Styx exploit kit network traffic analysis

A couple of days ago, researchers at Barracuda Networks reported that Hasbro.com was serving malware to its visitors. For additional information, I recommend that you read the Threatpost blog, which covers the story in greater detail. The purpose for this blog post is to provide my analysis of the network traffic file(s) that were provided by Barracuda Networks, which you can obtain here. Obviously, this is nothing new. Exploit kits, specifically this one, are nothing new. However, as I continue to dive into the malware research world, I think it makes sense to explore the inner workings of common threats like this one. As a side note, I am not suggesting that this is by any means the best and only way to conduct this type of analysis. So with that, lets dive in! ...

January 30, 2014 · 9 min · James Espinosa

Android/Beita.A malware analysis

Recently, I started reading Decompiling Android by Godfrey Nolan, primarily out of interest and curiosity. Obviously, I have an interest in malware and all-things threatsy, maliciously and shady (I made those words up, just now). Anyway, I figured I’d give this Android malware sample and whirl, and see what that side of the world looks like. This post will be my first analysis on this subject, so it most certainly may not be complete - but I’ll try my best. ...

January 5, 2014 · 5 min · James Espinosa

Perl Shellbot.B trojan activity

This is probably not amazing news to many of you, since you probably see a lot of automated scanning and exploitation attempts on your network perimeter. Although a bit of old news by now, I thought I’d share anyway. About a week or two prior to ISC Diary posting about this active threat, I had seen activity related to this Trojan on one of the systems that I have. The following is one of the many similar entries in my access.log: ...

October 10, 2013 · 5 min · James Espinosa

Discovered XSS vulnerabilities in The Bug Genie

Earlier this year, I discovered multiple cross-site scripting (XSS) vulnerabilities in The Bug Genie, an open source issue tracking and project management application. The Vulnerabilities For reference, the vulnerabilities were assigned CVE-2013-1760. Proper and timely disclosure practices were coordinated through the Trustwave SpiderLabs’ security advisory team. The Bug Genie version 3.2.4 and earlier, suffer from multiple persistent, and reflected XSS vulnerabilities in different areas of the application. I will not dive into details for each finding, as they are mentioned in the references below. ...

May 14, 2013 · 2 min · James Espinosa