Diamond Fox – part 2: let’s dive in the code

In a previous post we made an initial analysis of a Diamond Fox bot delivered by the Nebula Exploit Kit (more about the campaign can be found here). We described the way to unpack the protection layer in order to get the core, written in Visual Basic, that can be decompiled. In this second part of…

Categories:

Tags:

(Read more…)

The post Diamond Fox – part 2: let’s dive in the code appeared first on Malwarebytes Labs.

Continue reading Diamond Fox – part 2: let’s dive in the code

Explained: Sage ransomware

Sage is yet another ransomware that has become a common threat nowadays. Similarly to Spora, it has capabilities to encrypt files offline. The malware is actively developed and currently, we are facing outbreak of version 2.2. of this product.
Categor… Continue reading Explained: Sage ransomware

Chinese PUPs and backdoor drivers: making systems less secure since 2013

In this blog, we expose a family of backdoor drivers that have been included in various PUPs of Chinese origin for several years.
Categories:
Malware
PUP/PUM
Threat analysis
Tags: IOCTLPUPPUPs

(Read more…)

The post Chinese PUPs and backdoor driv… Continue reading Chinese PUPs and backdoor drivers: making systems less secure since 2013

Diamond Fox – part 1: introduction and unpacking

In this short series of posts, we will take a deep dive in a sample of Diamond Fox delivered by the Nebula Exploit Kit (described here). We will also make a brief comparison with the old, leaked version, in order to show the evolution of this product.

Categories:

Tags:

(Read more…)

The post Diamond Fox – part 1: introduction and unpacking appeared first on Malwarebytes Labs.

Continue reading Diamond Fox – part 1: introduction and unpacking

Exploit kits: Winter 2017 review

We take a look at the current exploit kit scene (Winter 2017) according to our telemetry and honeypots.
Categories:
Exploits
Threat analysis
Tags: EKexploit kitsMagnitudemalvertisingmalvertsmalwareneutrinoransomwareRIGsundown

(Read more…)

The po… Continue reading Exploit kits: Winter 2017 review

Malwarebytes Labs Presents: The Cybercrime Tactics and Techniques Report

In our first wrap-up of the threat landscape, we are going to cover the trends observed during the last few months of 2016, provide an analyst’s view of the threats, and offer some predictions for the beginning of 2017. Moving forward, every quarter we will bring you a view of the threat landscape through the eyes of Malwarebytes researchers and analysts.

Categories:

Tags:

(Read more…)

The post Malwarebytes Labs Presents: The Cybercrime Tactics and Techniques Report appeared first on Malwarebytes Labs.

Continue reading Malwarebytes Labs Presents: The Cybercrime Tactics and Techniques Report

Free antivirus coupon leads to tech support scam

Yet another trick to watch out for with this free antivirus offer that misleads you into calling tech support scammers.
Categories:
Social engineering
Threat analysis
Tags: antiviruscouponGoogle ChromeMcAfeenortontech support scamTSS

(Read more…)
Continue reading Free antivirus coupon leads to tech support scam