Hybrid Analysis Blog

IT security blog focusing on malware forensics, dynamic and static analysis, as well as automated malware analysis techniques.

Thursday, October 27, 2016

On Dridex and a new "Zero-Day-Distribution" method

›
The banking trojan Dridex (also known as Cridex, Feodo, Geodo, etc.) has been distributed in the past via malicious documents containin...
Sunday, July 3, 2016

Financial malware delivered via embedded JSE

›
Just a few days ago our research lead came accross an interesting office file. Instead of the common macro malware everyone sees today ( wh...
Thursday, February 25, 2016

Changelog Q4 2015 - Q1 2016 (distilled)

›
We've been so busy improving VxStream Sandbox and the surrounding technology that we have been having a bit of an on-off relationship ...
Tuesday, September 29, 2015

Sandboxes are not dead: automatically decoding a heavily obfuscated javascript

›
That's right. Sandbox technology is not dead, but some implementations can turn out to be if they are not maintained to adapt to the ev...
Thursday, September 24, 2015

Evading APT industry leaders using the Task Scheduler

›
We often get asked how VxStream Sandbox compares to proclaimed malware analysis industry leaders and other competitors. One aspect when com...
Monday, September 14, 2015

Using powershell as an infection vector

›
It's been a bit quiet on our blog over the past weeks while we have been busy implementing new features and analyzing samples we come a...
Sunday, August 16, 2015

About Dridex, decoding and deobfuscating VBE files, behavior signature triplets and other features

›
Decoding and deobfuscating embedded VBE files We will start out this blogpost outlining the technologically speaking probably most exci...
‹
›
Home
View web version
Powered by Blogger.