A First Malicious OneNote Document, (Wed, Jan 25th)

Attackers are always trying to find new ways to deliver malware to victims. They recently started sending Microsoft OneNote files in massive phishing campaigns[1]. OneNote files (ending the extension “.one”) are handled automatically by computers that have the Microsoft Office suite installed. Yesterday, my honeypot caught a first sample. This is a good opportunity to have a look at these files. The file, called “delivery-note.one”, was delivered as an attachment to a classic phishing email:

Continue reading A First Malicious OneNote Document, (Wed, Jan 25th)→

Posted in Uncategorized

And yet another packet Tuesday. Sticking with IPv6 for this episode: Neighbor Discovery! https://www.youtube.com/watch?v=CoaZjuuY1do #ipv6 #packetlife #pcaps #inpcapswetrust #packettuesday, (Tue, Jan 24th)

—
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

Continue reading And yet another packet Tuesday. Sticking with IPv6 for this episode: Neighbor Discovery! https://www.youtube.com/watch?v=CoaZjuuY1do #ipv6 #packetlife #pcaps #inpcapswetrust #packettuesday, (Tue, Jan 24th)→

Posted in Uncategorized

DShield Sensor JSON Log to Elasticsearch, (Sat, Jan 21st)

My current project has been to rebuild my home DShield sensor from a Rasberry Pi to a Ubuntu 20.04.5 LTS server to be able to process my sensor logs into Elasticsearh. I use as a guide the example listed here (my ELK is version 8.x) sending the cowrie.json logs to a remote ELK server (version 8.4.1) using Filebeat and Logstash. However, my steps were a little different than the reference:

Continue reading DShield Sensor JSON Log to Elasticsearch, (Sat, Jan 21st)→

Posted in Uncategorized