VB Blog

VB2019 paper: Defeating APT10 compiler-level obfuscations

Posted by   Virus Bulletin on   Mar 13, 2020

At VB2019 in London, Carbon Black researcher Takahiro Haruyama presented a paper on defeating compiler-level obfuscations used by the APT10 group. Today we publish both Takahiro's paper and the recording of his presentation.

Read more  

VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers

Posted by   Virus Bulletin on   Mar 12, 2020

At VB2019 in London Michael Raggi (Proofpoint) and Ghareeb Saad (Anomali) presented a paper on the 'Royal Road' exploit builder (or weaponizer) and how the properties of RTF files can be used to track weaponizers and their users. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 presentation: Nexus between OT and IT threat intelligence

Posted by   Virus Bulletin on   Mar 11, 2020

Operational technology, the mission critical IT in ICS, shares many similarities with traditional IT systems, but also some crucial differences. During the Threat Intelligence Practitioners’ Summit at VB2019, Dragos cyber threat intelligence analyst Selena Larson gave a keynote on these similarities and differences. Today we release the recording of her presentation.

Read more  

VB2019 paper: Kimsuky group: tracking the king of the spear-phishing

Posted by   Virus Bulletin on   Mar 10, 2020

In a paper presented at VB2019 in London, researchers fron the Financial Security Institute detailed the tools and activities used by the APT group 'Kimsuky', some of which they were able to analyse through OpSec failures by the group. Today, we publish their paper.

Read more  

VB2019 paper: Play fuzzing machine - hunting iOS and macOS kernel vulnerabilities automatically and smartly

Posted by   Virus Bulletin on   Mar 9, 2020

In a paper presented at VB2019 in London, Trend Micro researchers Lilang Wu and Moony Li explained how the hunt for vulnerabilities in MacOS and iOS operating systems can be made both smarter and more automatic. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Finding drive-by rookies using an automated active observation platform

Posted by   Virus Bulletin on   Mar 6, 2020

In a last-minute paper presented at VB2019 in London, Rintaro Koike (NTT Security) and Yosuke Chubachi (Active Defense Institute, Ltd) discussed the platform they have built to automatically detect and analyse exploit kits. Today we publish the recording of their presentation.

Read more  

VB2019 paper: Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation state adversary

Posted by   Virus Bulletin on   Feb 28, 2020

The activities of China-based threat actor PKPLUG were detailed in a VB2019 paper by Palo Alto Networks researcher Alex Hinchliffe, who described the playbook of this long-standing adversary. Today we publish both Alex's paper and the recording of his presentation.

Read more  

VB2019 paper: Static analysis methods for detection of Microsoft Office exploits

Posted by   Virus Bulletin on   Feb 25, 2020

Today we publish the VB2019 paper and presentation by McAfee researcher Chintan Shah in which he described static analysis methods for the detection of Microsoft Office exploits.

Read more  

New paper: LokiBot: dissecting the C&C panel deployments

Posted by   Helen Martin on   Feb 17, 2020

First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the URL structure of the LokiBot C&C panels and how they have evolved over time.

Read more  

VB2019 presentation: Building secure sharing systems that treat humans as features not bugs

Posted by   Helen Martin on   Feb 14, 2020

In a presentation at VB2019 in London, Virtru's Andrea Limbago described how, by exploring data sharing challenges through a socio-technical lens, it is possible to make significant gains toward the secure sharing systems and processes that are vital for innovation and collaboration. Today we release the recording of her presentation.

Read more  

Search blog

Save your soul with spam

Spam goes yet one step further - spiritual salvation!
Spam goes yet one step further - spiritual salvation! We are all accustomed to receiving spam that advertises herbal medicines, designer watches, new mortgages and online degrees… https://www.virusbulletin.com/blog/2004/12/save-your-soul-spam/

Season's greetings

The VB team wishes all Virus Bulletin readers a very happy Christmas and a prosperous new year.
The VB team wishes all Virus Bulletin readers a very happy Christmas and a prosperous new year. The VB team wishes all Virus Bulletin readers a very happy Christmas and a… https://www.virusbulletin.com/blog/2004/12/season-s-greetings/

Email authentication in the open

35 high-profile organisations sign open letter, calling for a rapid rollout of email authentication technologies
35 high-profile organisations sign open letter, calling for a rapid rollout of email authentication technologies Last month an open letter was sent to members of the US Federal… https://www.virusbulletin.com/blog/2004/12/email-authentication-open/

December

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/12/

Spam-reporting trial

Australia's latest anti-spam initiative
Australia's latest anti-spam initiative The Australian Communications Authority (ACA) is teaming up with Internet Service Provider Pacific Internet and software company… https://www.virusbulletin.com/blog/2004/12/spam-reporting-trial/

Australia to protect critical computer systems

Vulnerability assessment for country's critical infrastructure systems
Vulnerability assessment for country's critical infrastructure systems The Australian government is to spend more than 8 million dollars on a project that will identify and fix… https://www.virusbulletin.com/blog/2004/11/australia-protect-critical-computer-systems/

Lycos turns hippy on spam

'Make love not spam'
'Make love not spam' Lycos Europe has come up with an interesting new way for its users to feel they are getting their own back on spammers. Lycos is encouraging its users to… https://www.virusbulletin.com/blog/2004/11/lycos-turns-hippy-spam/

Spam survey

Do women hate spam more than men? Are humans better at identifying spam than computers? Make your contribution to (anti-)spam research...
Do women hate spam more than men? Are humans better at identifying spam than computers? Make your contribution to (anti-)spam research... John Graham-Cumming, author of POPFile… https://www.virusbulletin.com/blog/2004/11/spam-survey/

Standardised malware naming for the new year

An end to the virus-naming problem?
An end to the virus-naming problem? A new initiative that aims to standardise malware naming may be in operation as early as January 2005. The US Department of Homeland… https://www.virusbulletin.com/blog/2004/11/standardised-malware-naming-new-year/

Most spammed

Think you've got it bad? Spare a thought for Bill.
Think you've got it bad? Spare a thought for Bill. Microsoft Chairman Bill Gates is the world's most spammed email recipient. The (let's face it, not entirely surprising) fact… https://www.virusbulletin.com/blog/2004/11/most-spammed/

29A virus writer sentenced

Member of notorious virus-writing group found guilty.
Member of notorious virus-writing group found guilty. A Russian virus writer has been found guilty of creating viruses and fined the somewhat paltry sum of 3,000 roubles. Eugene… https://www.virusbulletin.com/blog/2004/11/29a-virus-writer-sentenced/

Latest VGrep

The latest version of the virus name lookup tool - VGrep, is now available.
The latest version of the virus name lookup tool - VGrep, is now available. VGrep is a system produced in an attempt to clear up some of the confusion surrounding the naming of… https://www.virusbulletin.com/blog/2004/11/latest-vgrep/

November

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/11/

Spam becomes a collectors' item

British man sets up his own Museum of Spam.
British man sets up his own Museum of Spam. Just in case you hadn't already seen enough spam in your inbox, or in case your spam filter is so efficient that you find yourself… https://www.virusbulletin.com/blog/2004/10/spam-becomes-collectors-item/

November issue released

The Virus Bulletin November issue is on its way.
The Virus Bulletin November issue is on its way. It's that time of the month again... If you are a subscriber to Virus Bulletin, you should be receiving your November issue… https://www.virusbulletin.com/blog/2004/10/november-issue-released/

Dial a detection

Guidance issued on how to deal with rogue Internet diallers ('porn diallers')
Guidance issued on how to deal with rogue Internet diallers ('porn diallers') UK telecoms watchdog the Independent Committee for the Supervision of Standards of Telephone… https://www.virusbulletin.com/blog/2004/10/dial-detection/

Phishy goings on

Fewer than five zombie network operators are responsible for all Internet phishing attacks worldwide according to CipherTrust...
Fewer than five zombie network operators are responsible for all Internet phishing attacks worldwide according to CipherTrust... According to Commtouch Software the US, UK,… https://www.virusbulletin.com/blog/2004/10/phishy-goings/

Storms put the wind up spammers

Significant decline in the volume of spam messages seen in the days immediately following the three recent hurricanes.
Significant decline in the volume of spam messages seen in the days immediately following the three recent hurricanes. Email security firm FrontBridge Technologies Inc. reported… https://www.virusbulletin.com/blog/2004/10/storms-put-wind-spammers/

Spam gets the sniffles

Spammers seize the opportunity to cash in on the US flu vaccine problem.
Spammers seize the opportunity to cash in on the US flu vaccine problem. Not only has the shortage of flu vaccine been something of a political hot potato in the run up to the US… https://www.virusbulletin.com/blog/2004/10/spam-gets-sniffles/

Sender ID specification revised

Microsoft has another stab at getting its email authentication protocol approved.
Microsoft has another stab at getting its email authentication protocol approved. Microsoft has revised its Sender ID email authentication protocol and resubmitted it to the… https://www.virusbulletin.com/blog/2004/10/sender-id-specification-revised/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.