Older Articles

31 OCT 2017

Deobfuscating PHPJiami

I was sent a PHP script that was protected by PHPJiami which you can find here...
24 JUN 2017

Converter.NET Released

I spent the past several months porting Converter to the .NET Framework and am...
2 MAY 2017

Wild Wild West - 05/2017

Another update to the exploit kit scene. There's been some changes but nothing very...
5 NOV 2016

Wild Wild West - 11/2016

It's been awhile since I updated this; my apologies for the delay to those who have...
30 SEP 2016

Tools Update 09/2016

Several programs have been updated. You can find them on the Tools page...
22 JUN 2016

Locky JS and URL Revealer

From various reports, it appears that the malicious Javascript files sent via email...
3 OCT 2015

Cyber Exercise Tools

For the past two years, I've been involved with several cyber exercises and...
20 JUN 2015

Another Converter Update

The latest version includes several new features which I'd like to highlight here...
15 FEB 2015

Another Revelo Update

A colleague of mine received the following email in their Gmail in-box and...
5 OCT 2014

Tools Update 10/2014

No significant updates, just several enhancements and bug fixes to four tools...
25 JUL 2014

Wild Wild West - 07/2014

Added the following packs: RIG Exploit Kit, Niteris aka "CottonCastle", "Snet"...
12 MAY 2014

RIG Exploit Pack

A new exploit pack has been marketed in the underground since last month and appears...
5 APR 2014

Wild Wild West - 04/2014

sorry this is so late. added the following packs: "Zuponcic", Infinity (aka "RedKit"...
6 FEB 2014

Revelo Updated

I've been noticing obfuscated Javascript using a function that returns the deobfuscated...
30 JAN 2014

Box.php Fraud Kit

I've been researching that fake Adobe Flash update and Neutrino EK redirect that...
9 JAN 2014

Exploit Delivery Networks

Exploit packs are normally set up on a hacker-controlled server. Compromised websites...
2 JAN 2014

Pinpoint Tool Released

There are many times where I come across a drive-by download, especially malvertisements...
1 DEC 2013

Wild Wild West – 12/2013

Added the following packs: White Lotus, CK Exploit Kit, “x2o Exploit Kit”, “Angler...
5 NOV 2013

Converted v0.10 Released

The latest version of Converter includes changes to the menus and several new features...
12 OCT 2013

PHP Infector

A reader wanted me to analyze a PHP file that was found on his hacked Wordpress site...
4 AUG 2013

Wild Wild West – 08/2013

Added the following packs: “FlashPack”, “Topic Exploit Kit”, Silence Exploit, “Rawin...
27 JUL 2013

Tools Update - 07/2013

I've updated several of the tools. I hope you find the updates helpful...
18 JUL 2013

Kore Exploit Kit

Recently, a reader passed on to me a very active TDS link that redirected users to...
22 JUN 2013

If Computers Were Cars...

Found this on an image site and didn’t see this elsewhere. This is both educational...
2 JUN 2013

Converter v0.8 Released

I added several new features in this release to help you with reverse engineering...
16 MAR 2013

Converter v0.7 Released

Malicious Java applets have been making news for awhile so I thought I would update...
24 FEB 2013

Converter v0.6 Released

Thank you to all of you for your feedback, patience, and support! It now has the...
23 FEB 2013

Another Clever Drive-By

This is yet another drive-by that was challenging to find. It delivered payloads...
2 JAN 2013

Converter Update 01/2013

Happy New Year! I finally finished developing and testing another version of Converter...
26 NOV 2012

New Exploit Pack Spotted

Another new exploit pack has been found in the wild. This pack uses two interesting...
1 NOV 2012

Not A Very Nice Pack

Someone just rigged an unsubscribe page with a Nice Pack drive-by! How cruel is...
23 OCT 2012

Wild Wild West – 10/2012

Added the folllowing packs: “KaiXin Exploit Pack”, “Kein Exploit Pack”, Grandsoft...
13 SEP 2012

CrimeBoss Exploit Pack

Earlier this year, the CrimeBoss exploit pack was released in beta form. An updated...
1 SEP 2012

Neosploit Gets Java 0-Day

Neosploit has been popping up every once and awhile, quietly infecting users without...
2 AUG 2012

New Chinese Exploit Pack

A Korean news site was recently observed distributing malware. I thought it would...
4 JUN 2012

Revelo v0.4 Released

I got some feedback from some folks as well as trying out some new methods to improve...
1 JUN 2012

Wild Wild West – 06/2012

New ones added: Sweet Orange, “Red Kit”, “Gong Da Pack”, Styx, CrimeBoss. If anyone...
9 MAY 2012

Revelo v0.3 Released

In this release, I've made a couple of bug fixes. I'm also using a traditional...
2 MAY 2012

Revelo v0.2 Released

Thank you all for your support and feedback with the release of Revelo (finally...
17 APR 2012

Binary File Converter

I wanted to copy over some of my tools into a remote host via VPN. The remote host...
16 MAR 2012

Converter v0.3 Released

Here's another update based on some recent real-world analysis I've done as well...
13 FEB 2012

Another Chinese Pack

This set of exploits was found on a Chinese website by @switchingtoguns. It appears...
28 JAN 2012

Techno XPack

There's another new exploit pack in town called Techno XPack. This one looks like...
27 JAN 2012

Hierarchy Exploit Pack

A new pack has emerged called Hierarchy Exploit Pack. Looks a lot like Eleonore...
12 JAN 2012

Chinese Exploit Packs

While it can be difficult to attribute exploit packs in many cases, I believe it's...
15 DEC 2011

Another New Exploit Pack

A new exploit pack is being used in the wild. This one was linked to malvertisements...
29 NOV 2011

Custom Base64 Decoder

There’s another new exploit pack making its round. Seems to be quite pervasive...
12 NOV 2011

Interesting BOA Phish

Phishing appears to be on the decline but some phishers aren’t stopping and have...
9 NOV 2011

APEC SpearPhish

A suspicious email was received on 10/26/2011 and targeted a single, key...
27 OCT 2011

Two Drive-Bys, One Site

It's bad enough to get hit with one drive-by download...but two on one page...
26 OCT 2011

Neosploit is Back!

After a long hiatus, it appears that Neosploit may have come back to life! While...
1 OCT 2011

Wild Wild West 10/2011

added “Nuclear Pack” to most wanted section. there’s several new packs out there...
17 AUG 2011

Hacking Magazine Hacked

One of my favorite hacking resource site appears to be hacked and possibly...
15 JUN 2011

Best Pack

ScriptKiddieSec broke the news about a new exploit pack called “Best Pack”...
14 JUN 2011

Sava Exploits Pack

This is a new exploit pack that is being offered for free. It also goes by the name...
1 JUN 2011

Wild Wild West 06/2011

lots of requests to keep this going...send me updates here: sectek at live dot com...
20 MAY 2011

Meta(sploit) Pack

Some time ago, the Open Source Exploit Pack was released on some hacker forums...
10 MAY 2011

Wild Wild West 05/2011

i got a lot of responses on my graphic so i’m posting an update with the feedback...
8 MAY 2011

New (Unknown) Exploit Kit

Here’s yet another new kit but I don’t have much on this including whether this...
19 APR 2011

Wild Wild West 04/2011

since there seems to be a lot of interest in attack toolkits, i grabbed the logos...
14 APR 2011

Yes Exploit Kit Upgraded

The author(s) of the Yes Exploit System has quietly upgraded their kit to version...
7 APR 2011

Cyber Security Tips

just wanted to put out a cyber security tip sheet i created for my company...
3 APR 2011

Robopak Exploit Kit

Looks like a new exploit kit is making its rounds. The seller is actually a service...
25 FEB 2011

Incognito Exploit Kit

Incognito is a relatively new exploit kit. It uses the following Javascript...
14 JAN 2011

Siberia Exploit Kit

Siberia Exploit Kit has been around for awhile but has been updated recently and...
2 JAN 2011

New Exploit Kits

PandaLabs reported that 34% of all malware ever created has appeared in the last...
7 DEC 2010

Deobfuscating Tricks

Deobfuscating malicious Javascript can be tricky at times. Luckily, there are...
29 NOV 2010

Bypassing XSS Filters

Testing web applications can be a frustrating experience especially when you keep...
24 NOV 2010

New Russian Exploit Kit

On the eve of Thanksgiving Day, I followed the trail of a drive-by exploit which...
20 NOV 2010

ZeuS...Alive and Well

Despite reports that the ZeuS author is getting out of the scene, hackers will...

DISCLAIMER

Kahu Security highlights security projects and research that may include references to malicious content. Your use of this website is at your own risk. You assume complete responsibility for, and for all risk of loss and damage resulting from, your downloading and/or using of any information obtained from this website.

CONTACT US