pedro BuenoWordPress Hardening
2009-08-11/a>Swa FrantzenWordpress unauthenticated administrator password reset
2008-11-11/a>Swa FrantzenPhishing for Google adwords
2008-09-22/a>Jim ClausingLessons learned from the Palin (and other) account hijacks
2008-09-09/a>Swa Frantzenwordpress upgrade
2008-07-17/a>Mari NicholsAdobe Reader 9 Released
2008-07-09/a>Johannes UllrichUnpatched Word Vulnerability
2008-04-23/a>Mari NicholsWhat's New, Old and Morphing?

MACRO

2019-03-17/a>Didier StevensVideo: Maldoc Analysis: Excel 4.0 Macro
2019-03-16/a>Didier StevensMaldoc: Excel 4.0 Macros
2019-03-13/a>Brad DuncanMalspam pushes Emotet with Qakbot as the follow-up malware
2019-01-24/a>Brad DuncanMalspam with Word docs uses macro to run Powershell script and steal system data
2018-12-18/a>Brad DuncanMalspam links to password-protected Word docs that push IcedID (Bokbot)
2018-11-15/a>Brad DuncanEmotet infection with IcedID banking Trojan
2018-08-24/a>Xavier MertensMicrosoft Publisher Files Delivering Malware
2018-05-25/a>Xavier MertensAntivirus Evasion? Easy as 1,2,3
2018-05-01/a>Xavier MertensDiving into a Simple Maldoc Generator
2017-12-19/a>Xavier MertensExample of 'MouseOver' Link in a Powerpoint File
2017-12-16/a>Xavier MertensMicrosoft Office VBA Macro Obfuscation via Metadata
2017-11-15/a>Xavier MertensIf you want something done right, do it yourself!
2017-02-26/a>Guy BruneauIt is Tax Season - Watch out for Suspicious Attachment
2016-09-30/a>Xavier MertensAnother Day, Another Malicious Behaviour
2015-02-19/a>Daniel WesemannMacros? Really?!