DShield Honeypot Setup with pfSense, (Tue, Jan 31st)

Setting up a DShield honeypot is well guided by the installation script &#;x26;#;x5b;1&#;x26;#;x5d;. After several minutes of following the instructions and adding some custom details, the honeypot is up and running. What&#;x26;#;39;s needed after that is to expose the honeypot to the internet. I recently decided to update my home router and thought it was a great opportunity to dig into using pfSense &#;x26;#;x5b;2&#;x26;#;x5d;. To expose the honeypot using the pfsense, there are two main options to consider for NAT rules &#;x26;#;x5b;3&#;x26;#;x5d;:

Continue reading DShield Honeypot Setup with pfSense, (Tue, Jan 31st)→

Posted in Uncategorized

Decoding DNS over HTTP(s) Requests, (Mon, Jan 30th)

I have written before about scans for DNS over HTTP(s) (DoH) servers. DoH is now widely supported in different browsers and recursive resolvers. It has been an important piece in the puzzle to evade various censorship regimes, in particular, the “Big Chinese Firewall”. Malware has at times used DoH, but often uses its own HTTP(s) based resolvers that do not necessarily comply with the official DoH standard.

Continue reading Decoding DNS over HTTP(s) Requests, (Mon, Jan 30th)→

Posted in Uncategorized

A First Malicious OneNote Document, (Wed, Jan 25th)

Attackers are always trying to find new ways to deliver malware to victims. They recently started sending Microsoft OneNote files in massive phishing campaigns[1]. OneNote files (ending the extension “.one”) are handled automatically by computers that have the Microsoft Office suite installed. Yesterday, my honeypot caught a first sample. This is a good opportunity to have a look at these files. The file, called “delivery-note.one”, was delivered as an attachment to a classic phishing email:

Continue reading A First Malicious OneNote Document, (Wed, Jan 25th)→

Posted in Uncategorized