VB Blog

VB2019 paper: Defeating APT10 compiler-level obfuscations

Posted by   Virus Bulletin on   Mar 13, 2020

At VB2019 in London, Carbon Black researcher Takahiro Haruyama presented a paper on defeating compiler-level obfuscations used by the APT10 group. Today we publish both Takahiro's paper and the recording of his presentation.

Read more  

VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers

Posted by   Virus Bulletin on   Mar 12, 2020

At VB2019 in London Michael Raggi (Proofpoint) and Ghareeb Saad (Anomali) presented a paper on the 'Royal Road' exploit builder (or weaponizer) and how the properties of RTF files can be used to track weaponizers and their users. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 presentation: Nexus between OT and IT threat intelligence

Posted by   Virus Bulletin on   Mar 11, 2020

Operational technology, the mission critical IT in ICS, shares many similarities with traditional IT systems, but also some crucial differences. During the Threat Intelligence Practitioners’ Summit at VB2019, Dragos cyber threat intelligence analyst Selena Larson gave a keynote on these similarities and differences. Today we release the recording of her presentation.

Read more  

VB2019 paper: Kimsuky group: tracking the king of the spear-phishing

Posted by   Virus Bulletin on   Mar 10, 2020

In a paper presented at VB2019 in London, researchers fron the Financial Security Institute detailed the tools and activities used by the APT group 'Kimsuky', some of which they were able to analyse through OpSec failures by the group. Today, we publish their paper.

Read more  

VB2019 paper: Play fuzzing machine - hunting iOS and macOS kernel vulnerabilities automatically and smartly

Posted by   Virus Bulletin on   Mar 9, 2020

In a paper presented at VB2019 in London, Trend Micro researchers Lilang Wu and Moony Li explained how the hunt for vulnerabilities in MacOS and iOS operating systems can be made both smarter and more automatic. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Finding drive-by rookies using an automated active observation platform

Posted by   Virus Bulletin on   Mar 6, 2020

In a last-minute paper presented at VB2019 in London, Rintaro Koike (NTT Security) and Yosuke Chubachi (Active Defense Institute, Ltd) discussed the platform they have built to automatically detect and analyse exploit kits. Today we publish the recording of their presentation.

Read more  

VB2019 paper: Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation state adversary

Posted by   Virus Bulletin on   Feb 28, 2020

The activities of China-based threat actor PKPLUG were detailed in a VB2019 paper by Palo Alto Networks researcher Alex Hinchliffe, who described the playbook of this long-standing adversary. Today we publish both Alex's paper and the recording of his presentation.

Read more  

VB2019 paper: Static analysis methods for detection of Microsoft Office exploits

Posted by   Virus Bulletin on   Feb 25, 2020

Today we publish the VB2019 paper and presentation by McAfee researcher Chintan Shah in which he described static analysis methods for the detection of Microsoft Office exploits.

Read more  

New paper: LokiBot: dissecting the C&C panel deployments

Posted by   Helen Martin on   Feb 17, 2020

First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the URL structure of the LokiBot C&C panels and how they have evolved over time.

Read more  

VB2019 presentation: Building secure sharing systems that treat humans as features not bugs

Posted by   Helen Martin on   Feb 14, 2020

In a presentation at VB2019 in London, Virtru's Andrea Limbago described how, by exploring data sharing challenges through a socio-technical lens, it is possible to make significant gains toward the secure sharing systems and processes that are vital for innovation and collaboration. Today we release the recording of her presentation.

Read more  

Search blog

February

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/02/

2006

Latest news from the anti-virus industry provided by independent anti-virus advisors, Virus Bulletin
NewsBitDefender vulnerability disclosedDetails released of overflow issue reported and patched.18 December 2006UK taxman warns of rebate phishMails promising tax refund just… https://www.virusbulletin.com/blog/2006/

A global view

live spam map showing exactly where spam is coming from.
live spam map showing exactly where spam is coming from. Maintainers of cartographic collections may be interested in a new map created by Mailinator, a company that provides… https://www.virusbulletin.com/blog/2005/09/global-view/

Addendum: August 2005 Netware 6.5 Comparative Review

VB regrets that Symantec was not included in NetWare 6.5 comparative review published in the August 2005 issue of Virus Bulletin
VB regrets that Symantec was not included in NetWare 6.5 comparative review published in the August 2005 issue of Virus Bulletin Unfortunately, due to a combination of… https://www.virusbulletin.com/blog/2005/09/addendum-august-2005-netware-6-5-comparative-review/

Latest VGrep

The latest version of the virus name lookup tool - VGrep, is now available.
The latest version of the virus name lookup tool - VGrep, is now available. VGrep is a system produced in an attempt to clear up some of the confusion surrounding the naming of… https://www.virusbulletin.com/blog/2005/09/latest-vgrep/

CME initiative sets forth

US-CERT will officially unveil its Common Malware Enumeration (CME) initiative this month.
US-CERT will officially unveil its Common Malware Enumeration (CME) initiative this month. The scheme, which will be operated by MITRE, and will work very much like the current… https://www.virusbulletin.com/blog/2005/09/cme-initiative-sets-forth/

Czech spammers receive fines

The Czech Office for Personal Data Protection (UOOU) imposes first fines for spamming offences.
The Czech Office for Personal Data Protection (UOOU) imposes first fines for spamming offences. The Czech Office for Personal Data Protection (UOOU) has imposed its first fines for… https://www.virusbulletin.com/blog/2005/09/czech-spammers-receive-fines/

Spam 'hotline' for German users

German email users can now report spam directly to the Federation of German Consumer Organisations (vzbv)
German email users can now report spam directly to the Federation of German Consumer Organisations (vzbv)German email users can now report spam directly to the Federation of German… https://www.virusbulletin.com/blog/2005/09/spam-hotline-german-users/

Symantec snaps up Wholesecurity

Symantec announces plans to purchase privately held behavioural endpoint security solutions provider WholeSecurity Inc.
Symantec announces plans to purchase privately held behavioural endpoint security solutions provider WholeSecurity Inc. WholeSecurity’s behavioural detection technology identifies… https://www.virusbulletin.com/blog/2005/09/symantec-snaps-wholesecurity/

AVIEN virtual conference

Organisers of the AVIEN/AVIEWS virtual conference issue call for papers.
Organisers of the AVIEN/AVIEWS virtual conference issue call for papers. The organisers of the inaugural AVIEN/AVIEWS virtual conference have issued a call for papers. The… https://www.virusbulletin.com/blog/2005/09/avien-virtual-conference/

September

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2005/09/

Trial and retribution

Former AOL employee Jason Smathers sentenced to 15 months imprisonment for selling customers' email details to spammers.
Former AOL employee Jason Smathers sentenced to 15 months imprisonment for selling customers' email details to spammers. Former AOL employee Jason Smathers has been sentenced to 15… https://www.virusbulletin.com/blog/2005/08/trial-and-retribution/

The naming game

CA becomes latest AV firm to join name game with the announcement of its new division
CA becomes latest AV firm to join name game with the announcement of its new division First there was Kaspersky Lab and ICSA Labs, then came along MessageLabs and SophosLabs. Now… https://www.virusbulletin.com/blog/2005/08/naming-game/

More hash woes

For the second year running, research presented at the annual Crypto conference raised concerns over the security of commonly-used hash functions.
For the second year running, research presented at the annual Crypto conference raised concerns over the security of commonly-used hash functions. For the second year running,… https://www.virusbulletin.com/blog/2005/08/more-hash-woes/

Black Hat round-up

Andrew Lee shares his highlights of the Black Hat Briefings USA
Andrew Lee shares his highlights of the Black Hat Briefings USA In the midsummer heat of the Nevada desert, close to two thousand people donned their sunscreen and their coolest… https://www.virusbulletin.com/blog/2005/08/black-hat-round/

AhnLab wins in anti-spyware ruling

Court approves AhnLab's spyware classification
Court approves AhnLab's spyware classification The Southern District Court of Seoul ruled this week that AhnLab's detection and labelling as spyware of the product of software… https://www.virusbulletin.com/blog/2005/08/ahnlab-wins-anti-spyware-ruling/

August

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2005/08/

Hoax alert

New hoax email comes to light after the launch in the UK of a campaign involving personal emergency contact numbers
New hoax email comes to light after the launch in the UK of a campaign involving personal emergency contact numbers It has been a long while since VB reported on any virus hoaxes,… https://www.virusbulletin.com/blog/2005/07/hoax-alert/

Sun, sea, sand and scams

310 people arrested in Malaga after an operation involving the FBI, the US Postal Service and the Spanish police.
310 people arrested in Malaga after an operation involving the FBI, the US Postal Service and the Spanish police. Authorities in Malaga, Spain, must be congratulated on a bumper… https://www.virusbulletin.com/blog/2005/07/sun-sea-sand-and-scams/

Spammer reformed?

Scott Richter, aka the 'Spam King', is no longer classed as a spammer according to Spamhaus's authoritative Register of Known Spam Operations (ROKSO)
Scott Richter, aka the 'Spam King', is no longer classed as a spammer according to Spamhaus's authoritative Register of Known Spam Operations (ROKSO) Scott Richter, aka the 'Spam… https://www.virusbulletin.com/blog/2005/07/spammer-reformed/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.