Welcome to DeepEnd Research
We are pleased to introduce DeepEnd Research, an independent information security research group that will focus on threat and intelligence analysis. Our emphasis will be on malware, exploit analysis,...
View ArticleDirt Jumper DDoS Bot - New versions, New targets
By Andre' M. DiMino & Mila ParkourEnd-2012.comI recently encountered a malware sample that when sandboxed, exhibited a great deal of DDoS-like activity toward a large number of URLs. When I looked...
View ArticleYara Signature Exchange Google Group
Yara-Exchange Google Group (by invitation only)https://groups.google.com/d/forum/yaraexchangePlease read the Yara Exchange Group rules below and if you are interested, request an invitation by sending...
View ArticleJava 7 0-Day vulnerability information and mitigation.
Update Aug.30, 2012Oracle issued update 7 (7u7), which fixed the vulnerability img.kids.discovery.comThe cat is out of the bag. There is a 0-day out there currently being used in targeted attacks....
View ArticleCVE-2012-4681 Java 7 0-Day vulnerability analysis
Update Aug.30, 2012Oracle issued update 7 (7u7), which fixed the vulnerability. Update: Aug. 28, 2012. Rapid 7 / Metasploit released their module and we get a lot of questions related to it from...
View ArticleBlackhole & Cridex: Season 2 Episode 1: Intuit Spam & SSL traffic analysis
The other day, I received another spam email, this time supposedly from Intuit. Since I know that Blackhole2 is now directing to Bugat/Feodo/Cridex banking malware, I wanted to look more closely and...
View ArticleCommon Exploit Kits 2012 Poster
Hurricane Sandy, Jersey ShoreSrc. Twitter Oct 28,2012 author unknownThe poster includes most common exploit packs of 2012. The poster will be updated and new issues posted in the future.Poster...
View ArticleTrojan Nap aka Kelihos/Hlux - Feb. 2013 Status Update
Update Feb 11, 2012 Regarding media headlines that it is a "new version": Please note that this post is a "status update" on the growth of the Kelihos botnet. It is the same botnet and malware as we...
View ArticleYara Resources
Yara Project by Víctor Manuel Álvarez Yara Exchange Google Group - exchange yara signatures, tools, resources, and ideas. 170+ members as of Feb.2013Notable Yara related publications by date:2013-02...
View ArticleLibrary of Malware Traffic Patterns
Update May 6, 2013We added ability to download corresponding samples and pcaps (when available). Same password scheme as contagio. Email Mila if needed.Traffic analysis has been the primary method of...
View ArticleUnder this rock... Vulnerable Wordpress/Joomla sites...
Overview of the RFI botnet malware arsenalExploits directed at Wordpress and/or Joomla content management systems(CMS) have been increasing at a dramatic rate over the past year. Internet blogs and...
View ArticleList of malware pcaps, samples, and indicators for the Library of Malware...
The library of malware traffic patterns have been popular. We found it very useful as well ourselves and we encourage you to send your contributions. I know at some point the spreadsheet will become...
View ArticleHey Zollard, leave my Internet of Things alone!
We've long been tracking exploit attempts against web servers, notably CMS hosts, ColdFusion, and vanilla PHP/CGI servers. Of late, we've observed a fairly large increase in PHP exploit attempts. So...
View ArticleAnother Linux DDoS bot via CVE-2012-1823
If you run a web server, you should be very familiar with the PHP vulnerability classified as CVE-2012-1823. Successful exploitation of this vulnerability allows a remote attacker to inject arbitrary...
View ArticleLinux.BackDoor.XNote.1 indicators
We continue to see a variety of Linux ELF malware, particularly those focused on DDoS.Over the past few years, the good folks at Malware Must Die have done an extensive study of ELF malware variants at...
View ArticleWelcome to DeepEnd Research
We are pleased to introduce DeepEnd Research, an independent information security research group that will focus on threat and intelligence analysis. Our emphasis will be on malware, exploit analysis,...
View ArticleDirt Jumper DDoS Bot - New versions, New targets
By Andre' M. DiMino& Mila ParkourEnd-2012.comI recently encountered a malware sample that when sandboxed, exhibited a great deal of DDoS-like activity toward a large number of URLs. When I looked...
View ArticleYara Signature Exchange Google Group
Yara-Exchange Google Group (by invitation only)https://groups.google.com/d/forum/yaraexchangePlease read the Yara Exchange Group rules below and if you are interested, request an invitation by sending...
View ArticleJava 7 0-Day vulnerability information and mitigation.
Update Aug.30, 2012Oracle issued update 7 (7u7), which fixed the vulnerability img.kids.discovery.comThe cat is out of the bag. There is a 0-day out there currently being used in targeted attacks....
View ArticleCVE-2012-4681 Java 7 0-Day vulnerability analysis
Update Aug.30, 2012Oracle issued update 7 (7u7), which fixed the vulnerability. Update: Aug. 28, 2012. Rapid 7 / Metasploit released their module and we get a lot of questions related to it from...
View Article