Phishing page with trivial anti-analysis features, (Fri, Nov 17th)

Anti-analysis features in phishing pages – especially in those, which threat actors send out as e-mail attachments – are nothing new[1,2]. Nevertheless, sometimes the way that these mechanisms are implemented may still leave one somewhat mystified. This has happened to me a few weeks ago when I found what appeared to be a generic phishing message in one of my spam traps.

Continue reading Phishing page with trivial anti-analysis features, (Fri, Nov 17th)

Posted in Uncategorized

Redline Dropped Through MSIX Package, (Wed, Nov 15th)

The MSIX package file format has been in the light for a few weeks. The GHOSTPULSE[1] malware has been identified to bypass many security controls delivered through an MSIX package. Like many operating systems, Windows can install applications by executing an executable (often called “setup.exe”), but packages are also available. Think about the well-known “.deb” for Debian/Ubuntu or “.rpm” for RedHat/CentOS. In the Windows eco-system, packages have the “.msi” extension. They have been used to deliver malware for a while (see my old diary from 2018![2]).

Continue reading Redline Dropped Through MSIX Package, (Wed, Nov 15th)

Posted in Uncategorized

Redline Dropped Through MSIX Package, (Wed, Nov 15th)

The MSIX package file format has been in the light for a few weeks. The GHOSTPULSE[1] malware has been identified to bypass many security controls delivered through an MSIX package. Like many operating systems, Windows can install applications by executing an executable (often called “setup.exe”), but packages are also available. Think about the well-known “.deb” for Debian/Ubuntu or “.rpm” for RedHat/CentOS. In the Windows eco-system, packages have the “.msi” extension. They have been used to deliver malware for a while (see my old diary from 2018![2]).

Continue reading Redline Dropped Through MSIX Package, (Wed, Nov 15th)

Posted in Uncategorized

Microsoft Patch Tuesday November 2023, (Tue, Nov 14th)

Today, Microsoft released patches for 64 different vulnerabilities in Microsoft products, 14 vulnerabilities in Chromium affecting Microsoft Edge, and five vulnerabilities affecting Microsoft&#;x26;#;39;s Linux distribution, Mariner. Three of these vulnerabilities are already being exploited, and three have been made public before the release of the patches.

Continue reading Microsoft Patch Tuesday November 2023, (Tue, Nov 14th)

Posted in Uncategorized

Noticing command and control channels by reviewing DNS protocols, (Mon, Nov 13th)

Malicious software pieces installed in computers call home. Some of them can be noticed because they perform DNS lookup and some of them initiates connection without DNS lookup. For this last option, this is abnormal and can be noticed by any Network Detection and Response (NDR) tool that reviews the network traffic by at least two weeks.

Continue reading Noticing command and control channels by reviewing DNS protocols, (Mon, Nov 13th)

Posted in Uncategorized