Update: oledump & MSI Files, (Sun, Apr 2nd)
I wrote about my new oledump plugin plugin_msi_info that analyzes MSI files (MSI files are OLE files) in diary entry “oledump & MSI Files“.
Continue reading Update: oledump & MSI Files, (Sun, Apr 2nd)
Collaborate Disseminate
I wrote about my new oledump plugin plugin_msi_info that analyzes MSI files (MSI files are OLE files) in diary entry “oledump & MSI Files“.
Continue reading Update: oledump & MSI Files, (Sun, Apr 2nd)
We wrote 2 diary entries about new features in release candidates of YARA 4.3.0.
Over the years I have found grep to be very versatile. The most common use of grep is to find if the logs have a string that match an IP address, a domain, a service or protocol, some application was logged, etc.
Continue reading Using Linux grep and Windows findstr to Manipulate Files, (Fri, Mar 31st)
In my last Diary[1], I shortly mentioned the need for correctly set Content Security Policy and/or the obsolete[2] X-Frame-Options HTTP security headers (not just) in order to prevent phishing pages, which overlay a fake login prompt over a legitimate website, from functioning correctly. Or, to be more specific, to prevent them from dynamically loading a legitimate page in an iframe under the fake login prompt, since this makes such phishing websites look much less like a legitimate login page and thus much less effective.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Friday, March 31st, 2023 https://isc.sans.edu/podcastdetail.html?id=8434, (Fri, Mar 31st)
Yesterday, I found a malicious PowerShell script that was heavily obfuscated. The filename is âB0A4.ps1″[1] (SHA256:b4814c8db16ecdd7904e81186715bf2a4b4ba28ef5853a41a8f59824f47f8f24), reported with a very low score on VirusTotal: 6/58. The file size is abnormal for a script like this (496KB). A first look at it reveals that it has been strongly obfuscated:
Continue reading Bypassing PowerShell Strong Obfuscation, (Thu, Mar 30th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Thursday, March 30th, 2023 https://isc.sans.edu/podcastdetail.html?id=8432, (Thu, Mar 30th)
Reader Martin asks us for some help extracting embedded content from a submitted malicious document.
Continue reading Extracting Multiple Streams From OLE Files, (Wed, Mar 29th)
Reader Martin asks us for some help extracting embedded content from a submitted malicious document.
Continue reading Extracting Multiple Streams From OLE Files, (Wed, Mar 29th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Wednesday, March 29th, 2023 https://isc.sans.edu/podcastdetail.html?id=8430, (Wed, Mar 29th)