VB Blog

VB2018 video: Adware is just malware with a legal department - how we reverse engineered OSX/Pirrit, received legal threats, and survived

Posted by   Martijn Grooten on   Mar 8, 2019

Amit Serper first analysed the OSX/Pirrit adware in 2016, highlighting some of its malware-like techniques, and soon afterwards started receiving legal threats from the company behind it. At VB2018 Amit gave a presentation in which he discussed both the adware and the legal threats he received for calling it malware. Today, we publish the video of Amit's presentation.

Read more  

VB2018 paper: Anatomy of an attack: detecting and defeating CRASHOVERRIDE

Posted by   Martijn Grooten on   Mar 5, 2019

In December 2016, the CRASHOVERRIDE malware framework was used to cause a blackout in Ukraine. At VB2018 in Montreal, Dragos researcher Joe Slowik presented a detailed paper on the framework, explaining how the malware works and how it targets various protocols used to operate the electric grid. Today we publish both Joe's paper and the recording of his presentation.

Read more  

VB2018 presentation: Levelling up: why sharing threat intelligence makes you more competitive

Posted by   Helen Martin on   Mar 1, 2019

In a presentation at VB2018, Michael Daniel, President and CEO of the Cyber Threat Alliance, outlined exactly how threat sharing strengthens a company's competitive advantage. Today we release the recording of his presentation.

Read more  

The malspam security products miss: Emotet, Ursnif, and a spammer's blunder

Posted by   Martijn Grooten on   Feb 25, 2019

The set-up of the VBSpam test lab gives us a unique insight into the kinds of emails that are more likely to bypass email filters. This week we look at the malspam that was missed: a very international email with a link serving Emotet, an Italian Ursnif campaign with a password-protected ZIP and an email to which a clumsy spammer had attached a list of email addresses rather than a payload.

Read more  

VB2018 paper: The modality of mortality in domain names

Posted by   Martijn Grooten on   Feb 22, 2019

Domains play a crucial role in most cyber attacks, from the very advanced to the very mundane. Today, we publish a VB2018 paper by Paul Vixie (Farsight Security) who undertook the first systematic study into the lifetimes of newly registered domains.

Read more  

VB2018 paper: Analysing compiled binaries using logic

Posted by   Martijn Grooten on   Feb 20, 2019

Constraint programming is a lesser-known technique that is becoming increasingly popular among malware analysts. In a paper presented at VB2018 Thaís Moreira Hamasaki presented an overview of the technique and explained how it can be applied to the analysis of (potentially) malicious binaries. Today, we publish both Thaís' paper and the video of her presentation.

Read more  

Virus Bulletin encourages experienced speakers and newcomers alike to submit proposals for VB2019

Posted by   Martijn Grooten on   Feb 19, 2019

With a little less than a month before the deadline of the call for papers for VB2019, Virus Bulletin encourages submissions from experienced speakers and newcomers alike.

Read more  

VB2018 paper: Internet balkanization: why are we raising borders online?

Posted by   Helen Martin on   Feb 13, 2019

At VB2018 in Montreal, Ixia researcher Stefan Tanase presented a thought-provoking paper on the current state of the Internet and the worrying tendency towards raising borders and restricting the flow of information. Today we publish both his paper and the recording of his presentation.

Read more  

The malspam security products miss: banking and email phishing, Emotet and Bushaloader

Posted by   Martijn Grooten on   Feb 11, 2019

The set-up of the VBSpam test lab gives us a unique insight into the kinds of emails that are more likely to bypass email filters. This week we look at the malspam that was missed: banking and email phishing, Emotet and Bushaloader.

Read more  

VB2018 paper: Where have all the good hires gone?

Posted by   Helen Martin on   Feb 8, 2019

The cybersecurity skills gap has been described as one of the biggest challenges facing IT leaders today. At VB2018 in Montreal, ESET's Lysa Myers outlined some of the things the industry can do to help address the problem. Today we publish Lysa's paper and the recording of her presentation.

Read more  

Search blog

OECD calls for coordination and cooperation

OECD issues 'Recommendation on Cross-Border Cooperation in the Enforcement of Laws against Spam'.
OECD issues 'Recommendation on Cross-Border Cooperation in the Enforcement of Laws against Spam'. The Organization for Economic Cooperation and Development (OECD) has called on… https://www.virusbulletin.com/blog/2006/05/oecd-calls-coordination-and-cooperation/

VoIP phishing scam

New species of phish spotted.
New species of phish spotted. A new variety of phishing scam was spotted last month: VoIP phishing. Instead of coercing victims into entering their confidential details on a fake… https://www.virusbulletin.com/blog/2006/05/voip-phishing-scam/

May issue of VB published

The May issue of Virus Bulletin is now available for subscribers to download.
The May issue of Virus Bulletin is now available for subscribers to download. The May 2006 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2006/05/may-issue-vb-published/

May

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/05/

VB job vacancy

There are currently no job vacancies at Virus Bulletin.
There are currently no job vacancies at Virus Bulletin. Posted on 8 June 2006 by Virus Bulletin https://www.virusbulletin.com/blog/2006/04/vb-job-vacancy/

VB2006 conference programme revealed

The VB2006 conference programme is now available.
The VB2006 conference programme is now available. VB has revealed the conference programme for VB2006, the 16th Virus Bulletin International Conference. The three-day conference… https://www.virusbulletin.com/blog/2006/04/conference-programme-revealed/

Grisoft makes acquisition

AVG developer acquires Ewido Networks.
AVG developer acquires Ewido Networks. Anti-Virus vendor Grisoft has announced the acquisition of German anti-malware firm Ewido Networks. Although one of the smaller players in… https://www.virusbulletin.com/blog/2006/04/grisoft-makes-acquisition/

Spy couple sentenced

Trojan peddlers get their comeuppance.
Trojan peddlers get their comeuppance. An Israeli couple who ran a private investigation service have been handed jail sentences and a $426,000 fine after pleading guilty to… https://www.virusbulletin.com/blog/2006/04/spy-couple-sentenced/

Code of practice for Australia's ISPs

Legislative code to come into force.
Legislative code to come into force. The Australian Communications and Media Authority (ACMA) is poised to introduce a legislative code of practice for ISPs that could see hefty… https://www.virusbulletin.com/blog/2006/04/code-practice-australia-s-isps/

China calculates cost of spam

Lost productivity costs dear.
Lost productivity costs dear. Spam is costing China $756m (6.069 billion yuan) every year according to estimates by the Internet Society of China (ISC). The figure, published in… https://www.virusbulletin.com/blog/2006/04/china-calculates-cost-spam/

'Real' computer virus

Digital life form.
Digital life form. Researchers in the US have constructed a virtual version of the satellite tobacco mosaic virus using more than a million 'digital atoms'. The researchers used… https://www.virusbulletin.com/blog/2006/04/real-computer-virus/

April

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/04/

More updating woes

Another troublesome month for security vendors.
Another troublesome month for security vendors. Last month we reported on problems for Kaspersky, Sophos and Microsoft caused by faulty updates. This month it is the turn of… https://www.virusbulletin.com/blog/2006/04/more-updating-woes/

Largest can-spam fine to be paid

Internet marketing firm makes $900,000 settlement.
Internet marketing firm makes $900,000 settlement. An Internet marketing firm in the US has agreed to pay $900,000 to settle a case brought against it by the Federal Trade… https://www.virusbulletin.com/blog/2006/04/largest-can-spam-fine-be-paid/

Updating niggles

Troublesome month for security vendors
Troublesome month for security vendors Last month proved to be troublesome for security vendors Sophos, Microsoft and Kaspersky, as niggles with updates caused problems for their… https://www.virusbulletin.com/blog/2006/03/updating-niggles/

Vigilant staff avert phishing scam

Scammers halted in their tracks
Scammers halted in their tracks A web-hosting company based in New Zealand claims that, thanks to the vigilance of its staff, it has averted a potential phishing scam targeted at… https://www.virusbulletin.com/blog/2006/03/vigilant-staff-avert-phishing-scam/

Dutch police arrest Nigerian scammers

419 scamming ring uncovered
419 scamming ring uncovered Dutch police arrested 12 Nigerians in Amsterdam last month after they were found to be operating a 419 scamming ring. According to Dutch police, who… https://www.virusbulletin.com/blog/2006/03/dutch-police-arrest-nigerian-scammers/

Hotbar adware dispute settled

Symantec settles adware case
Symantec settles adware case Symantec has reached an out-of-court agreement in the pre-emptive lawsuit it filed against marketing firm Hotbar.com Inc. In the unusual case, the… https://www.virusbulletin.com/blog/2006/03/hotbar-adware-dispute-settled/

China to crack down on spam

China toughens up its anti-spam regulations
China toughens up its anti-spam regulations The Chinese Government has introduced a set of regulations aimed at reducing the amount of spam circulating in the country. The sending… https://www.virusbulletin.com/blog/2006/03/china-crack-down-spam/

March

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/03/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.