VB Blog

VB2019 paper: Fantastic Information and Where to Find it: A guidebook to open-source OT reconnaissance

Posted by   Martijn Grooten on   Nov 22, 2019

A VB2019 paper by FireEye researcher Daniel Kapellmann Zafra explained how open source intelligence (OSINT) can be used to learn crucial details of the inner workings of many a system. Today we publish Daniel's paper and the recording of his presentation.

Read more  

VB2019 paper: Different ways to cook a crab: GandCrab Ransomware-as-a-Service (RaaS) analysed in depth

Posted by   Martijn Grooten on   Nov 21, 2019

Though active for not much longer than a year, GandCrab had been one of the most successful ransomware operations. In a paper presented at VB2019 in London, McAfee researchers John Fokker and Alexandre Mundo looked at the malware code, its evolution and the affiliate scheme behind it. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Domestic Kitten: an Iranian surveillance program

Posted by   Martijn Grooten on   Nov 18, 2019

At VB2019 in London, Check Point researchers Aseel Kayal and Lotem Finkelstein presented a paper detailing an Iranian operation they named 'Domestic Kitten' that used Android apps for targeted surveillance. Today we publish their paper and the video of their presentation.

Read more  

VB2019 video: Discretion in APT: recent APT attack on crypto exchange employees

Posted by   Martijn Grooten on   Nov 18, 2019

At VB2019 in London, LINE's HeungSoo Kang explained how cryptocurrency exchanges had been attacked using Firefox zero-days. Today, we publish the video of his presentation.

Read more  

VB2019 paper: DNS on fire

Posted by   Martijn Grooten on   Nov 7, 2019

In a paper presented at VB2019, Cisco Talos researchers Warren Mercer and Paul Rascagneres looked at two recent attacks against DNS infrastructure: DNSpionage and Sea Turtle. Today we publish their paper and the recording of their presentation.

Read more  

German Dridex spam campaign is unfashionably large

Posted by   Martijn Grooten on   Nov 6, 2019

VB has analysed a malicious spam campaign targeting German-speaking users with obfuscated Excel malware that would likely download Dridex but that mostly stood out through its size.

Read more  

Paper: Dexofuzzy: Android malware similarity clustering method using opcode sequence

Posted by   Martijn Grooten on   Nov 5, 2019

We publish a paper by researchers from ESTsecurity in South Korea, who describe a fuzzy hashing algorithm for clustering Android malware datasets.

Read more  

Emotet continues to bypass many email security products

Posted by   Martijn Grooten on   Nov 4, 2019

Having returned from a summer hiatus, Emotet is back targeting inboxes and, as seen in the VBSpam test lab, doing a better job than most other malicious campaigns at bypassing email security products.

Read more  

VB2019 paper: We need to talk - opening a discussion about ethics in infosec

Posted by   Martijn Grooten on   Nov 1, 2019

Those working in the field of infosec are often faced with ethical dilemmas that are impossible to avoid. Today, we publish a VB2019 paper by Kaspersky researcher Ivan Kwiatkowski looking at ethics in infosec as well as the recording of Ivan's presentation.

Read more  

Stalkerware poses particular challenges to anti-virus products

Posted by   Martijn Grooten on   Oct 31, 2019

Malware used in domestic abuse situations is a growing threat, and the standard way for anti-virus products to handle such malware may not be good enough. But that doesn't mean there isn't an important role for anti-virus to play.

Read more  

Search blog

VB2006 call for papers

The deadline for submitting paper proposals for VB2006 is fast approaching.
The deadline for submitting paper proposals for VB2006 is fast approaching. The deadline for submitting paper proposals for VB2006 is fast approaching. Abstracts of approximately… https://www.virusbulletin.com/blog/2006/02/call-papers/

2006

Latest news from the anti-virus industry provided by independent anti-virus advisors, Virus Bulletin
NewsBitDefender vulnerability disclosedDetails released of overflow issue reported and patched.18 December 2006UK taxman warns of rebate phishMails promising tax refund just… https://www.virusbulletin.com/blog/2006/

CME initiative sets forth

US-CERT will officially unveil its Common Malware Enumeration (CME) initiative this month.
US-CERT will officially unveil its Common Malware Enumeration (CME) initiative this month. The scheme, which will be operated by MITRE, and will work very much like the current… https://www.virusbulletin.com/blog/2005/09/cme-initiative-sets-forth/

A global view

live spam map showing exactly where spam is coming from.
live spam map showing exactly where spam is coming from. Maintainers of cartographic collections may be interested in a new map created by Mailinator, a company that provides… https://www.virusbulletin.com/blog/2005/09/global-view/

Addendum: August 2005 Netware 6.5 Comparative Review

VB regrets that Symantec was not included in NetWare 6.5 comparative review published in the August 2005 issue of Virus Bulletin
VB regrets that Symantec was not included in NetWare 6.5 comparative review published in the August 2005 issue of Virus Bulletin Unfortunately, due to a combination of… https://www.virusbulletin.com/blog/2005/09/addendum-august-2005-netware-6-5-comparative-review/

Latest VGrep

The latest version of the virus name lookup tool - VGrep, is now available.
The latest version of the virus name lookup tool - VGrep, is now available. VGrep is a system produced in an attempt to clear up some of the confusion surrounding the naming of… https://www.virusbulletin.com/blog/2005/09/latest-vgrep/

Czech spammers receive fines

The Czech Office for Personal Data Protection (UOOU) imposes first fines for spamming offences.
The Czech Office for Personal Data Protection (UOOU) imposes first fines for spamming offences. The Czech Office for Personal Data Protection (UOOU) has imposed its first fines for… https://www.virusbulletin.com/blog/2005/09/czech-spammers-receive-fines/

Spam 'hotline' for German users

German email users can now report spam directly to the Federation of German Consumer Organisations (vzbv)
German email users can now report spam directly to the Federation of German Consumer Organisations (vzbv)German email users can now report spam directly to the Federation of German… https://www.virusbulletin.com/blog/2005/09/spam-hotline-german-users/

Symantec snaps up Wholesecurity

Symantec announces plans to purchase privately held behavioural endpoint security solutions provider WholeSecurity Inc.
Symantec announces plans to purchase privately held behavioural endpoint security solutions provider WholeSecurity Inc. WholeSecurity’s behavioural detection technology identifies… https://www.virusbulletin.com/blog/2005/09/symantec-snaps-wholesecurity/

AVIEN virtual conference

Organisers of the AVIEN/AVIEWS virtual conference issue call for papers.
Organisers of the AVIEN/AVIEWS virtual conference issue call for papers. The organisers of the inaugural AVIEN/AVIEWS virtual conference have issued a call for papers. The… https://www.virusbulletin.com/blog/2005/09/avien-virtual-conference/

September

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2005/09/

Trial and retribution

Former AOL employee Jason Smathers sentenced to 15 months imprisonment for selling customers' email details to spammers.
Former AOL employee Jason Smathers sentenced to 15 months imprisonment for selling customers' email details to spammers. Former AOL employee Jason Smathers has been sentenced to 15… https://www.virusbulletin.com/blog/2005/08/trial-and-retribution/

The naming game

CA becomes latest AV firm to join name game with the announcement of its new division
CA becomes latest AV firm to join name game with the announcement of its new division First there was Kaspersky Lab and ICSA Labs, then came along MessageLabs and SophosLabs. Now… https://www.virusbulletin.com/blog/2005/08/naming-game/

More hash woes

For the second year running, research presented at the annual Crypto conference raised concerns over the security of commonly-used hash functions.
For the second year running, research presented at the annual Crypto conference raised concerns over the security of commonly-used hash functions. For the second year running,… https://www.virusbulletin.com/blog/2005/08/more-hash-woes/

Black Hat round-up

Andrew Lee shares his highlights of the Black Hat Briefings USA
Andrew Lee shares his highlights of the Black Hat Briefings USA In the midsummer heat of the Nevada desert, close to two thousand people donned their sunscreen and their coolest… https://www.virusbulletin.com/blog/2005/08/black-hat-round/

AhnLab wins in anti-spyware ruling

Court approves AhnLab's spyware classification
Court approves AhnLab's spyware classification The Southern District Court of Seoul ruled this week that AhnLab's detection and labelling as spyware of the product of software… https://www.virusbulletin.com/blog/2005/08/ahnlab-wins-anti-spyware-ruling/

August

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2005/08/

Sun, sea, sand and scams

310 people arrested in Malaga after an operation involving the FBI, the US Postal Service and the Spanish police.
310 people arrested in Malaga after an operation involving the FBI, the US Postal Service and the Spanish police. Authorities in Malaga, Spain, must be congratulated on a bumper… https://www.virusbulletin.com/blog/2005/07/sun-sea-sand-and-scams/

Spammer reformed?

Scott Richter, aka the 'Spam King', is no longer classed as a spammer according to Spamhaus's authoritative Register of Known Spam Operations (ROKSO)
Scott Richter, aka the 'Spam King', is no longer classed as a spammer according to Spamhaus's authoritative Register of Known Spam Operations (ROKSO) Scott Richter, aka the 'Spam… https://www.virusbulletin.com/blog/2005/07/spammer-reformed/

Hoax alert

New hoax email comes to light after the launch in the UK of a campaign involving personal emergency contact numbers
New hoax email comes to light after the launch in the UK of a campaign involving personal emergency contact numbers It has been a long while since VB reported on any virus hoaxes,… https://www.virusbulletin.com/blog/2005/07/hoax-alert/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.