A drive-by download that exploits CVE-2024-6332

First, Happy Thanksgiving to anyone that celebrates this holiday. In reality, I hope that we’re all thankful every day. Yes, I know- I’m working on a blog post on turkey day. It’s alright because I already helped cook a few items for the dinner table later this evening, and I have some free time, so why not? I’ll keep this one short. If you follow Microsoft Patch Tuesday’s like I do, then you probably know that Microsoft provided a patch for Microsoft Security Bulletin MS14-064, which was rated as critical. You can learn more about it here. ...

November 27, 2014 · 10 min · James Espinosa

SecTor basic malware analysis training

Last month, I attended SecTor 2014 in Toronto, a beautiful city in Ontario, Canada. Actually, that was the first time I had ever attended the conference and visited the country. I had a great time, and I met a few people that really made the rest of my time out there worthwhile. It has been a while since I last posted anything and thought I’d share some of the content that was presented during a basic malware analysis training session that I took at SecTor. You can find a better description of the session here. ...

November 15, 2014 · 7 min · James Espinosa

Styx exploit kit network traffic analysis

A couple of days ago, researchers at Barracuda Networks reported that Hasbro.com was serving malware to its visitors. For additional information, I recommend that you read the Threatpost blog, which covers the story in greater detail. The purpose for this blog post is to provide my analysis of the network traffic file(s) that were provided by Barracuda Networks, which you can obtain here. Obviously, this is nothing new. Exploit kits, specifically this one, are nothing new. However, as I continue to dive into the malware research world, I think it makes sense to explore the inner workings of common threats like this one. As a side note, I am not suggesting that this is by any means the best and only way to conduct this type of analysis. So with that, lets dive in! ...

January 30, 2014 · 9 min · James Espinosa

Android/Beita.A malware analysis

Recently, I started reading Decompiling Android by Godfrey Nolan, primarily out of interest and curiosity. Obviously, I have an interest in malware and all-things threatsy, maliciously and shady (I made those words up, just now). Anyway, I figured I’d give this Android malware sample and whirl, and see what that side of the world looks like. This post will be my first analysis on this subject, so it most certainly may not be complete - but I’ll try my best. ...

January 5, 2014 · 5 min · James Espinosa

Perl Shellbot.B trojan activity

This is probably not amazing news to many of you, since you probably see a lot of automated scanning and exploitation attempts on your network perimeter. Although a bit of old news by now, I thought I’d share anyway. About a week or two prior to ISC Diary posting about this active threat, I had seen activity related to this Trojan on one of the systems that I have. The following is one of the many similar entries in my access.log: ...

October 10, 2013 · 5 min · James Espinosa