From Perfctl to InfoStealer, (Wed, Oct 9th)

A few days ago, a new stealthy malware targeting Linux hosts made a lot of noise: perfctl[1]. The malware has been pretty well analyzed and I won’t repeat what has been already disclosed. I found a copy of the “httpd” binary (SHA256:22e4a57ac560ebe1eff8957906589f4dd5934ee555ebcc0f7ba613b07fad2c13)[2]. I dropped the malware in my lab to see how it detonated. I infected the lab without root privileges and detected the same behavior except files were not written to some locations due to a lack of access (not root). When executing without root privileges, the rootkit feature is unavailable and the malware runs “disclosed”.

Continue reading From Perfctl to InfoStealer, (Wed, Oct 9th)

Posted in Uncategorized

macOS Sequoia: System/Network Admins, Hold On!, (Mon, Oct 7th)

It&#;x26;#;39;s always tempting to install the latest releases of your preferred software and operating systems. After all, that&#;x26;#;39;s the message we pass to our beloved users: “Patch, patch, and patch again!”. Last week, I was teaching for SANS and decided to not upgrade my MacBook to macOS 15.0 (Sequoia). Today, I had nothing critical scheduled and made the big jump. Upgrading the operating system is always stressful but everything ran smoothly. So far so good…

Continue reading macOS Sequoia: System/Network Admins, Hold On!, (Mon, Oct 7th)

Posted in Uncategorized

Survey of CUPS exploit attempts, (Fri, Oct 4th)

It is about a week since the release of the four CUPS remote code execution vulnerabilities. After the vulnerabilities became known, I configured one of our honeypots that watches a larger set of IPs to specifically collect UDP packets to port 631. Here is a quick summary of the results.

Continue reading Survey of CUPS exploit attempts, (Fri, Oct 4th)

Posted in Uncategorized