SANS Site Network
Current Site
Internet Storm Center
Choose a different site
Help
Training
Certification
Cyber Security Graduate School
Security Awareness Training
Computer Forensics
Penetration Testing
IT Audit
Software Security
Threat Level:
DSHIELD
Diary Page
Diary Archive
ISC Podcasts
Daily Stormcast!
Security News
ISC Handlers
ISC Events
ISC on Twitter
ISC Poll
ISC Search
Tools
Tools List
Feeds (XML/RSS)
Infocon Status
Link to ISC
Video/Audio
Presentations/Papers
Links
Glossary
Download Our Sensor!
Data/Reports
Summary Page
ISC/DShield API
HTTP Headers
404Project
Suspicious Domains
Report Fake Calls
Submit Logs
Using DShield Data
Webhoneypot
My DSHIELD
ISC Login
SANS Portal »
Contact
About ISC
Contact Form
Security Contact
Submit Site Bug
Submit Logs
Privacy Policy
Diaries by Keyword: Antivirus Malware protection
Handler on Duty:
Adrien de Beaupre
Contact Us
Date
Author
Title
ANTIVIRUS MALWARE PROTECTION
2012-04-26
Richard Porter
Define Irony: A medical device with a Virus?
2009-08-29
Guy Bruneau
Immunet Protect - Cloud and Community Malware Protection
ANTIVIRUS
2012-11-02
Daniel Wesemann
The shortcomings of anti-virus software
2012-04-26
Richard Porter
Define Irony: A medical device with a Virus?
2011-06-02
Johannes Ullrich
Some Insight into Apple's Anti-Virus Signatures
2011-03-17
Kevin Liston
So You Got an AV Alert. Now What?
2011-03-09
Kevin Shortt
AVG Anti-Virus 2011 False Positives - Luhe.Exploit.PDF.B
2011-03-01
Daniel Wesemann
AV software and "sharing samples"
2010-05-26
Bojan Zdrnja
Malware modularization and AV detection evasion
2009-09-25
Lenny Zeltser
Categories of Common Malware Traits
2009-09-17
Bojan Zdrnja
Why is Rogue/Fake AV so successful?
2009-08-29
Guy Bruneau
Immunet Protect - Cloud and Community Malware Protection
2009-08-19
Daniel Wesemann
Checking your protection
2009-08-13
Johannes Ullrich
CA eTrust update crashes systems
2008-09-15
donald smith
Fake antivirus 2009 and search engine results
2006-10-30
William Salusky
ToD - Configuration Management - maintaining security awareness
MALWARE
2013-05-21
Adrien de Beaupre
Moore, Oklahoma tornado charitable organization scams, malware, and phishing
2013-05-17
Daniel Wesemann
e-netprotections.su ?
2013-05-16
Daniel Wesemann
Extracting signatures from Apple .apps
2013-05-11
Lenny Zeltser
Extracting Digital Signatures from Signed Malware
2013-05-01
Daniel Wesemann
The cost of cleaning up
2013-04-10
Manuel Humberto Santander Pelaez
Massive Google scam sent by email to Colombian domains
2013-03-22
Mark Baggett
Wipe the drive! Stealthy Malware Persistence - Part 4
2013-03-20
Mark Baggett
Wipe the drive! Stealthy Malware Persistence - Part 3
2013-03-19
Johannes Ullrich
Scam of the day: More fake CNN e-mails
2013-03-15
Mark Baggett
AVG detect legit file as virus
2013-03-14
Mark Baggett
Wipe the drive! Stealthy Malware Persistence - Part 2
2013-03-13
Mark Baggett
Wipe the drive! Stealthy Malware Persistence Mechanism - Part 1
2013-02-25
Johannes Ullrich
Mass-Customized Malware Lures: Don't trust your cat!
2013-01-08
Jim Clausing
Cuckoo 0.5 is out and the world didn't end
2012-12-18
Rob VandenBrink
All I Want for Christmas is to Not Get Hacked !
2012-12-03
Kevin Liston
Mobile Malware: Request for Field Reports
2012-11-02
Daniel Wesemann
Lamiabiocasa
2012-11-01
Daniel Wesemann
Patched your Java yet?
2012-10-14
Pedro Bueno
Cyber Security Awareness Month - Day 14 - Poor Man's File Analysis System - Part 1
2012-09-21
Guy Bruneau
Storing your Collection of Malware Samples with Malwarehouse
2012-09-14
Lenny Zeltser
Analyzing Malicious RTF Files Using OfficeMalScanner's RTFScan
2012-07-21
Rick Wanner
OpenDNS is looking for a few good malware people!
2012-07-05
Adrien de Beaupre
New OS X trojan backdoor MaControl variant reported
2012-06-27
Swa Frantzen
Online Banking Heists
2012-06-26
Daniel Wesemann
Run, Forest! (Update)
2012-06-25
Rick Wanner
Targeted Malware for Industrial Espionage?
2012-06-25
Swa Frantzen
Belgian online banking customers hacked.
2012-06-22
Daniel Wesemann
Run, Forest!
2012-06-21
Raul Siles
Print Bomb? (Take 2)
2012-06-21
Russ McRee
Analysis of drive-by attack sample set
2012-06-19
Daniel Wesemann
Vulnerabilityqueerprocessbrittleness
2012-06-04
Lenny Zeltser
Decoding Common XOR Obfuscation in Malicious Code
2012-04-26
Richard Porter
Define Irony: A medical device with a Virus?
2012-04-25
Daniel Wesemann
Blacole's obfuscated JavaScript
2012-04-25
Daniel Wesemann
Blacole's shell code
2012-04-12
Guy Bruneau
HP ProCurve 5400 zl Switch, Flash Cards Infected with Malware
2012-04-12
Guy Bruneau
Apple Java Updates for Mac OS X
2012-03-25
Daniel Wesemann
evilcode.class
2012-03-03
Jim Clausing
New automated sandbox for Android malware
2012-02-24
Guy Bruneau
Flashback Trojan in the Wild
2012-02-20
Pedro Bueno
Simple Malware Research Tools
2012-02-20
Rick Wanner
DNSChanger resolver shutdown deadline is March 8th
2012-01-14
Daniel Wesemann
Hello, Antony!
2011-12-28
Daniel Wesemann
.nl.ai ?
2011-12-10
Daniel Wesemann
Unwanted Presents
2011-12-07
Lenny Zeltser
V8 as an Alternative to SpiderMonkey for JavaScript Deobfuscation
2011-11-04
Guy Bruneau
Duqu Mitigation
2011-10-20
Johannes Ullrich
Evil Printers Sending Mail
2011-09-07
Lenny Zeltser
Analyzing Mobile Device Malware - Honeynet Forensic Challenge 9 and Some Tools
2011-08-29
Kevin Shortt
Internet Worm in the Wild
2011-06-15
Pedro Bueno
Hit by MacDefender, Apple Web Security (name your Mac FakeAV here)...
2011-05-25
Daniel Wesemann
Apple advisory on "MacDefender" malware
2011-05-19
Daniel Wesemann
Fake AV Bingo
2011-05-14
Guy Bruneau
Websense Study Claims Canada Next Hotbed for Cybercrime Web Hosting Activity
2011-05-03
Johannes Ullrich
Update on Osama Bin Laden themed Malware
2011-05-02
Johannes Ullrich
Bin Laden Death Related Malware
2011-04-23
Manuel Humberto Santander Pelaez
Image search can lead to malware download
2011-03-01
Daniel Wesemann
AV software and "sharing samples"
2011-02-07
Pedro Bueno
The Good , the Bad and the Unknown Online Scanners
2011-02-01
Lenny Zeltser
The Importance of HTTP Headers When Investigating Malicious Sites
2010-12-29
Daniel Wesemann
Malware Domains 2234.in, 0000002.in & co
2010-12-29
Daniel Wesemann
Beware of strange web sites bearing gifts ...
2010-10-26
Pedro Bueno
Cyber Security Awareness Month - Day 26 - Sharing Office Files
2010-09-09
Marcus Sachs
'Here You Have' Email
2010-07-21
Adrien de Beaupre
Dell PowerEdge R410 replacement motherboard firmware contains malware
2010-07-21
Adrien de Beaupre
autorun.inf and .lnk Malware (NOT 'Vulnerability in Windows Shell Could Allow Remote Code Execution' 2286198)
2010-07-06
Rob VandenBrink
Bogus Support Organizations use Live Operators to Install Malware
2010-07-04
Manuel Humberto Santander Pelaez
Malware inside PDF Files
2010-06-17
Deborah Hale
FYI - Another bogus site
2010-06-14
Manuel Humberto Santander Pelaez
Rogue facebook application acting like a worm
2010-06-07
Manuel Humberto Santander Pelaez
Software Restriction Policy to keep malware away
2010-06-02
Rob VandenBrink
New Mac malware - OSX/Onionspy
2010-05-26
Bojan Zdrnja
Malware modularization and AV detection evasion
2010-05-23
Manuel Humberto Santander Pelaez
e-mail scam announcing Fidel Castro's funeral ... and nasty malware to your computer.
2010-05-21
Rick Wanner
IBM distributes malware at AusCERT!
2010-04-30
Kevin Liston
The Importance of Small Files
2010-04-19
Daniel Wesemann
Linked into scams?
2010-04-18
Guy Bruneau
Some NetSol hosted sites breached
2010-04-13
Johannes Ullrich
More Legal Threat Malware E-Mail
2010-03-30
Pedro Bueno
Sharing the Tools
2010-03-26
Daniel Wesemann
Getting the EXE out of the RTF again
2010-03-09
Marcus Sachs
Energizer Malware
2010-03-04
Daniel Wesemann
salefale-dot-com is bad
2010-03-03
Johannes Ullrich
Reports about large number of fake Amazon order confirmations
2010-02-21
Patrick Nolan
Looking for "more useful" malware information? Help develop the format.
2010-01-14
Bojan Zdrnja
PDF Babushka
2010-01-07
Daniel Wesemann
Static analysis of malicious PDFs
2010-01-07
Daniel Wesemann
Static analysis of malicous PDFs (Part #2)
2009-12-17
Daniel Wesemann
overlay.xul is back
2009-12-17
Daniel Wesemann
In caches, danger lurks
2009-12-16
Rob VandenBrink
Beware the Attack of the Christmas Greeting Cards !
2009-12-07
Rick Wanner
Cheat Sheet: Analyzing Malicious Documents
2009-12-04
Daniel Wesemann
Max Power's Malware Paradise
2009-12-02
Rob VandenBrink
SPAM and Malware taking advantage of H1N1 concerns
2009-11-25
Jim Clausing
Updates to my GREM Gold scripts and a new script
2009-09-25
Lenny Zeltser
Categories of Common Malware Traits
2009-09-25
Deborah Hale
Conficker Continues to Impact Networks
2009-09-25
Deborah Hale
Malware delivered over Google and Yahoo Ad's?
2009-09-04
Adrien de Beaupre
Fake anti-virus
2009-08-29
Guy Bruneau
Immunet Protect - Cloud and Community Malware Protection
2009-08-26
Johannes Ullrich
Malicious CD ROMs mailed to banks
2009-07-26
Jim Clausing
New Volatility plugins
2009-07-03
Adrien de Beaupre
Happy 4th of July!
2009-07-02
Daniel Wesemann
Getting the EXE out of the RTF
2009-07-02
Bojan Zdrnja
Cold Fusion web sites getting compromised
2009-06-16
John Bambenek
Iran Internet Blackout: Using Twitter for Operational Intelligence
2009-06-16
John Bambenek
URL Shortening Service Cligs Hacked
2009-06-04
Raul Siles
Malware targetting banks ATM's
2009-06-04
Raul Siles
Targeted e-mail attacks asking to verify wire transfer details
2009-06-01
G. N. White
Yet another "Digital Certificate" malware campaign
2009-05-20
Pedro Bueno
Cyber Warfare and Kylin thoughts
2009-05-07
Deborah Hale
Malicious Content on the Web
2009-05-04
Tom Liston
Facebook phishing malware
2009-04-24
Pedro Bueno
Did you check your conference goodies?
2009-03-13
Bojan Zdrnja
When web application security, Microsoft and the AV vendors all fail
2009-02-23
Daniel Wesemann
Turf War
2009-02-23
Daniel Wesemann
And the Oscar goes to...
2009-02-10
Bojan Zdrnja
More tricks from Conficker and VM detection
2009-02-09
Bojan Zdrnja
Some tricks from Conficker's bag
2009-02-04
Daniel Wesemann
Titan Shields up!
2009-01-31
John Bambenek
Google Search Engine's Malware Detection Broken
2009-01-24
Pedro Bueno
Identifying and Removing the iWork09 Trojan
2009-01-18
Daniel Wesemann
3322. org
2009-01-15
Bojan Zdrnja
Conficker's autorun and social engineering
2009-01-12
William Salusky
Downadup / Conficker - MS08-067 exploit and Windows domain account lockout
2009-01-07
Bojan Zdrnja
An Israeli patriot program or a trojan
2009-01-02
Rick Wanner
Tools on my Christmas list.
2008-12-25
Maarten Van Horenbeeck
Merry Christmas, and beware of digital hitchhikers!
2008-12-25
Maarten Van Horenbeeck
Christmas Ecard Malware
2008-12-17
donald smith
Team CYMRU's Malware Hash Registry
2008-12-05
Daniel Wesemann
Been updatin' your Flash player lately?
2008-12-05
Daniel Wesemann
Baby, baby!
2008-12-04
Bojan Zdrnja
Rogue DHCP servers
2008-11-17
Jim Clausing
Finding stealth injected DLLs
2008-11-16
Maarten Van Horenbeeck
Detection of Trojan control channels
2008-11-12
John Bambenek
Thoughts on Security Intelligence (McColo Corp alleged spam/malware host knocked offline)
2008-11-11
Swa Frantzen
Acrobat continued activity in the wild
2008-11-10
Stephen Hall
Adobe Reader Vulnerability - part 2
2008-10-07
Kyle Haugsness
Good reading and a malware challenge
2008-09-29
Daniel Wesemann
ASPROX mutant
2008-09-22
Maarten Van Horenbeeck
Data exfiltration and the use of anonymity providers
2008-09-18
Bojan Zdrnja
Monitoring HTTP User-Agent fields
2008-09-07
Lorna Hutcheson
Malware Analysis: Tools are only so good
2008-09-03
Daniel Wesemann
Static analysis of Shellcode
2008-09-03
Daniel Wesemann
Static analysis of Shellcode - Part 2
2008-09-01
John Bambenek
The Number of Machines Controlled by Botnets Has Jumped 4x in Last 3 Months
2008-08-13
Adrien de Beaupre
CNN switched to MSNBC
2008-08-05
Daniel Wesemann
The news update you never asked for
2008-07-20
Kevin Liston
Malware Intelligence: Making it Actionable
2008-07-15
Maarten Van Horenbeeck
Extracting scripts and data from suspect PDF files
2008-07-14
Daniel Wesemann
Obfuscated JavaScript Redux
2008-07-07
Pedro Bueno
Bad url classification
2008-06-18
Marcus Sachs
Olympics Part II
2008-06-14
Lorna Hutcheson
Malware Detection - Take the Blinders Off
2008-06-10
Swa Frantzen
Ransomware keybreaking
2008-06-01
Mark Hofman
Free Yahoo email account! Sign me up, Ok well maybe not.
2008-05-28
Adrien de Beaupre
Another example of malicious SWF
2008-05-27
Adrien de Beaupre
Malicious swf files?
2008-05-26
Marcus Sachs
Predictable Response
2008-05-14
Bojan Zdrnja
War of the worlds?
2008-05-02
Adrien de Beaupre
Hi, remember me?...
2008-04-30
Bojan Zdrnja
(Minor) evolution in Mac DNS changer malware
2008-04-24
Maarten Van Horenbeeck
Targeted attacks using malicious PDF files
2008-04-16
Bojan Zdrnja
The 10.000 web sites infection mystery solved
2008-04-15
Johannes Ullrich
SRI Malware Threat Center
2008-04-14
John Bambenek
A Federal Subpoena or Just Some More Spam & Malware?
2008-04-07
John Bambenek
HP USB Keys Shipped with Malware for your Proliant Server
2008-04-07
John Bambenek
Got Kraken?
2008-04-07
John Bambenek
Kraken Technical Details: UPDATED x3
2008-04-06
Daniel Wesemann
Advanced obfuscated JavaScript analysis
2008-04-04
Daniel Wesemann
nmidahena
2008-04-03
Bojan Zdrnja
VB detection: is it so difficult?
2008-04-02
Adrien de Beaupre
When is a DMG file not a DMG file
2008-03-27
Maarten Van Horenbeeck
Guarding the guardians: a story of PGP key ring theft
2006-08-31
Swa Frantzen
NT botnet submitted
2000-01-02
Deborah Hale
2010 A Look Back - 2011 A Look Ahead
PROTECTION
2012-04-26
Richard Porter
Define Irony: A medical device with a Virus?
2011-01-12
Richard Porter
How Many Loyalty Cards do you Carry?
2010-03-10
Rob VandenBrink
Microsoft re-release of KB973811 - attacks on Extended Protection for Authentication
2009-12-07
Rob VandenBrink
Layer 2 Network Protections – reloaded!
2009-11-11
Rob VandenBrink
Layer 2 Network Protections against Man in the Middle Attacks
2009-10-30
Rob VandenBrink
New version of NIST 800-41, Firewalls and Firewall Policy Guidelines
2009-08-29
Guy Bruneau
Immunet Protect - Cloud and Community Malware Protection
2009-06-27
Tony Carothers
New NIAP Strategy on the Horizon
site/port/ip search:
Announcement!
IPv6 Support Added
Our iptables client now supports submitting IPv6 firewall logs.
Get ISC Swag!!
Advertisement