• CIF – Ransomware Tracker abuse.ch feeds

    Good Day guys!!!!!. Just finished another yml script to collect feeds from abuse.ch for Ransomware (ransomware tracker) and has been uploaded on my github account. Threat feeds is provided in CSV format and therefore CSV parser have been used. YML script is available on my github account – https://github.com/makflwana/CIF-Threat-Feeds-and-parsers Happy Hunting!!!!!!! Read More ⇢

  • CIF – Feodotracker threat feeds

    Good Day guys!!!!!. Was able to write another yml script to collect feeds from Feodotracker and has been uploaded on my github account and also a project that I am honoured to work on with CSIRT (with guidance of Wes Young) – BEARDED AVENGER. This is a new version of… Read More ⇢

  • CIF – cleanmx threat feeds

    Good Day today indeed. Have finally got some time to work on my skills for CIF and writing configuration (YAML scripts) to fetch open source threat feeds. Started with a disabled configuration (/etc/cif/rules/disabled/cleanmx.cfg) for cleanmx. The cleanmx.cfg file provided should be referenced for the remote sites and id for cleanmx, that… Read More ⇢

  • CIF – Collective Intelligence Framework – My deployment

    Morning Everybody!!!! Been working on crafting my skills in Threat Intelligence and available open source system. As the title says I have been working on CIF from CSIRT and wanted to share my experience and my personal future developments. Following are few screenshots of the system : CIF comes with… Read More ⇢

  • Malware Analysis – Mind Map

    Its been long time have updated my blog. Just busy @work and with family and trying to juggle a lot. Have been working a mind maps and this is the first one. Malware Analysis is something I like and interested in. I will creating other mind-maps. Mind-maps are also available… Read More ⇢

  • Dridex malware dropper -New doc 115.doc

    On a pleasant morning I received an email with an doc attachment. The email was not having any text or message. Subject was name of the attachment ‘New Doc 115’. It was my curious mind (place where the cat gets kills inevitably) that I decided to analyse it. The email actually… Read More ⇢

  • Ho Ho Ho – Here comes the spam/phish

    Merry Christmas and Happy New Year to all ! I thought to start the new year with a blog with regards to spam from Australian Giants – Woolworths, JB HiFi, Flight Centre, Bunnings etc. Although, we are on holidays, attackers/hackers are not. Holiday time is in fact very good time… Read More ⇢

  • Heap Spray attempts : Compromised site http://www.efendim.net

    On a Saturday evening I spent some time in upgrading my MacBook Pro with an SSD. The only SSD I had was having security Onion built on it. So I fired up the best NSM OS and tested. Is that during the test I found a compromised site – http://www.efendim.net. My SQUIL… Read More ⇢

  • Information Gathering – Then, Now and Why ?

    Information gathering is considered first and most important part before launching any types of attacks, hacking or penetration testing. Information gathering is known by several names – Reconnaissance, Intelligence assessment, surveillance etc. The better an attacker/analyst is in information gathering with regards to the target the better he/she can exploit… Read More ⇢