MAC INFO |
2021-03-12 | Guy Bruneau | Microsoft DHCP Logs Shipped to ELK |
MAC |
2025-04-02/a> | Guy Bruneau | Exploring Statistical Measures to Predict URLs as Legitimate or Intrusive [Guest Diary] |
2025-03-31/a> | Johannes Ullrich | Apple Patches Everything: March 31st 2025 Edition |
2025-03-26/a> | Jesse La Grew | [Guest Diary] Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest |
2025-03-11/a> | Johannes Ullrich | Apple Fixes Exploited WebKit Vulnerability in iOS, MacOS, visionOS and Safari |
2024-12-11/a> | Johannes Ullrich | Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS) |
2024-10-28/a> | Johannes Ullrich | Apple Updates Everything |
2024-10-07/a> | Xavier Mertens | macOS Sequoia: System/Network Admins, Hold On! |
2024-07-30/a> | Johannes Ullrich | Apple Patches Everything. July 2024 Edition |
2024-07-10/a> | Jesse La Grew | Finding Honeypot Data Clusters Using DBSCAN: Part 1 |
2024-01-22/a> | Johannes Ullrich | Apple Updates Everything - New 0 Day in WebKit |
2024-01-19/a> | Xavier Mertens | macOS Python Script Replacing Wallet Applications with Rogue Apps |
2023-12-11/a> | Johannes Ullrich | Apple Patches Everything |
2023-09-26/a> | Johannes Ullrich | Apple Releases MacOS Sonoma Including Numerous Security Patches |
2023-09-11/a> | Johannes Ullrich | Apple fixes 0-Day Vulnerability in Older Operating Systems |
2023-09-07/a> | Johannes Ullrich | Apple Releases iOS/iPadOS 16.6.1, macOS 13.5.2, watchOS 9.6.2 fixing two zeroday vulnerabilities |
2023-08-26/a> | Xavier Mertens | macOS: Who?s Behind This Network Connection? |
2023-06-22/a> | Johannes Ullrich | Apple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari |
2023-04-07/a> | Johannes Ullrich | Apple Patching Two 0-Day Vulnerabilities in iOS and macOS |
2023-03-27/a> | Johannes Ullrich | Apple Updates Everything (including Studio Display) |
2022-07-26/a> | Xavier Mertens | How is Your macOS Security Posture? |
2022-07-20/a> | Johannes Ullrich | Apple Patches Everything Day |
2022-04-20/a> | Brad Duncan | "aa" distribution Qakbot (Qbot) infection with DarkVNC traffic |
2022-03-31/a> | Johannes Ullrich | Apple Patches Actively Exploited Vulnerability in macOS, iOS and iPadOS, |
2022-03-25/a> | Xavier Mertens | XLSB Files: Because Binary is Stealthier Than XML |
2022-03-14/a> | Johannes Ullrich | Apple Updates Everything: MacOS 12.3, XCode 13.3, tvOS 15.4, watchOS 8.5, iPadOS 15.4 and more |
2022-02-10/a> | Johannes Ullrich | iOS/iPadOS and MacOS Update: Single WebKit 0-Day Vulnerability Patched |
2022-01-27/a> | Johannes Ullrich | Apple Patches Everything |
2022-01-22/a> | Xavier Mertens | Mixed VBA & Excel4 Macro In a Targeted Excel Sheet |
2021-12-28/a> | Russ McRee | LotL Classifier tests for shells, exfil, and miners |
2021-12-20/a> | Jan Kopriva | PowerPoint attachments, Agent Tesla and code reuse in malware |
2021-12-02/a> | Brad Duncan | TA551 (Shathak) pushes IcedID (Bokbot) |
2021-09-23/a> | Xavier Mertens | Excel Recipe: Some VBA Code with a Touch of Excel4 Macro |
2021-09-01/a> | Brad Duncan | STRRAT: a Java-based RAT that doesn't care if you have Java |
2021-08-06/a> | Xavier Mertens | Malicious Microsoft Word Remains A Key Infection Vector |
2021-04-23/a> | Xavier Mertens | Malicious PowerPoint Add-On: "Small Is Beautiful" |
2021-03-12/a> | Guy Bruneau | Microsoft DHCP Logs Shipped to ELK |
2021-03-03/a> | Brad Duncan | Qakbot infection with Cobalt Strike |
2021-02-25/a> | Daniel Wesemann | Forensicating Azure VMs |
2021-02-23/a> | Jan Kopriva | Qakbot in a response to Full Disclosure post |
2021-02-05/a> | Xavier Mertens | VBA Macro Trying to Alter the Application Menus |
2021-02-03/a> | Brad Duncan | Excel spreadsheets push SystemBC malware |
2021-02-02/a> | Xavier Mertens | New Example of XSL Script Processing aka "Mitre T1220" |
2021-01-26/a> | Brad Duncan | TA551 (Shathak) Word docs push Qakbot (Qbot) |
2021-01-20/a> | Brad Duncan | Qakbot activity resumes after holiday break |
2021-01-14/a> | Bojan Zdrnja | Dynamically analyzing a heavily obfuscated Excel 4 macro malicious file |
2021-01-13/a> | Brad Duncan | Hancitor activity resumes after a hoilday break |
2020-12-22/a> | Xavier Mertens | Malware Victim Selection Through WiFi Identification |
2020-12-09/a> | Brad Duncan | Recent Qakbot (Qbot) activity |
2020-11-20/a> | Xavier Mertens | Malicious Python Code and LittleSnitch Detection |
2020-11-09/a> | Xavier Mertens | How Attackers Brush Up Their Malicious Scripts |
2020-10-26/a> | Didier Stevens | Excel 4 Macros: "Abnormal Sheet Visibility" |
2020-10-14/a> | Brad Duncan | More TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-09-23/a> | Xavier Mertens | Malicious Word Document with Dynamic Content |
2020-09-18/a> | Xavier Mertens | A Mix of Python & VBA in a Malicious Word Document |
2020-09-10/a> | Brad Duncan | Recent Dridex activity |
2020-09-09/a> | Johannes Ullrich | A First Look at macOS 11 Big Sur Network Traffic (New! Now with more GREASE!) |
2020-08-26/a> | Xavier Mertens | Malicious Excel Sheet with a NULL VT Score |
2020-08-19/a> | Xavier Mertens | Example of Word Document Delivering Qakbot |
2020-08-07/a> | Brad Duncan | TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-08-06/a> | Xavier Mertens | A Fork of the FTCode Powershell Ransomware |
2020-08-03/a> | Xavier Mertens | Powershell Bot with Multiple C2 Protocols |
2020-07-15/a> | Brad Duncan | Word docs with macros for IcedID (Bokbot) |
2020-07-11/a> | Guy Bruneau | VMware XPC Client validation privilege escalation vulnerability - https://www.vmware.com/security/advisories/VMSA-2020-0017.html |
2020-07-10/a> | Brad Duncan | Excel spreasheet macro kicks off Formbook infection |
2020-07-04/a> | Russ McRee | Happy FouRth of July from the Internet Storm Center |
2020-06-12/a> | Xavier Mertens | Malicious Excel Delivering Fileless Payload |
2020-06-10/a> | Brad Duncan | Job application-themed malspam pushes ZLoader |
2020-06-01/a> | Didier Stevens | XLMMacroDeobfuscator: An Update |
2020-05-20/a> | Brad Duncan | Microsoft Word document with malicious macro pushes IcedID (Bokbot) |
2020-04-05/a> | Guy Bruneau | Maldoc XLS Invoice with Excel 4 Macros |
2020-03-29/a> | Didier Stevens | Obfuscated Excel 4 Macros |
2020-03-18/a> | Brad Duncan | Trickbot gtag red5 distributed as a DLL file |
2020-03-09/a> | Didier Stevens | Malicious Spreadsheet With Data Connection and Excel 4 Macros |
2020-03-06/a> | Xavier Mertens | A Safe Excel Sheet Not So Safe |
2020-02-24/a> | Didier Stevens | Maldoc: Excel 4 Macros and VBA, Devil and Angel? |
2020-02-23/a> | Didier Stevens | Maldoc: Excel 4 Macros in OOXML Format |
2020-02-21/a> | Xavier Mertens | Quick Analysis of an Encrypted Compound Document Format |
2020-01-22/a> | Brad Duncan | German language malspam pushes Ursnif |
2020-01-09/a> | Xavier Mertens | Quick Analyzis of a(nother) Maldoc |
2019-12-11/a> | Brad Duncan | German language malspam pushes yet another wave of Trickbot |
2019-12-04/a> | Jan Kopriva | Analysis of a strangely poetic malware |
2019-10-02/a> | Brad Duncan | A recent example of Emotet malspam |
2019-09-26/a> | Rob VandenBrink | Mining MAC Address and OUI Information |
2019-09-18/a> | Brad Duncan | Emotet malspam is back |
2019-07-08/a> | Didier Stevens | Machine Code? No! |
2019-07-04/a> | Didier Stevens | Machine Code? |
2019-06-18/a> | Brad Duncan | Malspam with password-protected Word docs pushing Dridex |
2019-03-17/a> | Didier Stevens | Video: Maldoc Analysis: Excel 4.0 Macro |
2019-03-16/a> | Didier Stevens | Maldoc: Excel 4.0 Macros |
2019-03-13/a> | Brad Duncan | Malspam pushes Emotet with Qakbot as the follow-up malware |
2019-01-24/a> | Brad Duncan | Malspam with Word docs uses macro to run Powershell script and steal system data |
2018-12-18/a> | Brad Duncan | Malspam links to password-protected Word docs that push IcedID (Bokbot) |
2018-11-27/a> | Xavier Mertens | More obfuscated shell scripts: Fake MacOS Flash update |
2018-11-15/a> | Brad Duncan | Emotet infection with IcedID banking Trojan |
2018-11-04/a> | Pasquale Stirparo | Beyond good ol' LaunchAgent - part 1 |
2018-10-21/a> | Pasquale Stirparo | Beyond good ol’ LaunchAgent - part 0 |
2018-08-24/a> | Xavier Mertens | Microsoft Publisher Files Delivering Malware |
2018-06-29/a> | Remco Verhoef | Crypto community target of MacOS malware |
2018-05-25/a> | Xavier Mertens | Antivirus Evasion? Easy as 1,2,3 |
2018-05-23/a> | Remco Verhoef | Track naughty and nice binaries with Google Santa |
2018-05-01/a> | Xavier Mertens | Diving into a Simple Maldoc Generator |
2017-12-19/a> | Xavier Mertens | Example of 'MouseOver' Link in a Powerpoint File |
2017-12-16/a> | Xavier Mertens | Microsoft Office VBA Macro Obfuscation via Metadata |
2017-11-15/a> | Xavier Mertens | If you want something done right, do it yourself! |
2017-09-19/a> | Jim Clausing | New tool: mac-robber.py |
2017-02-26/a> | Guy Bruneau | It is Tax Season - Watch out for Suspicious Attachment |
2016-09-30/a> | Xavier Mertens | Another Day, Another Malicious Behaviour |
2015-02-19/a> | Daniel Wesemann | Macros? Really?! |
2014-01-24/a> | Chris Mohan | Security Update for OS X for CVE-2014-1252 http://support.apple.com/kb/HT6117 |
2013-12-17/a> | Adrien de Beaupre | Apple security updates Mac OS X and Safari |
2013-10-22/a> | Richard Porter | Greenbone and OpenVAS Scanner |
2013-10-02/a> | John Bambenek | Obamacare related domain registration spike, Government shutdown domain registration beginning |
2013-09-10/a> | Swa Frantzen | Macs need to patch too! |
2013-08-09/a> | Kevin Shortt | Copy Machines - Changing Scanned Content |
2013-03-02/a> | Scott Fendley | Apple Blocks Older Insecure Versions of Flash Player |
2012-07-05/a> | Adrien de Beaupre | New OS X trojan backdoor MaControl variant reported |
2012-05-05/a> | Tony Carothers | Vulnerability Exploit for Snow Leopard |
2012-04-12/a> | Guy Bruneau | Apple Java Updates for Mac OS X |
2012-02-24/a> | Guy Bruneau | Flashback Trojan in the Wild |
2012-02-04/a> | Scott Fendley | Apple Security Advisory 2012-001 v1.1 |
2011-08-05/a> | donald smith | New Mac Trojan: BASH/QHost.WB |
2011-06-23/a> | Jim Clausing | Apple Security Updates 2011-004 |
2011-06-15/a> | Pedro Bueno | Hit by MacDefender, Apple Web Security (name your Mac FakeAV here)... |
2011-05-26/a> | Swa Frantzen | MacDefender ups the ante with removing the password need for installation |
2011-05-06/a> | Richard Porter | Unpatched Exploit: Skype for MAC |
2010-11-16/a> | Guy Bruneau | Mac OS X Server v10.6.5 (10H575) Security Update: http://support.apple.com/kb/HT4452 |
2010-06-17/a> | Deborah Hale | Digital Copy Machines - Security Risk? |
2010-06-15/a> | Manuel Humberto Santander Pelaez | Apple releases advisory for Mac OS X - Multiple vulnerabilities discovered |
2010-03-29/a> | Adrien de Beaupre | APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 |
2010-02-05/a> | Jim Clausing | Memory Analysis - time to move beyond XP |
2010-01-12/a> | Adrien de Beaupre | PoC for CVE-2009-0689 MacOS X 10.5/10.6 vulnerability |
2009-12-07/a> | Rob VandenBrink | Layer 2 Network Protections – reloaded! |
2009-11-09/a> | Guy Bruneau | Apple Security Update 2009-006 for Mac OS X v10.6.2 |
2009-01-24/a> | Pedro Bueno | Identifying and Removing the iWork09 Trojan |
2008-07-17/a> | Mari Nichols | Firefox Releases 3.0.1 and fixes 3 security vulnerabilities |
2008-04-30/a> | Bojan Zdrnja | (Minor) evolution in Mac DNS changer malware |
2008-04-02/a> | Adrien de Beaupre | When is a DMG file not a DMG file |
2006-12-12/a> | Swa Frantzen | Microsoft Office 2004 - Mac OS X updated |
2006-11-29/a> | Toby Kohlenberg | New Vulnerability Announcement and patches from Apple |
INFO |
2025-04-15/a> | Xavier Mertens | Online Services Again Abused to Exfiltrate Data |
2025-01-29/a> | Xavier Mertens | From PowerShell to a Python Obfuscation Race! |
2025-01-28/a> | Xavier Mertens | Fileless Python InfoStealer Targeting Exodus |
2024-11-30/a> | Xavier Mertens | From a Regular Infostealer to its Obfuscated Version |
2024-11-22/a> | Xavier Mertens | An Infostealer Searching for « BIP-0039 » Data |
2024-11-07/a> | Xavier Mertens | Steam Account Checker Poisoned with Infostealer |
2024-10-31/a> | Guy Bruneau | October 2024 Activity with Username chenzilong |
2024-10-09/a> | Xavier Mertens | From Perfctl to InfoStealer |
2024-09-18/a> | Guy Bruneau | Time-to-Live Analysis of DShield Data with Vega-Lite |
2024-09-18/a> | Xavier Mertens | Python Infostealer Patching Windows Exodus App |
2024-08-27/a> | Xavier Mertens | Why Is Python so Popular to Infect Windows Hosts? |
2024-05-31/a> | Xavier Mertens | "K1w1" InfoStealer Uses gofile.io for Exfiltration |
2024-05-22/a> | Rob VandenBrink | NMAP Scanning without Scanning (Part 2) - The ipinfo API |
2024-02-20/a> | Xavier Mertens | Python InfoStealer With Dynamic Sandbox Detection |
2024-01-25/a> | Xavier Mertens | Facebook AdsManager Targeted by a Python Infostealer |
2023-12-22/a> | Xavier Mertens | Shall We Play a Game? |
2023-09-29/a> | Xavier Mertens | Are You Still Storing Passwords In Plain Text Files? |
2023-05-04/a> | Xavier Mertens | Infostealer Embedded in a Word Document |
2023-03-12/a> | Guy Bruneau | AsynRAT Trojan - Bill Payment (Pago de la factura) |
2023-03-01/a> | Xavier Mertens | Python Infostealer Targeting Gamers |
2023-02-18/a> | Guy Bruneau | Spear Phishing Handlers for Username/Password |
2023-02-04/a> | Guy Bruneau | Assemblyline as a Malware Analysis Sandbox |
2023-01-21/a> | Guy Bruneau | DShield Sensor JSON Log to Elasticsearch |
2023-01-08/a> | Guy Bruneau | DShield Sensor JSON Log Analysis |
2022-12-21/a> | Guy Bruneau | DShield Sensor Setup in Azure |
2022-12-18/a> | Guy Bruneau | Infostealer Malware with Double Extension |
2022-08-13/a> | Guy Bruneau | Phishing HTML Attachment as Voicemail Audio Transcription |
2022-08-11/a> | Xavier Mertens | InfoStealer Script Based on Curl and NSudo |
2022-03-23/a> | Brad Duncan | Arkei Variants: From Vidar to Mars Stealer |
2022-03-09/a> | Xavier Mertens | Infostealer in a Batch File |
2022-02-13/a> | Guy Bruneau | DHL Spear Phishing to Capture Username/Password |
2021-12-21/a> | Xavier Mertens | More Undetected PowerShell Dropper |
2021-12-14/a> | Johannes Ullrich | Log4j: Getting ready for the long haul (CVE-2021-44228) |
2021-12-01/a> | Xavier Mertens | Info-Stealer Using webhook.site to Exfiltrate Data |
2021-05-08/a> | Guy Bruneau | Who is Probing the Internet for Research Purposes? |
2021-04-06/a> | Jan Kopriva | Malspam with Lokibot vs. Outlook and RFCs |
2021-03-31/a> | Xavier Mertens | Quick Analysis of a Modular InfoStealer |
2021-03-12/a> | Guy Bruneau | Microsoft DHCP Logs Shipped to ELK |
2020-12-29/a> | Jan Kopriva | Want to know what's in a folder you don't have a permission to access? Try asking your AV solution... |
2019-11-27/a> | Brad Duncan | Finding an Agent Tesla malware sample |
2019-10-09/a> | Brad Duncan | What data does Vidar malware steal from an infected host? |
2019-01-24/a> | Brad Duncan | Malspam with Word docs uses macro to run Powershell script and steal system data |
2018-11-11/a> | Pasquale Stirparo | Community contribution: joining forces or multiply solutions? |
2017-05-06/a> | Xavier Mertens | The story of the CFO and CEO... |
2016-10-02/a> | Guy Bruneau | Is there an Infosec Cybersecurity Talent Shortage? |
2015-01-23/a> | Adrien de Beaupre | Infocon change to yellow for Adobe Flash issues |
2014-09-26/a> | Richard Porter | Why We Have Moved to InfoCon:Yellow |
2014-05-22/a> | Johannes Ullrich | Discontinuing Support for ISC Alert Task Bar Icon |
2014-04-14/a> | Kevin Shortt | INFOCon Green: Heartbleed - on the mend |
2013-02-17/a> | Guy Bruneau | HP ArcSight Connector Appliance and Logger Vulnerabilities |
2012-03-16/a> | Swa Frantzen | INFOCON Yellow - Microsoft RDP - MS12-020 |
2012-01-19/a> | Chris Mohan | WHOIS contacts are your friends |
2012-01-13/a> | Guy Bruneau | Sysinternals Updates - http://blogs.technet.com/b/sysinternals/archive/2012/01/13/updates-autoruns-v11-21-coreinfo-v3-03-portmon-v-3-03-process-explorer-v15-12-mark-s-blog-and-mark-at-rsa-2012.aspx |
2011-02-05/a> | Guy Bruneau | OpenSSH Legacy Certificate Information Disclosure Vulnerability |
2011-01-12/a> | Richard Porter | How Many Loyalty Cards do you Carry? |
2010-12-26/a> | Manuel Humberto Santander Pelaez | ISC infocon monitor app for OS X |
2010-10-22/a> | Manuel Humberto Santander Pelaez | Intypedia project |
2010-07-24/a> | Manuel Humberto Santander Pelaez | Transmiting logon information unsecured in the network |
2010-07-20/a> | Manuel Humberto Santander Pelaez | Lowering infocon back to green |
2010-06-15/a> | Manuel Humberto Santander Pelaez | iPhone 4 Order Security Breach Exposes Private Information |
2010-04-21/a> | Guy Bruneau | Google Chrome Security Update v4.1.249.1059 Released: http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html |
2010-03-27/a> | Guy Bruneau | HP-UX Running NFS/ONCplus, Inadvertently Enabled NFS |
2010-01-17/a> | Mark Hofman | Why not Yellow? |
2009-11-29/a> | Patrick Nolan | A Cloudy Weekend |
2009-10-22/a> | Adrien de Beaupre | Sysinternals updates: Disk2vhd v1.1, ZoomIt v4.1, Coreinfo v2.0, VMMap v2.4 |
2009-10-04/a> | Guy Bruneau | Samba Security Information Disclosure and DoS |
2009-10-02/a> | Stephen Hall | New SysInternal fun for the weekend |
2009-07-13/a> | Adrien de Beaupre | * Infocon raised to yellow for Excel Web Components ActiveX vulnerability |
2009-07-10/a> | Guy Bruneau | WordPress Fixes Multiple vulnerabilities |
2009-07-07/a> | Marcus Sachs | * INFOCON Status - staying green |
2009-06-11/a> | Rick Wanner | MIR-ROR Motile Incident Response - Respond Objectively Remediate |
2009-03-02/a> | Swa Frantzen | Obama's leaked chopper blueprints: anything we can learn? |
2008-09-11/a> | David Goldsmith | CookieMonster is coming to Pown (err, Town) |
2008-08-12/a> | Johannes Ullrich | Upcoming Infocon Test and new Color |
2008-07-02/a> | Jim Clausing | Another little script I threw together |
2008-04-07/a> | John Bambenek | HP USB Keys Shipped with Malware for your Proliant Server |
2006-10-02/a> | Jim Clausing | Back to green, but the exploits are still running wild |