VB Blog

VB2019 paper: Defeating APT10 compiler-level obfuscations

Posted by   Virus Bulletin on   Mar 13, 2020

At VB2019 in London, Carbon Black researcher Takahiro Haruyama presented a paper on defeating compiler-level obfuscations used by the APT10 group. Today we publish both Takahiro's paper and the recording of his presentation.

Read more  

VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers

Posted by   Virus Bulletin on   Mar 12, 2020

At VB2019 in London Michael Raggi (Proofpoint) and Ghareeb Saad (Anomali) presented a paper on the 'Royal Road' exploit builder (or weaponizer) and how the properties of RTF files can be used to track weaponizers and their users. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 presentation: Nexus between OT and IT threat intelligence

Posted by   Virus Bulletin on   Mar 11, 2020

Operational technology, the mission critical IT in ICS, shares many similarities with traditional IT systems, but also some crucial differences. During the Threat Intelligence Practitioners’ Summit at VB2019, Dragos cyber threat intelligence analyst Selena Larson gave a keynote on these similarities and differences. Today we release the recording of her presentation.

Read more  

VB2019 paper: Kimsuky group: tracking the king of the spear-phishing

Posted by   Virus Bulletin on   Mar 10, 2020

In a paper presented at VB2019 in London, researchers fron the Financial Security Institute detailed the tools and activities used by the APT group 'Kimsuky', some of which they were able to analyse through OpSec failures by the group. Today, we publish their paper.

Read more  

VB2019 paper: Play fuzzing machine - hunting iOS and macOS kernel vulnerabilities automatically and smartly

Posted by   Virus Bulletin on   Mar 9, 2020

In a paper presented at VB2019 in London, Trend Micro researchers Lilang Wu and Moony Li explained how the hunt for vulnerabilities in MacOS and iOS operating systems can be made both smarter and more automatic. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Finding drive-by rookies using an automated active observation platform

Posted by   Virus Bulletin on   Mar 6, 2020

In a last-minute paper presented at VB2019 in London, Rintaro Koike (NTT Security) and Yosuke Chubachi (Active Defense Institute, Ltd) discussed the platform they have built to automatically detect and analyse exploit kits. Today we publish the recording of their presentation.

Read more  

VB2019 paper: Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation state adversary

Posted by   Virus Bulletin on   Feb 28, 2020

The activities of China-based threat actor PKPLUG were detailed in a VB2019 paper by Palo Alto Networks researcher Alex Hinchliffe, who described the playbook of this long-standing adversary. Today we publish both Alex's paper and the recording of his presentation.

Read more  

VB2019 paper: Static analysis methods for detection of Microsoft Office exploits

Posted by   Virus Bulletin on   Feb 25, 2020

Today we publish the VB2019 paper and presentation by McAfee researcher Chintan Shah in which he described static analysis methods for the detection of Microsoft Office exploits.

Read more  

New paper: LokiBot: dissecting the C&C panel deployments

Posted by   Helen Martin on   Feb 17, 2020

First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the URL structure of the LokiBot C&C panels and how they have evolved over time.

Read more  

VB2019 presentation: Building secure sharing systems that treat humans as features not bugs

Posted by   Helen Martin on   Feb 14, 2020

In a presentation at VB2019 in London, Virtru's Andrea Limbago described how, by exploring data sharing challenges through a socio-technical lens, it is possible to make significant gains toward the secure sharing systems and processes that are vital for innovation and collaboration. Today we release the recording of her presentation.

Read more  

Search blog

UN to curb spam within two years

UN aims to bring spam under control by 2007.
UN aims to bring spam under control by 2007. Representatives of the United Nation's International Telecommunications Union (ITU) meeting in Geneva this week as part of the World… https://www.virusbulletin.com/blog/2004/07/un-curb-spam-within-two-years/

International pact to fight spam

Countries join forces to declare war on spam.
Countries join forces to declare war on spam. Representatives from the US, the UK and Australia have signed a 'Memorandum of Understanding' (MoU) on spam. The agreement was… https://www.virusbulletin.com/blog/2004/07/international-pact-fight-spam/

Magold teen on probation

Hungarian virus writer convicted.
Hungarian virus writer convicted. A Hungarian teenager has been sentenced to two years' probation for creating the Magold virus. Earlier this week the Veszprem City Court… https://www.virusbulletin.com/blog/2004/07/magold-teen-probation/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/07/

Patent filed for voice spam blocking technology

Technology to stamp out Internet telephony spam.
Technology to stamp out Internet telephony spam. A patent application has been filed for a method to identify and block SPIT - spam over Internet telephony, or VoIP spam. SPIT, or… https://www.virusbulletin.com/blog/2004/06/patent-filed-voice-spam-blocking-technology/

SMS spammer arrested

First Russian to be sentenced for sending spam.
First Russian to be sentenced for sending spam. Russian student Dmitry Anosov made history last month when he became the first Russian to be sentenced for sending spam - even… https://www.virusbulletin.com/blog/2004/06/sms-spammer-arrested/

7 steps to a spam-free existence?

Anti-virus and security related articles provided by independent anti-virus advisors, Virus Bulletin
"Stunning" survey results lead to seven-step guide. Email security firm Vircom has issued a seven-step guide to avoiding spam, after its six-month study revealed (shock, horror)… https://www.virusbulletin.com/blog/2004/06/7-steps-spam-free-existence/

Gates urges users to turn on auto-update

Microsoft chief says users must play their part in cutting down virus combat time.
Microsoft chief says users must play their part in cutting down virus combat time. Microsoft chief Bill Gates has pledged that the time taken for Microsoft to patch… https://www.virusbulletin.com/blog/2004/06/gates-urges-users-turn-auto-update/

Microsoft issues advice about critical vulnerability

Apply your patches and update your AV software.
Apply your patches and update your AV software. Microsoft has issued advice on what you should know about Download.Ject The Trojan downloader, also known as JS/Scob.A and Toofer,… https://www.virusbulletin.com/blog/2004/06/microsoft-issues-advice-about-critical-vulnerability/

AOL victim of inside spam job

AOL employee arrested.
AOL employee arrested. An AOL employee has been arrested and charged with selling the company's customer email list to spammers. 24-year-old AOL engineer Jason Smathers is accused… https://www.virusbulletin.com/blog/2004/06/aol-victim-inside-spam-job/

ISPs take responsibility

The six major ISPs of the Anti-Spam Technical Alliance say spam cannot be stopped unless they take action.
The six major ISPs of the Anti-Spam Technical Alliance say spam cannot be stopped unless they take action. Six major Internet Service Providers have put forward a joint proposal… https://www.virusbulletin.com/blog/2004/06/isps-take-responsibility/

Microsoft to buy NAI?

Rumours abound. NAI CEO denies them.
Rumours abound. NAI CEO denies them. Tech news website CRN reports that AV vendor Network Associates is up for sale, and that Microsoft is the likely lucky new owner. Although no… https://www.virusbulletin.com/blog/2004/06/microsoft-buy-nai/

Obituary: Marek Sell

On 12 June 2004 Marek Sell, creator of the Polish MkS_Vir anti-virus, died. Aleksander Czarnowksi looks back.
On 12 June 2004 Marek Sell, creator of the Polish MkS_Vir anti-virus, died. Aleksander Czarnowksi looks back. I met Marek somewhere around 1990, two years after he released the… https://www.virusbulletin.com/blog/2004/06/obituary-marek-sell/

AV going mobile

Mobile providers clamour to become the first to offer AV protection for mobile phones.
Mobile providers clamour to become the first to offer AV protection for mobile phones. Following the appearance of SymbOS/Cabir.A, the first virus capable of spreading via mobile… https://www.virusbulletin.com/blog/2004/06/av-going-mobile/

Sasser author jobseeking

Gis' a job! Name: Sven Jaschan. Age: 18. Previous work experience: creating and distributing Internet worm(s).
Gis' a job! Name: Sven Jaschan. Age: 18. Previous work experience: creating and distributing Internet worm(s). The lawyer representing Sven Jaschan, self-confessed author of the… https://www.virusbulletin.com/blog/2004/06/sasser-author-jobseeking/

Microsoft AV still on track

Not forgotten...
Not forgotten... Microsoft is still on track to offer its own anti-virus product, according to the chief of its security business unit. It has been a year since Microsoft… https://www.virusbulletin.com/blog/2004/06/microsoft-av-still-track/

FTC says no to 'Do Not Spam'

A 'Do Not Spam' list could actually increase spam levels, says FTC.
A 'Do Not Spam' list could actually increase spam levels, says FTC. The Federal Trade Commission (FTC) has told Congress that a national 'Do Not Spam' registry is not appropriate… https://www.virusbulletin.com/blog/2004/06/ftc-says-no-do-not-spam/

Virus calling

First mobile phone worm discovered.
First mobile phone worm discovered. The first worm to be capable of spreading via mobile phones has been discovered. The initial announcement of the proof-of-concept worm was… https://www.virusbulletin.com/blog/2004/06/virus-calling/

More spammers sued

Microsoft throws its weight around against spammers
Microsoft throws its weight around against spammers Microsoft has filed eight new lawsuits against spammers. All of the suits allege spoofing and falsifying of domain names.… https://www.virusbulletin.com/blog/2004/06/more-spammers-sued/

Virus cost MOD £10 million

Ministry of Defence reveals Lovgate found a weakness in its defences
Ministry of Defence reveals Lovgate found a weakness in its defences According to Computer Weekly the UK's Ministry of Defence (MOD) has revealed that, last year, it spent £10m on… https://www.virusbulletin.com/blog/2004/06/virus-cost-mod-10-million/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.