Internet Storm Center
Sign In
Sign Up
Handler on Duty:
Xavier Mertens
Threat Level:
green
Date
Author
Title
PYTHON 32
2011-02-21
Adrien de Beaupre
What’s New, it's Python 3.2
PYTHON
2024-11-22/a>
Xavier Mertens
An Infostealer Searching for « BIP-0039 » Data
2024-11-19/a>
Xavier Mertens
Detecting the Presence of a Debugger in Linux
2024-11-07/a>
Xavier Mertens
Steam Account Checker Poisoned with Infostealer
2024-11-05/a>
Xavier Mertens
Python RAT with a Nice Screensharing Feature
2024-09-18/a>
Xavier Mertens
Python Infostealer Patching Windows Exodus App
2024-09-17/a>
Xavier Mertens
23:59, Time to Exfiltrate!
2024-09-16/a>
Xavier Mertens
Managing PE Files With Overlays
2024-09-13/a>
Jesse La Grew
Finding Honeypot Data Clusters Using DBSCAN: Part 2
2024-09-11/a>
Xavier Mertens
Python Libraries Used for Malicious Purposes
2024-08-30/a>
Jesse La Grew
Simulating Traffic With Scapy
2024-08-29/a>
Xavier Mertens
Live Patching DLLs with Python
2024-08-27/a>
Xavier Mertens
Why Is Python so Popular to Infect Windows Hosts?
2024-08-26/a>
Xavier Mertens
From Highly Obfuscated Batch File to XWorm and Redline
2024-08-23/a>
Jesse La Grew
Pandas Errors: What encoding are my logs in?
2024-08-19/a>
Xavier Mertens
Do you Like Donuts? Here is a Donut Shellcode Delivered Through PowerShell/Python
2024-08-16/a>
Jesse La Grew
[Guest Diary] 7 minutes and 4 steps to a quick win: A write-up on custom tools
2024-07-26/a>
Xavier Mertens
ExelaStealer Delivered "From Russia With Love"
2024-07-24/a>
Xavier Mertens
"Mouse Logger" Malicious Python Script
2024-07-10/a>
Jesse La Grew
Finding Honeypot Data Clusters Using DBSCAN: Part 1
2024-06-06/a>
Xavier Mertens
Malicious Python Script with a "Best Before" Date
2024-05-31/a>
Xavier Mertens
"K1w1" InfoStealer Uses gofile.io for Exfiltration
2024-05-30/a>
Xavier Mertens
Feeding MISP with OSSEC
2024-03-13/a>
Xavier Mertens
Using ChatGPT to Deobfuscate Malicious Scripts
2024-02-20/a>
Xavier Mertens
Python InfoStealer With Dynamic Sandbox Detection
2024-02-08/a>
Xavier Mertens
A Python MP3 Player with Builtin Keylogger Capability
2024-01-25/a>
Xavier Mertens
Facebook AdsManager Targeted by a Python Infostealer
2024-01-19/a>
Xavier Mertens
macOS Python Script Replacing Wallet Applications with Rogue Apps
2024-01-17/a>
Jesse La Grew
Number Usage in Passwords
2024-01-08/a>
Jesse La Grew
What is that User Agent?
2023-12-23/a>
Xavier Mertens
Python Keylogger Using Mailtrap.io
2023-12-22/a>
Xavier Mertens
Shall We Play a Game?
2023-12-16/a>
Xavier Mertens
An Example of RocketMQ Exploit Scanner
2023-11-20/a>
Jesse La Grew
Overflowing Web Honeypot Logs
2023-10-31/a>
Xavier Mertens
Multiple Layers of Anti-Sandboxing Techniques
2023-09-30/a>
Xavier Mertens
Simple Netcat Backdoor in Python Script
2023-08-25/a>
Xavier Mertens
Python Malware Using Postgresql for C2 Communications
2023-08-23/a>
Guy Bruneau
How I made a qwerty ?keyboard walk? password generator with ChatGPT [Guest Diary]
2023-08-22/a>
Xavier Mertens
Have You Ever Heard of the Fernet Encryption Algorithm?
2023-08-17/a>
Jesse La Grew
Command Line Parsing - Are These Really Unique Strings?
2023-08-11/a>
Xavier Mertens
Show me All Your Windows!
2023-07-28/a>
Xavier Mertens
ShellCode Hidden with Steganography
2023-06-20/a>
Xavier Mertens
Malicious Code Can Be Anywhere
2023-04-28/a>
Xavier Mertens
Quick IOC Scan With Docker
2023-03-18/a>
Xavier Mertens
Old Backdoor, New Obfuscation
2023-03-11/a>
Xavier Mertens
Overview of a Mirai Payload Generator
2023-03-01/a>
Xavier Mertens
Python Infostealer Targeting Gamers
2023-02-09/a>
Xavier Mertens
A Backdoor with Smart Screenshot Capability
2022-11-14/a>
Jesse La Grew
Extracting 'HTTP CONNECT' Requests with Python
2022-10-24/a>
Xavier Mertens
C2 Communications Through outlook.com
2022-10-18/a>
Xavier Mertens
Python Obfuscation for Dummies
2022-09-26/a>
Xavier Mertens
Easy Python Sandbox Detection
2022-09-14/a>
Xavier Mertens
Easy Process Injection within Python
2022-08-19/a>
Johannes Ullrich
Windows Security Blocks UPX Compressed (packed) Binaries
2022-08-18/a>
Johannes Ullrich
Honeypot Attack Summaries with Python
2022-07-20/a>
Xavier Mertens
Malicious Python Script Behaving Like a Rubber Ducky
2022-06-24/a>
Xavier Mertens
Python (ab)using The Windows GUI
2022-05-24/a>
Yee Ching Tok
ctx Python Library Updated with "Extra" Features
2022-04-21/a>
Xavier Mertens
Multi-Cryptocurrency Clipboard Swapper
2022-01-20/a>
Xavier Mertens
RedLine Stealer Delivered Through FTP
2022-01-07/a>
Xavier Mertens
Custom Python RAT Builder
2022-01-06/a>
Xavier Mertens
Malicious Python Script Targeting Chinese People
2021-12-10/a>
Xavier Mertens
Python Shellcode Injection From JSON Data
2021-12-01/a>
Xavier Mertens
Info-Stealer Using webhook.site to Exfiltrate Data
2021-08-30/a>
Xavier Mertens
Cryptocurrency Clipboard Swapper Delivered With Love
2021-07-16/a>
Xavier Mertens
Multiple BaseXX Obfuscations
2021-07-08/a>
Xavier Mertens
Using Sudo with Python For More Security Controls
2021-07-06/a>
Xavier Mertens
Python DLL Injection Check
2021-07-02/a>
Xavier Mertens
"inception.py"... Multiple Base64 Encodings
2021-06-11/a>
Xavier Mertens
Keeping an Eye on Dangerous Python Modules
2021-05-31/a>
Rick Wanner
Quick and dirty Python: nmap
2021-05-04/a>
Rick Wanner
Quick and dirty Python: masscan
2021-04-29/a>
Xavier Mertens
From Python to .Net
2021-04-09/a>
Xavier Mertens
No Python Interpreter? This Simple RAT Installs Its Own Copy
2021-04-02/a>
Xavier Mertens
C2 Activity: Sandboxes or Real Victims?
2021-03-18/a>
Xavier Mertens
Simple Python Keylogger
2020-12-10/a>
Xavier Mertens
Python Backdoor Talking to a C2 Through Ngrok
2020-11-20/a>
Xavier Mertens
Malicious Python Code and LittleSnitch Detection
2020-11-09/a>
Xavier Mertens
How Attackers Brush Up Their Malicious Scripts
2020-10-20/a>
Xavier Mertens
Mirai-alike Python Scanner
2020-10-14/a>
Xavier Mertens
Nicely Obfuscated Python RAT
2020-09-18/a>
Xavier Mertens
A Mix of Python & VBA in a Malicious Word Document
2020-09-03/a>
Xavier Mertens
Sandbox Evasion Using NTP
2020-09-02/a>
Xavier Mertens
Python and Risky Windows API Calls
2020-08-18/a>
Xavier Mertens
Using API's to Track Attackers
2020-07-30/a>
Johannes Ullrich
Python Developers: Prepare!!!
2019-10-29/a>
Xavier Mertens
Generating PCAP Files from YAML
2018-11-26/a>
Russ McRee
ViperMonkey: VBA maldoc deobfuscation
2017-11-23/a>
Xavier Mertens
Proactive Malicious Domain Search
2017-10-05/a>
Johannes Ullrich
pcap2curl: Turning a pcap file into a set of cURL commands for "replay"
2017-08-22/a>
Xavier Mertens
Defang all the things!
2017-04-19/a>
Xavier Mertens
Hunting for Malicious Excel Sheets
2017-01-12/a>
Mark Baggett
System Resource Utilization Monitor
2017-01-01/a>
Didier Stevens
py2exe Decompiling - Part 1
2016-11-27/a>
Russ McRee
Scapy vs. CozyDuke
2016-07-25/a>
Didier Stevens
Python Malware - Part 4
2016-07-16/a>
Didier Stevens
Python Malware - Part 3
2016-05-15/a>
Didier Stevens
Python Malware - Part 1
2014-12-04/a>
Mark Baggett
Automating Incident data collection with Python
2011-02-21/a>
Adrien de Beaupre
What’s New, it's Python 3.2
2010-08-15/a>
Manuel Humberto Santander Pelaez
Python to test web application security
2010-06-14/a>
Manuel Humberto Santander Pelaez
Python on a microcontroller?
2010-03-30/a>
Marcus Sachs
Zigbee Analysis Tools
2010-02-17/a>
Rob VandenBrink
Multiple Security Updates for ESX 3.x and ESXi 3.x
2009-05-25/a>
Jim Clausing
More tools for (US) Memorial Day
32
2023-11-06/a>
Johannes Ullrich
Exploit Activity for CVE-2023-22518, Atlassian Confluence Data Center and Server
2023-08-25/a>
Xavier Mertens
Python Malware Using Postgresql for C2 Communications
2023-05-14/a>
Guy Bruneau
VMware Aria Operations addresses multiple Local Privilege Escalations and a Deserialization issue
2023-03-25/a>
Guy Bruneau
Microsoft Released an Update for Windows Snipping Tool Vulnerability
2022-10-15/a>
Guy Bruneau
Malware - Covid Vaccination Supplier Declaration
2022-08-22/a>
Xavier Mertens
32 or 64 bits Malware?
2021-05-21/a>
Xavier Mertens
Locking Kernel32.dll As Anti-Debugging Technique
2021-05-18/a>
Xavier Mertens
From RunDLL32 to JavaScript then PowerShell
2019-04-02/a>
Johannes Ullrich
Fake AV is Back: LaCie Network Drives Used to Spread Malware
2018-10-10/a>
Xavier Mertens
New Campaign Using Old Equation Editor Vulnerability
2017-09-05/a>
Johannes Ullrich
The Mirai Botnet: A Look Back and Ahead At What's Next
2014-07-07/a>
Johannes Ullrich
Multi Platform *Coin Miner Attacking Routers on Port 32764
2014-03-02/a>
Stephen Hall
Symantec goes yellow
2013-10-25/a>
Rob VandenBrink
Kaspersky flags TCPIP.SYS as Malware
2013-08-16/a>
Kevin Liston
CVE-2013-2251 Apache Struts 2.X OGNL Vulnerability
2013-02-22/a>
Chris Mohan
PHP 5.4.12 and PHP 5.3.22 released http://www.php.net/ChangeLog-5.php
2013-01-09/a>
Richard Porter
The 80's called - They Want Their Mainframe Back!
2012-09-23/a>
Tony Carothers
Update for CVE-2012-3132
2012-09-09/a>
Guy Bruneau
Phishing/Spam Pretending to be from BBB
2011-12-21/a>
Johannes Ullrich
New Vulnerability in Windows 7 64 bit
2011-02-21/a>
Adrien de Beaupre
What’s New, it's Python 3.2
2010-09-17/a>
Robert Danford
Circa 2007 Linux Kernel Vulnerability Resurfaces (Was CVE-2007-4573, Now CVE-2010-3301)
2010-01-04/a>
Bojan Zdrnja
Sophisticated, targeted malicious PDF documents exploiting CVE-2009-4324
2009-07-12/a>
Mari Nichols
CA Apologizes for False Positive
2008-08-15/a>
Jim Clausing
Another MS update that may have escaped notice
2008-04-27/a>
Marcus Sachs
What's With Port 20329?
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Contact Us
Contact Us
About Us
Handlers
About Us
Slack Channel
Mastodon
Bluesky
X
Learn
about the Internet Storm Center
and our
volunteer InfoSec handlers