VB Blog

VB2018 paper: Fake News, Inc.

Posted by   Helen Martin on   Apr 25, 2019

A former reporter by profession, Andrew Brandt's curiosity was piqued when he came across what appeared at first glance to be the website of a small-town newspaper based in Illinois, but under scrutiny, things didn’t add up. At VB2018 he presented a paper in which he shared the results of his investigation of the site. Today, we publish his paper and the recording of his presentation.

Read more  

Paper: Alternative communication channel over NTP

Posted by   Martijn Grooten on   Apr 24, 2019

In a new paper published today, independent researcher Nikolaos Tsapakis writes about the possibilities of malware using NTP as a covert communication channel and how to stop this.

Read more  

VB2019 conference programme announced

Posted by   Martijn Grooten on   Apr 5, 2019

VB is excited to reveal the details of an interesting and diverse programme for VB2019, the 29th Virus Bulletin International Conference, which takes place 2-4 October in London, UK.

Read more  

VB2018 paper: Under the hood - the automotive challenge

Posted by   Martijn Grooten on   Mar 27, 2019

Car hacking has become a hot subject in recent years, and at VB2018 in Montreal, Argus Cyber Security's Inbar Raz presented a paper that provides an introduction to the subject, looking at the complex problem, examples of car hacks, and the challenges ahead. Today, we publish both Inbar's paper and the recording of his presentation.

Read more  

VB2018 paper and video: Android app deobfuscation using static-dynamic cooperation

Posted by   Martijn Grooten on   Mar 20, 2019

Static analysis and dynamic analysis each have their shortcomings as methods for analysing potentially malicious files. Today, we publish a VB2018 paper by Check Point researchers Yoni Moses and Yaniv Mordekhay, in which they describe a method that combines static and dynamic analysis to defeat app obfuscation in Android binaries. We also publish the video of their presentation.

Read more  

VB2019 call for papers closes this weekend

Posted by   Martijn Grooten on   Mar 15, 2019

The call for papers for VB2019 closes on 17 March, and while we've already received many great submissions, we still want more!

Read more  

Registration open for VB2019 ─ book your ticket now!

Posted by   Martijn Grooten on   Mar 13, 2019

Registration for VB2019, the 29th Virus Bulletin International Conference, is now open, with an early bird rate available until 1 July.

Read more  

The VB2019 call for papers is about ... papers

Posted by   Martijn Grooten on   Mar 8, 2019

When we are calling for papers for the Virus Bulletin conference as we are doing now, we really mean a written paper. But don't worry if you've never written a paper - we can help!

Read more  

VB2018 video: Adware is just malware with a legal department - how we reverse engineered OSX/Pirrit, received legal threats, and survived

Posted by   Martijn Grooten on   Mar 8, 2019

Amit Serper first analysed the OSX/Pirrit adware in 2016, highlighting some of its malware-like techniques, and soon afterwards started receiving legal threats from the company behind it. At VB2018 Amit gave a presentation in which he discussed both the adware and the legal threats he received for calling it malware. Today, we publish the video of Amit's presentation.

Read more  

VB2018 paper: Anatomy of an attack: detecting and defeating CRASHOVERRIDE

Posted by   Martijn Grooten on   Mar 5, 2019

In December 2016, the CRASHOVERRIDE malware framework was used to cause a blackout in Ukraine. At VB2018 in Montreal, Dragos researcher Joe Slowik presented a detailed paper on the framework, explaining how the malware works and how it targets various protocols used to operate the electric grid. Today we publish both Joe's paper and the recording of his presentation.

Read more  

Search blog

OneCare labels Gmail a virus

Rival webmail system flagged infected by Microsoft AV.
Rival webmail system flagged infected by Microsoft AV. A number of users of Microsoft's anti-virus product Windows Live OneCare have reported being warned of a virus infection when… https://www.virusbulletin.com/blog/2006/11/onecare-labels-gmail-virus/

Vista safe without AV, says Allchin

Microsoft chief confident in new security measures.
Microsoft chief confident in new security measures. During a telephone press conference, Microsoft Platform Products and Services Co-president Jim Allchin revealed that he lets his… https://www.virusbulletin.com/blog/2006/11/vista-safe-without-av-says-allchin/

More US political spam

Voter persuasion campaign late and sloppy, says Panda
Voter persuasion campaign late and sloppy, says Panda Spam watchers at PandaLabs have spotted a campaign hoping to trick recipients into visiting a page attacking the state of US… https://www.virusbulletin.com/blog/2006/11/more-us-political-spam/

MS releases new Sysinternals utility

Process Monitor combines filemon, regmon into unified analysis tool.
Process Monitor combines filemon, regmon into unified analysis tool.Sysinternals, now 'a wholly owned subsidiary of Microsoft Corporation', has released a new system analysis tool… https://www.virusbulletin.com/blog/2006/11/ms-releases-new-sysinternals-utility/

Email worm spams global war news

Bush and Putin still alive, no nuclear war ahead.
Bush and Putin still alive, no nuclear war ahead. An email worm is posing as news of global warfare and the death of major world leaders in an attempt to persuade recipients to… https://www.virusbulletin.com/blog/2006/11/email-worm-spams-global-war-news/

Google blog spreads Kama Sutra worm

MyWife variant mailed to 50,000 video blog watchers.
MyWife variant mailed to 50,000 video blog watchers.Google has apologised to users of its Google Video Blog, some 50,000 of whom were exposed to an email worm after three postings… https://www.virusbulletin.com/blog/2006/11/google-blog-spreads-kama-sutra-worm/

US politicians slated for spam tactics

Report criticises leaders for election-pushing mass mail campaigns.
Report criticises leaders for election-pushing mass mail campaigns. A report from Sophos has criticised the behaviour of both major US political parties, after numerous emails… https://www.virusbulletin.com/blog/2006/11/us-politicians-slated-spam-tactics/

AOL ICQ vulnerability revealed

Chat program remote execution flaw patched.
Chat program remote execution flaw patched. Details of a vulnerability found in AOL's ICQ instant messaging software have been released by TippingPoint. The ActiveX flaw could… https://www.virusbulletin.com/blog/2006/11/aol-icq-vulnerability-revealed/

XMLHTTP zero-day exploit

ActiveX vulnerability in use by attackers.
ActiveX vulnerability in use by attackers. A new flaw in Microsoft's XML Core Services 4.0 is in active use by malicious websites, with attackers using the vulnerability to… https://www.virusbulletin.com/blog/2006/11/xmlhttp-zero-day-exploit/

US way ahead in phishing and spam

PhishTank, Sophos stats put US at top of lists.
PhishTank, Sophos stats put US at top of lists. Statistics released by anti-phishing community project PhishTank, launched early last month, have put the US far ahead of the field… https://www.virusbulletin.com/blog/2006/11/us-way-ahead-phishing-and-spam/

Adware costs Zango $3 million

Cash and promises settle deceptive practices case.
Cash and promises settle deceptive practices case. Adware giant Zango, formerly known as 180Solutions, has settled a case brought by the US Federal Trade Commission (FTC) for $3… https://www.virusbulletin.com/blog/2006/11/adware-costs-zango-3-million/

FBI busts phishing gang

Arrests made in Poland and US, more expected.
Arrests made in Poland and US, more expected. A large operation carried out by the FBI against a phishing operation has resulted in a string of arrests. Four people are being held… https://www.virusbulletin.com/blog/2006/11/fbi-busts-phishing-gang/

Spam worse than postal junk mail

Survey finds emails more irritating than unwanted paper.
Survey finds emails more irritating than unwanted paper. A study carried out by researchers from the University of Georgia's Grady College of Journalism and Mass Communication and… https://www.virusbulletin.com/blog/2006/11/spam-worse-postal-junk-mail/

Wikipedia spam points to malware

Emails used archive function to lend authenticity.
Emails used archive function to lend authenticity. Popular online encyclopaedia Wikipedia has been used as a vector for malware, with a spam campaign using the site's reputation… https://www.virusbulletin.com/blog/2006/11/wikipedia-spam-points-malware/

IE7 causing McAfee update problems

New browser version blocking install and updates.
New browser version blocking install and updates. Security settings in the new version of Microsoft's web browser, Internet Explorer 7, are causing problems for users of McAfee… https://www.virusbulletin.com/blog/2006/11/ie7-causing-mcafee-update-problems/

New OSX parasitic virus found

Symantec report proof-of-concept file infector for Mac.
Symantec report proof-of-concept file infector for Mac. Analysts at Symantec have received samples of a proof-of-concept file infector for the Apple Mac OSX platform. The virus,… https://www.virusbulletin.com/blog/2006/11/new-osx-parasitic-virus-found/

Spammed trojans posing as McAfee report

Campaign uses security news to bypass security.
Campaign uses security news to bypass security. A spam campaign has been spotted, with the emails claiming to come from security giant McAfee and to contain a report on recent… https://www.virusbulletin.com/blog/2006/11/spammed-trojans-posing-mcafee-report/

Academics create mobile malware

California University publishes Symbian proof of concept.
California University publishes Symbian proof of concept. A group of researchers at the University of California, Santa Barbara, (UCSB) have released details and source code for a… https://www.virusbulletin.com/blog/2006/11/academics-create-mobile-malware/

New anti-spam group formed

StopSpamAlliance unites international bodies.
StopSpamAlliance unites international bodies. A group of international agencies and organisations have teamed up to launch StopSpamAlliance.org, designed to be a centralised base… https://www.virusbulletin.com/blog/2006/11/new-anti-spam-group-formed/

Phish check interface

Developer interface for checking phishy URLs.
Developer interface for checking phishy URLs. The people behind PhishTank, a collaborative clearing house for data and information about phishing, have revealed a simplified… https://www.virusbulletin.com/blog/2006/11/phish-check-interface/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.