Hybrid Analysis Blog

IT security blog focusing on malware forensics, dynamic and static analysis, as well as automated malware analysis techniques.

Tuesday, August 21, 2018

CrowdStrike donates Falcon MalQuery for rapid YARA hunts to the HA Community

›
We all know that YARA rules are  the pattern matching swiss knife  in many ways and have become the de-facto standard when it comes to dete...
Tuesday, December 20, 2016

Introducing A Unique Script Logging Engine

›
One advantage of being an exposed software vendor (we operate a popular  free public malware analysis service ) is that we constantly get c...
Thursday, October 27, 2016

On Dridex and a new "Zero-Day-Distribution" method

›
The banking trojan Dridex (also known as Cridex, Feodo, Geodo, etc.) has been distributed in the past via malicious documents containin...
Sunday, July 3, 2016

Financial malware delivered via embedded JSE

›
Just a few days ago our research lead came accross an interesting office file. Instead of the common macro malware everyone sees today ( wh...
Thursday, February 25, 2016

Changelog Q4 2015 - Q1 2016 (distilled)

›
We've been so busy improving VxStream Sandbox and the surrounding technology that we have been having a bit of an on-off relationship ...
Tuesday, September 29, 2015

Sandboxes are not dead: automatically decoding a heavily obfuscated javascript

›
That's right. Sandbox technology is not dead, but some implementations can turn out to be if they are not maintained to adapt to the ev...
Thursday, September 24, 2015

Evading APT industry leaders using the Task Scheduler

›
We often get asked how VxStream Sandbox compares to proclaimed malware analysis industry leaders and other competitors. One aspect when com...
‹
›
Home
View web version
Powered by Blogger.