Infostealer Embedded in a Word Document, (Thu, May 4th)

When attackers design malicious documents, one of their challenges is to make the potential victim confident to perform dangerous actions: click on a link, disable a security feature, etc. The best example is probably VBA macros in Microsoft Office documents. Disabled by default, the attacker must make the user confident to enable them by clicking on the “yellow ribbon” on top of the document.

Continue reading Infostealer Embedded in a Word Document, (Thu, May 4th)→

Posted in Uncategorized

Increased Number of Configuration File Scans, (Wed, May 3rd)

Today, automation is a crucial point for many organizations. In cloud environments, in containers, many apps are deployed automatically, for example, to face a sudden peak of activity or to reduce costs. Automation means that everything must be pre-configured: specifications of the applications but also critical information to interact with the hosting platform (credentials, API keys, secret keys, …)

Continue reading Increased Number of Configuration File Scans, (Wed, May 3rd)→

Posted in Uncategorized

“Passive” analysis of a phishing attachment, (Mon, May 1st)

When it comes to analysis of malicious code, one often has to weigh the potential benefits of a quick, dynamic analysis, which might cause the code to interact with infrastructure operated by a threat actor and thus “break OPSEC”, against the benefits of a slower approach based mostly on static analysis techniques.

Continue reading “Passive” analysis of a phishing attachment, (Mon, May 1st)→

Posted in Uncategorized

SANS.edu Research Journal Volume 3 Released into the Wild. https://www.sans.edu/cyber-security-research @sans_edu #cybersecurity #research, (Sun, Apr 30th)

—
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

Continue reading SANS.edu Research Journal Volume 3 Released into the Wild. https://www.sans.edu/cyber-security-research @sans_edu #cybersecurity #research, (Sun, Apr 30th)→

Posted in Uncategorized