Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: Diaries by Keyword Diaries by Keyword

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

DDOS EXTORTION FAKE

2017-07-07Renato MarinhoDDoS Extortion E-mail: Yet Another Bluff?

DDOS

2019-08-14/a>Brad DuncanRecent example of MedusaHTTP malware
2017-10-20/a>Rick WannerOne year Anniversary of Dyn DDOS
2017-07-07/a>Renato MarinhoDDoS Extortion E-mail: Yet Another Bluff?
2016-12-29/a>Rick WannerMore on Protocol 47 denys
2016-12-19/a>John BambenekUPDATED x1: Mirai Scanning for Port 6789 Looking for New Victims / Now hitting tcp/23231
2016-12-09/a>Rick WannerMirai - now with DGA
2016-05-29/a>Guy BruneauAnalysis of a Distributed Denial of Service (DDoS)
2016-02-07/a>Rick WannerDDOS is down, but still a concern for ISPs
2015-06-23/a>Kevin ShorttXOR DDOS Mitigation and Analysis
2015-02-27/a>Rick WannerDDOS are way down? Why?
2015-02-19/a>Daniel WesemannDNS-based DDoS
2014-08-31/a>Rick Wanner1900/UDP (SSDP) Scanning and DDOS
2014-08-17/a>Rick WannerPart 2: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-08-17/a>Rick WannerPart 1: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-06-24/a>Kevin ShorttNTP DDoS Counts Have Dropped
2014-06-02/a>Rick WannerUsing nmap to scan for DDOS reflectors
2014-04-30/a>Russ McReeUltraDNS DDOS
2014-03-12/a>Johannes UllrichWordpress "Pingback" DDoS Attacks
2014-02-17/a>Chris MohanNTP reflection attacks continue
2013-11-22/a>Rick WannerPort 0 DDOS
2013-06-05/a>Richard PorterBIND 9 Update fixing CVE-2013-3919
2013-04-21/a>John BambenekA Chargen-based DDoS? Chargen is still a thing?
2013-03-28/a>John BambenekWhere Were You During the Great DDoS Cybergeddon of 2013?
2013-03-18/a>Kevin ShorttSpamhaus DDOS
2012-09-20/a>Russ McReeFinancial sector advisory: attacks and threats against financial institutions
2012-03-30/a>Daniel WesemannTomorrow, the world will end
2012-01-22/a>Johannes UllrichJavascript DDoS Tool Analysis
2011-05-20/a>Guy BruneauDistributed Denial of Service Cheat Sheet
2011-04-05/a>Mark HofmanDNS.be DDOS
2011-04-05/a>Mark HofmanSony DDOS
2011-03-04/a>Mark HofmanDDOS, the new black?
2011-02-12/a>Kevin ListonDDoS Analysis Process
2011-01-29/a>Mark HofmanSourceforge attack
2010-12-09/a>Mark HofmanHaving a look at the DDOS tool used in the attacks today
2010-12-08/a>Rob VandenBrinkInteresting DDOS activity around Wikileaks
2010-09-14/a>Adrien de BeaupreBlackEnergy DDoS
2010-08-16/a>Raul SilesDDOS: State of the Art
2010-08-07/a>Stephen HallDnsMadeEasy under a "quite large and unique" ddos.
2010-02-02/a>Johannes UllrichPushdo Update
2010-01-19/a>Jim Clausing49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-06/a>Johannes UllrichDenial of Service Attack Aftermath (and what did Iran have to do with it?)
2009-09-09/a>Mark HofmanPossible DDOS on gov.au sites starting tonight?
2009-07-09/a>John BambenekLatest Updates on Ongoing DDoS on Governmental/Commercial Websites in USA and S. Korea
2009-07-08/a>Marcus SachsRFI: DDoS Against Government and Civilian Web Sites
2009-06-23/a>Bojan ZdrnjaSlowloris and Iranian DDoS attacks
2009-03-08/a>Marcus SachsBehind the Estonia Cyber Attacks
2009-01-31/a>Swa FrantzenDNS DDoS - let's use a long term solution
2008-12-03/a>Andre LudwigNew ISC Poll! Has your organization suffered a DDoS (Distributed Denial of Service) attack in the last year?
2008-07-20/a>Kevin ListonDenial of Service Attack Against Georgia-- Are You Participating?
2008-04-10/a>Deborah HaleDSLReports Being Attacked Again

EXTORTION

2019-09-22/a>Didier StevensVideo: Encrypted Sextortion PDFs
2019-09-16/a>Didier StevensEncrypted Sextortion PDFs
2019-08-05/a>Rick WannerSextortion: Follow the Money - The Final Chapter
2019-03-24/a>Didier StevensDecoding QR Codes with Python
2019-03-21/a>Xavier MertensNew Wave of Extortion Emails: Central Intelligence Agency Case
2019-02-25/a>Didier StevensSextortion Email Variant: With QR Code
2019-02-01/a>Rick WannerSextortion: Follow the Money Part 3 - The cashout begins!
2019-01-18/a>John BambenekSextortion Bitcoin on the Move
2018-12-14/a>Rick WannerBombstortion?? Boomstortion??
2018-08-13/a>Didier StevensNew Extortion Tricks: Now Including Your (Partial) Phone Number!
2018-07-12/a>Johannes UllrichNew Extortion Tricks: Now Including Your Password!
2017-07-07/a>Renato MarinhoDDoS Extortion E-mail: Yet Another Bluff?
2016-03-13/a>Guy BruneauA Look at the Mandiant M-Trends 2016 Report
2014-07-02/a>Johannes UllrichSimple Javascript Extortion Scheme Advertised via Bing
2014-04-21/a>Daniel WesemannAllow us to leave!
2011-09-05/a>Bojan ZdrnjaBitcoin – crypto currency of future or heaven for criminals?

FAKE

2020-02-05/a>Brad DuncanFake browser update pages are "still a thing"
2019-04-07/a>Guy BruneauFake Office 365 Payment Information Update
2019-04-02/a>Johannes UllrichFake AV is Back: LaCie Network Drives Used to Spread Malware
2019-03-21/a>Xavier MertensNew Wave of Extortion Emails: Central Intelligence Agency Case
2017-07-07/a>Renato MarinhoDDoS Extortion E-mail: Yet Another Bluff?
2016-05-12/a>Xavier MertensAnother Day, Another Wave of Phishing Emails
2015-09-28/a>Johannes Ullrich"Transport of London" Malicious E-Mail
2014-02-21/a>Johannes UllrichUPS Malware Spam Using Fake SPF Headers
2013-04-29/a>Adam SwangerReport Fake Tech Support Calls submission form reminder
2013-04-16/a>John BambenekFake Boston Marathon Scams Update
2013-01-03/a>Manuel Humberto Santander PelaezNew year and new CA compromised
2012-12-06/a>Daniel WesemannFake tech support calls - revisited
2012-10-03/a>Kevin ShorttFake Support Calls Reported
2012-06-19/a>Daniel Wesemann Vulnerabilityqueerprocessbrittleness
2011-07-25/a>Bojan ZdrnjaWhen the FakeAV coder(s) fail
2011-07-21/a>Daniel WesemannDown the FakeAV rabbit hole
2011-05-19/a>Daniel WesemannFake AV Bingo
2011-05-04/a>Bojan ZdrnjaMore on Google image poisoning
2011-01-18/a>Daniel WesemannYet another rogue anti-virus
2010-11-11/a>Daniel WesemannFake AV scams via Skype Chat
2010-02-27/a>Johannes UllrichSearch Engine Poisoning: Chile Earthquake
2010-02-15/a>Johannes UllrichVarious Olympics Related Dangerous Google Searches
2010-02-08/a>Adrien de BeaupreWhen is a 0day not a 0day? Fake OpenSSh exploit, again.
2010-01-08/a>Rob VandenBrinkMicrosoft OfficeOnline, Searching for Trust and Malware
2009-09-17/a>Bojan ZdrnjaWhy is Rogue/Fake AV so successful?
2009-09-04/a>Adrien de BeaupreFake anti-virus
2009-02-06/a>Adrien de BeaupreFake stimulus payments
2008-09-15/a>donald smithFake antivirus 2009 and search engine results