VB Blog

VB2019 paper: Fantastic Information and Where to Find it: A guidebook to open-source OT reconnaissance

Posted by   Martijn Grooten on   Nov 22, 2019

A VB2019 paper by FireEye researcher Daniel Kapellmann Zafra explained how open source intelligence (OSINT) can be used to learn crucial details of the inner workings of many a system. Today we publish Daniel's paper and the recording of his presentation.

Read more  

VB2019 paper: Different ways to cook a crab: GandCrab Ransomware-as-a-Service (RaaS) analysed in depth

Posted by   Martijn Grooten on   Nov 21, 2019

Though active for not much longer than a year, GandCrab had been one of the most successful ransomware operations. In a paper presented at VB2019 in London, McAfee researchers John Fokker and Alexandre Mundo looked at the malware code, its evolution and the affiliate scheme behind it. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Domestic Kitten: an Iranian surveillance program

Posted by   Martijn Grooten on   Nov 18, 2019

At VB2019 in London, Check Point researchers Aseel Kayal and Lotem Finkelstein presented a paper detailing an Iranian operation they named 'Domestic Kitten' that used Android apps for targeted surveillance. Today we publish their paper and the video of their presentation.

Read more  

VB2019 video: Discretion in APT: recent APT attack on crypto exchange employees

Posted by   Martijn Grooten on   Nov 18, 2019

At VB2019 in London, LINE's HeungSoo Kang explained how cryptocurrency exchanges had been attacked using Firefox zero-days. Today, we publish the video of his presentation.

Read more  

VB2019 paper: DNS on fire

Posted by   Martijn Grooten on   Nov 7, 2019

In a paper presented at VB2019, Cisco Talos researchers Warren Mercer and Paul Rascagneres looked at two recent attacks against DNS infrastructure: DNSpionage and Sea Turtle. Today we publish their paper and the recording of their presentation.

Read more  

German Dridex spam campaign is unfashionably large

Posted by   Martijn Grooten on   Nov 6, 2019

VB has analysed a malicious spam campaign targeting German-speaking users with obfuscated Excel malware that would likely download Dridex but that mostly stood out through its size.

Read more  

Paper: Dexofuzzy: Android malware similarity clustering method using opcode sequence

Posted by   Martijn Grooten on   Nov 5, 2019

We publish a paper by researchers from ESTsecurity in South Korea, who describe a fuzzy hashing algorithm for clustering Android malware datasets.

Read more  

Emotet continues to bypass many email security products

Posted by   Martijn Grooten on   Nov 4, 2019

Having returned from a summer hiatus, Emotet is back targeting inboxes and, as seen in the VBSpam test lab, doing a better job than most other malicious campaigns at bypassing email security products.

Read more  

VB2019 paper: We need to talk - opening a discussion about ethics in infosec

Posted by   Martijn Grooten on   Nov 1, 2019

Those working in the field of infosec are often faced with ethical dilemmas that are impossible to avoid. Today, we publish a VB2019 paper by Kaspersky researcher Ivan Kwiatkowski looking at ethics in infosec as well as the recording of Ivan's presentation.

Read more  

Stalkerware poses particular challenges to anti-virus products

Posted by   Martijn Grooten on   Oct 31, 2019

Malware used in domestic abuse situations is a growing threat, and the standard way for anti-virus products to handle such malware may not be good enough. But that doesn't mean there isn't an important role for anti-virus to play.

Read more  

Search blog

2003

Latest news from the anti-virus industry provided by independent anti-virus advisors, Virus Bulletin
NewsUS and UK spam legislation in place Anti-spam legislation in place. 29 December 2003Number crunchingCalculating the average cost of a virus attack - estimates or guesstimates?… https://www.virusbulletin.com/blog/2003/

January

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/01/

Stocks, viruses and a disgruntled employee

A systems administrator has been charged with attempting to manipulate a company's stock price by introducing a virus into its computer system.
A systems administrator has been charged with attempting to manipulate a company's stock price by introducing a virus into its computer system. The New York Times reports that a… https://www.virusbulletin.com/blog/2002/12/stocks-viruses-and-disgruntled-employee/

Stocking Fillers

It's that time of year again when we're frantically scouring the shopping malls for something unique and meaningful to give to our loved ones. Coincidentally, it's also that time of year when VB turns out its stock cupboards and puts some truly fabulous m…
It's that time of year again when we're frantically scouring the shopping malls for something unique and meaningful to give to our loved ones. Coincidentally, it's also that time… https://www.virusbulletin.com/blog/2002/12/stocking-fillers/

December

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/12/

Addendum: Windows 2000 Advanced Server Comparative Review

After re-testing, Trend's ServerProtect product gains a VB 100% award.
After re-testing, Trend's ServerProtect product gains a VB 100% award. In the November 2002 Comparative Review Trend's ServerProtect was reported to have failed to achieve full… https://www.virusbulletin.com/blog/2002/12/addendum-windows-2000-advanced-server-comparative-review/

Some thoughts on ViraLock

We examine ViraLock, a product which promises 'Zero Escape For Email Viruses', provided, it seems, the virus plays by their rules.
We examine ViraLock, a product which promises 'Zero Escape For Email Viruses', provided, it seems, the virus plays by their rules. It's understandable that we greet announcements… https://www.virusbulletin.com/blog/2002/11/some-thoughts-viralock/

Who's There?

New security portal unveiled by publishers of Information Security Bulletin magazine.
New security portal unveiled by publishers of Information Security Bulletin magazine. Last month a new security portal was unveiled by the publishers of Information Security… https://www.virusbulletin.com/blog/2002/11/who-s-there/

Paying the Price

McAfee Security issues press release estimating the potential costs to businesses of 'the next big virus attack'
McAfee Security issues press release estimating the potential costs to businesses of 'the next big virus attack' McAfee Security has become the latest security company to issue a… https://www.virusbulletin.com/blog/2002/11/paying-price/

Writer of virus trio in court

A British man has appeared in court charged with the creation and distribution of a trio of mass-mailing viruses: Gokar, Redesi and Admirer.
A British man has appeared in court charged with the creation and distribution of a trio of mass-mailing viruses: Gokar, Redesi and Admirer. A British man has appeared in court… https://www.virusbulletin.com/blog/2002/11/writer-virus-trio-court/

November

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/11/

'Kournikova' writer loses appeal

Reports are that Jan de Wit, author of the 'Kournikova' virus (VBSWG variant) has lost his appeal against 150 hours of community service.
Reports are that Jan de Wit, author of the 'Kournikova' virus (VBSWG variant) has lost his appeal against 150 hours of community service. The Register reports that Jan de Wit,… https://www.virusbulletin.com/blog/2002/10/kournikova-writer-loses-appeal/

With friends like these...

A nuisance email which is neither viral nor a hoax is proving to be equally bothersome.
A nuisance email which is neither viral nor a hoax is proving to be equally bothersome. A nuisance email which is neither viral nor a hoax is proving to be equally bothersome.… https://www.virusbulletin.com/blog/2002/10/friends-these/

Addendum: June 2002 Windows XP Comparative Review

F-Prot users relying on the on-access protection against W32/Nimda.A are safe
F-Prot users relying on the on-access protection against W32/Nimda.A are safe In the June 2002 comparative review of anti-virus products for Windows XP (see VB, June 2002, p.19),… https://www.virusbulletin.com/blog/2002/10/addendum-june-2002-windows-xp-comparative-review/

Moth-eaten software...

A warning issued by Israeli security firm GreyMagic Software last month revealed a total of nine vulnerabilities in IE 5.5 and 6.0, all concerning object caching.
A warning issued by Israeli security firm GreyMagic Software last month revealed a total of nine vulnerabilities in IE 5.5 and 6.0, all concerning object caching. A warning… https://www.virusbulletin.com/blog/2002/10/moth-eaten-software/

Service or bust

So confident is Trend Micro of its virus detection abilities that it is offering a financial penalty-backed detection guarantee.
So confident is Trend Micro of its virus detection abilities that it is offering a financial penalty-backed detection guarantee. So confident is Trend Micro of its virus detection… https://www.virusbulletin.com/blog/2002/10/service-or-bust/

October

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/10/

Viruses - Some Good

Just occasionally, a virus infection can have some positive effects...
Just occasionally, a virus infection can have some positive effects... Much like biological viruses, it turns out that infections by computer viruses can lead to increased measures… https://www.virusbulletin.com/blog/2002/09/viruses-some-good/

Bring on the DEET

The latest award for the most tenuous product-pushing story goes to BitDefender, whose marketeers claim a 'mosquito-borne disease could easily become a computer infection.'
The latest award for the most tenuous product-pushing story goes to BitDefender, whose marketeers claim a 'mosquito-borne disease could easily become a computer infection.' The… https://www.virusbulletin.com/blog/2002/09/bring-deet/

Virtually There

The Infosecurity show and exhibition has gone virtual with the launch of the first Infosecurity World Online exhibition. But where are the sweets?
The Infosecurity show and exhibition has gone virtual with the launch of the first Infosecurity World Online exhibition. But where are the sweets? The Infosecurity show and… https://www.virusbulletin.com/blog/2002/09/virtually-there/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.