Analyzing a YouTube Sponsorship Phishing Mail and Malware Targeting Content Creators, (Wed, Jun 21st)

One of our Stormcast listeners, Kevin, wrote in to share that his friend Jon had received a direct spear-phishing e-mail. We requested for more information, and Jon kindly provided us with the corresponding e-mails and data to analyze. The spear-phishing e-mail sent to Jon masqueraded as an individual representing NordVPN (note: NordVPN had published an advisory about scammers posing as NordVPN representatives earlier this year [1]) and enquired about the possibility of a YouTube sponsorship/collaboration with his YouTube channel. I took the liberty to examine the phishing e-mail and its associated artifacts, noting the details I observed from my analysis.

I first examined the e-mail headers, noting the observation of the mail.ru header in the X-Mailer field. (with reference to Figure 1). The e-mail address that the adversary used was collaboration@nordvpn-media[.]com, which had a very close domain name to the original domain name (nordvpnmedia[.]com) that NordVPN had stated to be genuine [1].

Continue reading Analyzing a YouTube Sponsorship Phishing Mail and Malware Targeting Content Creators, (Wed, Jun 21st)→

Posted in Uncategorized

Malware Delivered Through .inf File, (Mon, Jun 19th)

Microsoft has used “.inf” files for a while[1]. They are simple text files and contain setup information in a driver package. They describe what must be performed to install a driver package on a device. When you read them, the syntax is straightforward to understand. The file is based on sections that describe what must be performed. One of them is very interesting for attackers: [RunPreSetupCommandsSection]. Note that .inf files cannot be executed “as is”.

Continue reading Malware Delivered Through .inf File, (Mon, Jun 19th)→

Posted in Uncategorized

Another RAT Delivered Through VBS, (Fri, Jun 16th)

VBS looks popular these days&#;x26;#;x21; After the last Didier&#;x26;#;39;s diary, I found another interesting script. It started with an email that referenced a fake due invoice. The invoice icon pointed to a URL. Usually, such URLs display a fake login page asking for credentials. Not this time.

Continue reading Another RAT Delivered Through VBS, (Fri, Jun 16th)→

Posted in Uncategorized

Supervision and Verification in Vulnerability Management, (Thu, Jun 15th)

Managing vulnerabilities in operating systems and software can be challenging and even contentious. Opinions are divided among industry peers &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x93; some argue that security updates would be unnecessary if developers were held accountable for security vulnerabilities &#;x26;#;x5b;1&#;x26;#;x5d;. In contrast, others assert that updating systems as soon as possible (where applicable) was a critical best practice for users &#;x26;#;x5b;2&#;x26;#;x5d;. Most clients in my consulting job adopt some form of vulnerability management paradigm (quarterly vulnerability assessments and addressing discovered vulnerabilities to automated vulnerability management programs where identified vulnerabilities are addressed as soon as possible). I noticed some peculiarities while providing consultancy services to a discerning customer&#;x26;#;39;s automated vulnerability management program. The automated vulnerability management product will not be discussed here as it is neither the main focal point nor a debate on whether the product is trustworthy. Instead, it was serendipitous and stemmed from just a simple drive to appropriately mitigate identified vulnerabilities in all systems. Together with the client&#;x26;#;39;s management support, we worked together to address the vulnerability in question while ensuring it was fully mitigated.

Continue reading Supervision and Verification in Vulnerability Management, (Thu, Jun 15th)→

Posted in Uncategorized