Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC Diaries by Keyword


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
DateAuthorTitle

MALWARE FORENSICS

2010-04-30Kevin ListonThe Importance of Small Files

MALWARE

2014-10-03/a>Johannes UllrichCSAM: The Power of Virustotal to Turn Harmless Binaries Malicious
2014-09-22/a>Johannes UllrichFake LogMeIn Certificate Update with Bad AV Detection Rate
2014-08-06/a>Chris MohanFree Service to Help CryptoLocker Victims by FireEye and Fox-IT
2014-07-22/a>Daniel WesemannIvan's Order of Magnitude
2014-07-19/a>Russ McReeKeeping the RATs out: the trap is sprung - Part 3
2014-07-18/a>Russ McReeKeeping the RATs out: **it happens - Part 2
2014-07-18/a>Russ McReeGameover Zeus reported as "returned from the dead"
2014-07-16/a>Russ McReeKeeping the RATs out: an exercise in building IOCs - Part 1
2014-07-05/a>Guy BruneauMalware Analysis with pedump
2014-06-22/a>Russ McReeOfficeMalScanner helps identify the source of a compromise
2014-06-08/a>Guy Bruneauefax Spam Containing Malware
2014-04-06/a>Basil Alawi S.Taher"Power Worm" PowerShell based Malware
2014-04-05/a>Jim ClausingThose strange e-mails with URLs in them can lead to Android malware
2014-03-04/a>Daniel WesemannXPired!
2014-02-28/a>Daniel WesemannFiesta!
2014-01-19/a>Rick WannerAnatomy of a Malware distribution campaign
2013-12-24/a>Daniel WesemannMr Jones wants you to appear in court!
2013-12-23/a>Daniel WesemannCostco, BestBuy, Walmart really want to send you a package!
2013-12-07/a>Guy BruneauSuspected Active Rovnix Botnet Controller
2013-11-02/a>Rick WannerProtecting Your Family's Computers
2013-10-31/a>Russ McReeHappy Halloween: The Ghost Really May Be In The Machine
2013-10-30/a>Russ McReeSIR v15: Five good reasons to leave Windows XP behind
2013-10-28/a>Daniel WesemannExploit cocktail (Struts, Java, Windows) going after 3-month old vulnerabilities
2013-10-24/a>Johannes UllrichFalse Positive: php.net Malware Alert
2013-09-30/a>Adrien de BeaupreTwitter DM spam/malware
2013-09-12/a>Daniel Wesemann37.58.73.42 / 95.156.228.69 / 195.210.43.42, anyone?
2013-09-10/a>Swa FrantzenMacs need to patch too!
2013-08-29/a>Russ McReeSuspect Sendori software
2013-07-04/a>Russ McReeCelebrating 4th of July With a Malware PCAP Visualization
2013-06-18/a>Russ McReeVolatility rules...any questions?
2013-05-21/a>Adrien de BeaupreMoore, Oklahoma tornado charitable organization scams, malware, and phishing
2013-05-17/a>Daniel Wesemanne-netprotections.su ?
2013-05-16/a>Daniel WesemannExtracting signatures from Apple .apps
2013-05-11/a>Lenny ZeltserExtracting Digital Signatures from Signed Malware
2013-05-01/a>Daniel WesemannThe cost of cleaning up
2013-04-10/a>Manuel Humberto Santander PelaezMassive Google scam sent by email to Colombian domains
2013-03-22/a>Mark BaggettWipe the drive! Stealthy Malware Persistence - Part 4
2013-03-20/a>Mark BaggettWipe the drive! Stealthy Malware Persistence - Part 3
2013-03-19/a>Johannes UllrichScam of the day: More fake CNN e-mails
2013-03-15/a>Mark BaggettAVG detect legit file as virus
2013-03-14/a>Mark BaggettWipe the drive! Stealthy Malware Persistence - Part 2
2013-03-13/a>Mark BaggettWipe the drive! Stealthy Malware Persistence Mechanism - Part 1
2013-02-25/a>Johannes UllrichMass-Customized Malware Lures: Don't trust your cat!
2013-01-08/a>Jim ClausingCuckoo 0.5 is out and the world didn't end
2012-12-18/a>Rob VandenBrinkAll I Want for Christmas is to Not Get Hacked !
2012-12-03/a>Kevin ListonMobile Malware: Request for Field Reports
2012-11-02/a>Daniel WesemannLamiabiocasa
2012-11-01/a>Daniel WesemannPatched your Java yet?
2012-10-14/a>Pedro BuenoCyber Security Awareness Month - Day 14 - Poor Man's File Analysis System - Part 1
2012-09-21/a>Guy BruneauStoring your Collection of Malware Samples with Malwarehouse
2012-09-14/a>Lenny ZeltserAnalyzing Malicious RTF Files Using OfficeMalScanner's RTFScan
2012-07-21/a>Rick WannerOpenDNS is looking for a few good malware people!
2012-07-05/a>Adrien de BeaupreNew OS X trojan backdoor MaControl variant reported
2012-06-27/a>Swa FrantzenOnline Banking Heists
2012-06-26/a>Daniel WesemannRun, Forest! (Update)
2012-06-25/a>Swa FrantzenBelgian online banking customers hacked.
2012-06-25/a>Rick WannerTargeted Malware for Industrial Espionage?
2012-06-22/a>Daniel WesemannRun, Forest!
2012-06-21/a>Raul SilesPrint Bomb? (Take 2)
2012-06-21/a>Russ McReeAnalysis of drive-by attack sample set
2012-06-19/a>Daniel Wesemann Vulnerabilityqueerprocessbrittleness
2012-06-04/a>Lenny ZeltserDecoding Common XOR Obfuscation in Malicious Code
2012-04-26/a>Richard PorterDefine Irony: A medical device with a Virus?
2012-04-25/a>Daniel WesemannBlacole's obfuscated JavaScript
2012-04-25/a>Daniel WesemannBlacole's shell code
2012-04-12/a>Guy BruneauHP ProCurve 5400 zl Switch, Flash Cards Infected with Malware
2012-04-12/a>Guy BruneauApple Java Updates for Mac OS X
2012-03-25/a>Daniel Wesemannevilcode.class
2012-03-03/a>Jim ClausingNew automated sandbox for Android malware
2012-02-24/a>Guy BruneauFlashback Trojan in the Wild
2012-02-20/a>Pedro BuenoSimple Malware Research Tools
2012-02-20/a>Rick WannerDNSChanger resolver shutdown deadline is March 8th
2012-01-14/a>Daniel WesemannHello, Antony!
2011-12-28/a>Daniel Wesemann.nl.ai ?
2011-12-10/a>Daniel WesemannUnwanted Presents
2011-12-07/a>Lenny ZeltserV8 as an Alternative to SpiderMonkey for JavaScript Deobfuscation
2011-11-04/a>Guy BruneauDuqu Mitigation
2011-10-20/a>Johannes UllrichEvil Printers Sending Mail
2011-09-07/a>Lenny ZeltserAnalyzing Mobile Device Malware - Honeynet Forensic Challenge 9 and Some Tools
2011-08-29/a>Kevin ShorttInternet Worm in the Wild
2011-06-15/a>Pedro BuenoHit by MacDefender, Apple Web Security (name your Mac FakeAV here)...
2011-05-25/a>Daniel WesemannApple advisory on "MacDefender" malware
2011-05-19/a>Daniel WesemannFake AV Bingo
2011-05-14/a>Guy BruneauWebsense Study Claims Canada Next Hotbed for Cybercrime Web Hosting Activity
2011-05-03/a>Johannes UllrichUpdate on Osama Bin Laden themed Malware
2011-05-02/a>Johannes UllrichBin Laden Death Related Malware
2011-04-23/a>Manuel Humberto Santander PelaezImage search can lead to malware download
2011-03-01/a>Daniel WesemannAV software and "sharing samples"
2011-02-07/a>Pedro BuenoThe Good , the Bad and the Unknown Online Scanners
2011-02-01/a>Lenny ZeltserThe Importance of HTTP Headers When Investigating Malicious Sites
2010-12-29/a>Daniel WesemannMalware Domains 2234.in, 0000002.in & co
2010-12-29/a>Daniel WesemannBeware of strange web sites bearing gifts ...
2010-10-26/a>Pedro BuenoCyber Security Awareness Month - Day 26 - Sharing Office Files
2010-09-09/a>Marcus Sachs'Here You Have' Email
2010-07-21/a>Adrien de BeaupreDell PowerEdge R410 replacement motherboard firmware contains malware
2010-07-21/a>Adrien de Beaupreautorun.inf and .lnk Malware (NOT 'Vulnerability in Windows Shell Could Allow Remote Code Execution' 2286198)
2010-07-06/a>Rob VandenBrinkBogus Support Organizations use Live Operators to Install Malware
2010-07-04/a>Manuel Humberto Santander PelaezMalware inside PDF Files
2010-06-17/a>Deborah HaleFYI - Another bogus site
2010-06-14/a>Manuel Humberto Santander PelaezRogue facebook application acting like a worm
2010-06-07/a>Manuel Humberto Santander PelaezSoftware Restriction Policy to keep malware away
2010-06-02/a>Rob VandenBrinkNew Mac malware - OSX/Onionspy
2010-05-26/a>Bojan ZdrnjaMalware modularization and AV detection evasion
2010-05-23/a>Manuel Humberto Santander Pelaeze-mail scam announcing Fidel Castro's funeral ... and nasty malware to your computer.
2010-05-21/a>Rick WannerIBM distributes malware at AusCERT!
2010-04-30/a>Kevin ListonThe Importance of Small Files
2010-04-19/a>Daniel WesemannLinked into scams?
2010-04-18/a>Guy BruneauSome NetSol hosted sites breached
2010-04-13/a>Johannes UllrichMore Legal Threat Malware E-Mail
2010-03-30/a>Pedro BuenoSharing the Tools
2010-03-26/a>Daniel WesemannGetting the EXE out of the RTF again
2010-03-09/a>Marcus SachsEnergizer Malware
2010-03-04/a>Daniel Wesemannsalefale-dot-com is bad
2010-03-03/a>Johannes UllrichReports about large number of fake Amazon order confirmations
2010-02-21/a>Patrick Nolan Looking for "more useful" malware information? Help develop the format.
2010-01-14/a>Bojan ZdrnjaPDF Babushka
2010-01-07/a>Daniel WesemannStatic analysis of malicious PDFs
2010-01-07/a>Daniel WesemannStatic analysis of malicous PDFs (Part #2)
2009-12-17/a>Daniel Wesemannoverlay.xul is back
2009-12-17/a>Daniel WesemannIn caches, danger lurks
2009-12-16/a>Rob VandenBrinkBeware the Attack of the Christmas Greeting Cards !
2009-12-07/a>Rick WannerCheat Sheet: Analyzing Malicious Documents
2009-12-04/a>Daniel WesemannMax Power's Malware Paradise
2009-12-02/a>Rob VandenBrinkSPAM and Malware taking advantage of H1N1 concerns
2009-11-25/a>Jim ClausingUpdates to my GREM Gold scripts and a new script
2009-09-25/a>Lenny ZeltserCategories of Common Malware Traits
2009-09-25/a>Deborah HaleConficker Continues to Impact Networks
2009-09-25/a>Deborah HaleMalware delivered over Google and Yahoo Ad's?
2009-09-04/a>Adrien de BeaupreFake anti-virus
2009-08-29/a>Guy BruneauImmunet Protect - Cloud and Community Malware Protection
2009-08-26/a>Johannes UllrichMalicious CD ROMs mailed to banks
2009-07-26/a>Jim ClausingNew Volatility plugins
2009-07-03/a>Adrien de BeaupreHappy 4th of July!
2009-07-02/a>Daniel WesemannGetting the EXE out of the RTF
2009-07-02/a>Bojan ZdrnjaCold Fusion web sites getting compromised
2009-06-16/a>John BambenekURL Shortening Service Cligs Hacked
2009-06-16/a>John BambenekIran Internet Blackout: Using Twitter for Operational Intelligence
2009-06-04/a>Raul SilesMalware targetting banks ATM's
2009-06-04/a>Raul SilesTargeted e-mail attacks asking to verify wire transfer details
2009-06-01/a>G. N. WhiteYet another "Digital Certificate" malware campaign
2009-05-20/a>Pedro BuenoCyber Warfare and Kylin thoughts
2009-05-07/a>Deborah HaleMalicious Content on the Web
2009-05-04/a>Tom ListonFacebook phishing malware
2009-04-24/a>Pedro BuenoDid you check your conference goodies?
2009-03-13/a>Bojan ZdrnjaWhen web application security, Microsoft and the AV vendors all fail
2009-02-23/a>Daniel WesemannTurf War
2009-02-23/a>Daniel WesemannAnd the Oscar goes to...
2009-02-10/a>Bojan ZdrnjaMore tricks from Conficker and VM detection
2009-02-09/a>Bojan ZdrnjaSome tricks from Conficker's bag
2009-02-04/a>Daniel WesemannTitan Shields up!
2009-01-31/a>John BambenekGoogle Search Engine's Malware Detection Broken
2009-01-24/a>Pedro BuenoIdentifying and Removing the iWork09 Trojan
2009-01-18/a>Daniel Wesemann3322. org
2009-01-15/a>Bojan ZdrnjaConficker's autorun and social engineering
2009-01-12/a>William SaluskyDownadup / Conficker - MS08-067 exploit and Windows domain account lockout
2009-01-07/a>Bojan ZdrnjaAn Israeli patriot program or a trojan
2009-01-02/a>Rick WannerTools on my Christmas list.
2008-12-25/a>Maarten Van HorenbeeckMerry Christmas, and beware of digital hitchhikers!
2008-12-25/a>Maarten Van HorenbeeckChristmas Ecard Malware
2008-12-17/a>donald smithTeam CYMRU's Malware Hash Registry
2008-12-05/a>Daniel WesemannBeen updatin' your Flash player lately?
2008-12-05/a>Daniel WesemannBaby, baby!
2008-12-04/a>Bojan ZdrnjaRogue DHCP servers
2008-11-17/a>Jim ClausingFinding stealth injected DLLs
2008-11-16/a>Maarten Van HorenbeeckDetection of Trojan control channels
2008-11-12/a>John BambenekThoughts on Security Intelligence (McColo Corp alleged spam/malware host knocked offline)
2008-11-11/a>Swa FrantzenAcrobat continued activity in the wild
2008-11-10/a>Stephen HallAdobe Reader Vulnerability - part 2
2008-10-07/a>Kyle HaugsnessGood reading and a malware challenge
2008-09-29/a>Daniel WesemannASPROX mutant
2008-09-22/a>Maarten Van HorenbeeckData exfiltration and the use of anonymity providers
2008-09-18/a>Bojan ZdrnjaMonitoring HTTP User-Agent fields
2008-09-07/a>Lorna HutchesonMalware Analysis: Tools are only so good
2008-09-03/a>Daniel WesemannStatic analysis of Shellcode
2008-09-03/a>Daniel WesemannStatic analysis of Shellcode - Part 2
2008-09-01/a>John BambenekThe Number of Machines Controlled by Botnets Has Jumped 4x in Last 3 Months
2008-08-13/a>Adrien de BeaupreCNN switched to MSNBC
2008-08-05/a>Daniel WesemannThe news update you never asked for
2008-07-20/a>Kevin ListonMalware Intelligence: Making it Actionable
2008-07-15/a>Maarten Van HorenbeeckExtracting scripts and data from suspect PDF files
2008-07-14/a>Daniel WesemannObfuscated JavaScript Redux
2008-07-07/a>Pedro BuenoBad url classification
2008-06-18/a>Marcus SachsOlympics Part II
2008-06-14/a>Lorna HutchesonMalware Detection - Take the Blinders Off
2008-06-10/a>Swa FrantzenRansomware keybreaking
2008-06-01/a>Mark HofmanFree Yahoo email account! Sign me up, Ok well maybe not.
2008-05-28/a>Adrien de BeaupreAnother example of malicious SWF
2008-05-27/a>Adrien de BeaupreMalicious swf files?
2008-05-26/a>Marcus SachsPredictable Response
2008-05-14/a>Bojan ZdrnjaWar of the worlds?
2008-05-02/a>Adrien de BeaupreHi, remember me?...
2008-04-30/a>Bojan Zdrnja(Minor) evolution in Mac DNS changer malware
2008-04-24/a>Maarten Van HorenbeeckTargeted attacks using malicious PDF files
2008-04-16/a>Bojan ZdrnjaThe 10.000 web sites infection mystery solved
2008-04-15/a>Johannes UllrichSRI Malware Threat Center
2008-04-14/a>John BambenekA Federal Subpoena or Just Some More Spam & Malware?
2008-04-07/a>John BambenekHP USB Keys Shipped with Malware for your Proliant Server
2008-04-07/a>John BambenekGot Kraken?
2008-04-07/a>John BambenekKraken Technical Details: UPDATED x3
2008-04-06/a>Daniel WesemannAdvanced obfuscated JavaScript analysis
2008-04-04/a>Daniel Wesemannnmidahena
2008-04-03/a>Bojan ZdrnjaVB detection: is it so difficult?
2008-04-02/a>Adrien de BeaupreWhen is a DMG file not a DMG file
2008-03-27/a>Maarten Van HorenbeeckGuarding the guardians: a story of PGP key ring theft
2006-08-31/a>Swa FrantzenNT botnet submitted
2000-01-02/a>Deborah Hale2010 A Look Back - 2011 A Look Ahead

FORENSICS

2014-08-10/a>Basil Alawi S.TaherIncident Response with Triage-ir
2014-06-22/a>Russ McReeOfficeMalScanner helps identify the source of a compromise
2014-06-03/a>Basil Alawi S.TaherAn Introduction to RSA Netwitness Investigator
2014-05-18/a>Russ McReesed and awk will always rock
2014-03-11/a>Basil Alawi S.TaherIntroduction to Memory Analysis with Mandiant Redline
2014-03-07/a>Tom WebbLinux Memory Dump with Rekall
2014-02-09/a>Basil Alawi S.TaherMandiant Highlighter 2
2014-01-10/a>Basil Alawi S.TaherWindows Autorun-3
2013-12-12/a>Basil Alawi S.TaherAcquiring Memory Images with Dumpit
2013-11-21/a>Mark Baggett"In the end it is all PEEKS and POKES."
2013-11-20/a>Mark BaggettSearching live memory on a running machine with winpmem
2013-11-19/a>Mark BaggettWinpmem - Mild mannered memory aquisition tool??
2013-08-26/a>Alex StanfordStop, Drop and File Carve
2013-08-14/a>Johannes UllrichImaging LUKS Encrypted Drives
2013-07-12/a>Rob VandenBrinkHmm - where did I save those files?
2013-05-23/a>Adrien de BeaupreMoVP II
2013-04-25/a>Adam SwangerSANS 2013 Forensics Survey - https://www.surveymonkey.com/s/2013SANSForensicsSurvey
2012-11-02/a>Daniel WesemannThe shortcomings of anti-virus software
2012-09-14/a>Lenny ZeltserAnalyzing Malicious RTF Files Using OfficeMalScanner's RTFScan
2012-06-04/a>Lenny ZeltserDecoding Common XOR Obfuscation in Malicious Code
2011-09-29/a>Daniel WesemannThe SSD dilemma
2011-08-05/a>Johannes UllrichForensics: SIFT Kit 2.1 now available for download http://computer-forensics.sans.org/community/downloads
2011-03-01/a>Daniel WesemannAV software and "sharing samples"
2010-11-17/a>Guy BruneauReference on Open Source Digital Forensics
2010-05-22/a>Rick WannerSANS 2010 Digital Forensics Summit - APT Based Forensic Challenge
2010-05-21/a>Rick Wanner2010 Digital Forensics and Incident Response Summit
2010-04-30/a>Kevin ListonThe Importance of Small Files
2010-04-11/a>Marcus SachsNetwork and process forensics toolset
2010-03-26/a>Daniel WesemannSIFT2.0 SANS Investigative Forensics Toolkit released
2009-12-14/a>Adrien de BeaupreAnti-forensics, COFEE vs. DECAF
2009-11-25/a>Jim ClausingUpdates to my GREM Gold scripts and a new script
2009-08-18/a>Daniel WesemannForensics: Mounting partitions from full-disk 'dd' images
2009-08-13/a>Jim ClausingNew and updated cheat sheets
2009-07-02/a>Daniel WesemannGetting the EXE out of the RTF
2009-02-02/a>Stephen HallHow do you audit your production code?
2009-01-02/a>Rick WannerTools on my Christmas list.
2008-11-17/a>Marcus SachsNew Tool: NetWitness Investigator
2008-08-17/a>Kevin ListonVolatility 1.3 Released
2008-08-15/a>Jim ClausingOMFW 2008 reflections