VB Blog

VB2017 video: Turning Trickbot: decoding an encrypted command-and-control channel

Posted by   Martijn Grooten on   Nov 3, 2017

Trickbot, a banking trojan which appeared this year, seems to be a new, more modular, and more extensible malware descendant of the notorious Dyre botnet trojan. At VB2017, Symantec researcher Andrew Brandt presented a walkthrough of a typical Trickbot infection process, and its aftermath, as seen through the lens of a tool used to perform man-in-the-middle decryption. Today, we publish both Andrew's slides and the recording of his presentation.

Read more  

Paper: FAME - Friendly Malware Analysis Framework

Posted by   Martijn Grooten on   Nov 2, 2017

Today, we publish a short paper in which CERT Société Générale presents FAME, its open source malware analysis framework.

Read more  

Ebury and Mayhem server malware families still active

Posted by   Martijn Grooten on   Oct 31, 2017

Ebury and Mayhem, two families of Linux server malware, about which VB published papers back in 2014, are still active and have received recent updates.

Read more  

VB2017 paper: Crypton - exposing malware's deepest secrets

Posted by   Martijn Grooten on   Oct 27, 2017

Crypton, a tool developed by F5 Networks researchers Julia Karpin and Anna Dorfman, aims to speed up the reverse engineering process by decrypting encrypted content found in a (malicious) binary. The researchers described the tool in a paper which they presented at VB2017 in Madrid. Today, we publish both the paper and the recording of their presentation.

Read more  

VB2017 paper: The sprawling market of consumer spyware

Posted by   Martijn Grooten on   Oct 25, 2017

For many people, the threat of an abusive partner or ex-partner is very real - and the market for consumer spyware worryingly large. Today, we publish the recording of a presentation on the subject of consumer spyware given at VB2017 by The Daily Beast reporter Joseph Cox.

Read more  

Gábor Szappanos wins fourth Péter Szőr Award

Posted by   Martijn Grooten on   Oct 23, 2017

At the VB2017 gala dinner, the fourth Péter Szőr Award was presented to Sophos researcher Gábor Szappanos for his paper "AKBuilder – the crowdsourced exploit kit".

Read more  

VB2017 paper: Walking in your enemy's shadow: when fourth-party collection becomes attribution hell

Posted by   Martijn Grooten on   Oct 20, 2017

We publish the VB2017 paper and video by Kaspersky Lab researchers Juan Andres Guerrero-Saade and Costin Raiu, in which they look at fourth-party collection (spies spying on other spies' campaigns) and its implications for attribution.

Read more  

Didn't come to VB2017? Tell us why!

Posted by   Martijn Grooten on   Oct 11, 2017

Virus Bulletin is a company - and a conference - with a mission: to further the research in and facilitate the fight against digital threats. To help us in this mission, we want to hear from those who didn't come to Madrid. What is your impression of the VB Conference? What did you think of this year's programme? And why couldn't you come to Madrid?

Read more  

Montreal will host VB2018

Posted by   Martijn Grooten on   Oct 10, 2017

Last week, we announced the full details of VB2018, which will take place 3-5 October 2018 at the Fairmont The Queen Elizabeth hotel in Montreal, Quebec, Canada.

Read more  

VB2017 preview: Beyond lexical and PDNS (guest blog)

Posted by   Virus Bulletin on   Oct 5, 2017

In a special guest blog post, VB2017 Silver sponsor Cisco Umbrella writes about a paper that researchers Dhia Mahjoub and David Rodriguez will present at the conference this Friday.

Read more  

Search blog

New VB Spam Supplement

VB plans to present a selection of news and articles on spam and anti-spam techniques - some technical, some ethical, some relating to real-world experiences of dealing with spam.
VB plans to present a selection of news and articles on spam and anti-spam techniques - some technical, some ethical, some relating to real-world experiences of dealing with spam.… https://www.virusbulletin.com/blog/2003/11/new-vb-spam-supplement/

November

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/11/

Totally Toronto: VB2003

Helen Martin recounts the Virus Bulletin conference.
Helen Martin recounts the Virus Bulletin conference. full article Posted on 30 October 2003 by Virus Bulletin https://www.virusbulletin.com/blog/2003/10/totally-toronto/

Linux vs. Windows viruses: a rebuttal

Pete Sergeant responds to an article by a SecurityFocus columnist, which hints that Linux users really don't need to worry about viruses.
Pete Sergeant responds to an article by a SecurityFocus columnist, which hints that Linux users really don't need to worry about viruses. Regarding Linux vs. Windows Viruses:… https://www.virusbulletin.com/blog/2003/10/linux-vs-windows-viruses-rebuttal/

October

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/10/

Four arrests and a congressional hearing

US Congress starts to take computer security seriously, four alleged malware writers arrested...
US Congress starts to take computer security seriously, four alleged malware writers arrested... A US Congressional hearing was held last month to discuss the current state of… https://www.virusbulletin.com/blog/2003/09/four-arrests-and-congressional-hearing/

September

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/09/

Youth faces arrest for Blaster variant

Teenager suspected of creating Blaster variant faces arrest.
Teenager suspected of creating Blaster variant faces arrest. An 18-year-old suspected of creating a variant of the Blaster worm is reported to be facing arrest today. The… https://www.virusbulletin.com/blog/2003/08/youth-faces-arrest-blaster-variant/

Watching and waiting for Sobig

On 22 August 2003 anti-virus experts and sysadmins worldwide waited to discover what events, if any, would unfold when Sobig.F began a synchronized attack.
On 22 August 2003 anti-virus experts and sysadmins worldwide waited to discover what events, if any, would unfold when Sobig.F began a synchronized attack. Anti-virus experts and… https://www.virusbulletin.com/blog/2003/08/watching-and-waiting-sobig/

Symantec acquires Hilgraeve patent

Symantec pays $62.5m for a software patent, considers litigation against infringing competitors.
Symantec pays $62.5m for a software patent, considers litigation against infringing competitors. Symantec announced yesterday it had paid $62.5m for the infamous US Patent No.… https://www.virusbulletin.com/blog/2003/08/symantec-acquires-hilgraeve-patent/

August

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/08/

No more Mr Nice Guy: UK gets tough on hi-tech criminals

Welsh virus-writer shown justice, not mercy
Welsh virus-writer shown justice, not mercy London’s Court of Appeal has turned down Welsh virus writer Simon Vallor’s appeal to shorten his two-year custodial sentence. Vallor,… https://www.virusbulletin.com/blog/2003/08/no-more-mr-nice-guy-uk-gets-tough-hi-tech-criminals/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/07/

Canadian retreat

Ontario plays host to VB2003 and NTBugtraq Retreat.
Ontario plays host to VB2003 and NTBugtraq Retreat. This year's Virus Bulletin conference programme covers a wide range of subjects - from the detailed analysis of emerging… https://www.virusbulletin.com/blog/2003/07/canadian-retreat/

The big wait

Will Microsoft's second attempt at entering the anti-virus field result in the 'vast shake-up' of the AV industry that was expected last time?
Will Microsoft's second attempt at entering the anti-virus field result in the 'vast shake-up' of the AV industry that was expected last time? The big news in June was the… https://www.virusbulletin.com/blog/2003/07/big-wait/

School without thought - your thoughts

Your thoughts on the University of Calgary's proposals to teach virus writing in its course on computer viruses and malware.
Your thoughts on the University of Calgary's proposals to teach virus writing in its course on computer viruses and malware.Recently VB reported on the University of Calgary's… https://www.virusbulletin.com/blog/2003/06/school-without-thought-your-thoughts/

Microsoft buys into AV

Microsoft announces acquisition of anti-virus technology.
Microsoft announces acquisition of anti-virus technology.Microsoft has announced the acquisition of anti-virus technology from Romanian AV manufacturer GeCAD Software.The… https://www.virusbulletin.com/blog/2003/06/microsoft-buys-av/

June

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/06/

School without thought

University course teaches students to write malware.
University course teaches students to write malware. The University of Calgary has announced very proudly on its website that a new undergraduate course will 'focus on developing… https://www.virusbulletin.com/blog/2003/06/school-without-thought/

Military intelligence

US Army gets serious about anti-virus.
US Army gets serious about anti-virus. The US Army is using products supplied by Trend Micro to protect users of its Army Knowledge Online service from viruses, malicious content… https://www.virusbulletin.com/blog/2003/04/military-intelligence/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.