VB Blog

VB2018 paper: Unpacking the packed unpacker: reversing an Android anti-analysis library

Posted by   Martijn Grooten on   Jan 14, 2019

Today, we publish a VB2018 paper by Google researcher Maddie Stone in which she looks at one of the most interesting anti-analysis native libraries in the Android ecosystem. We also release the recording of Maddie's presentation.

Read more  

VB2018 paper: Draw me like one of your French APTs – expanding our descriptive palette for cyber threat actors

Posted by   Martijn Grooten on   Jan 7, 2019

Today, we publish the VB2018 paper by Chronicle researcher Juan Andres Guerrero-Saade, who argues we should change the way we talk about APT actors.

Read more  

Book Review: Cyber Wars

Posted by   Martijn Grooten on   Dec 19, 2018

VB Editor Martijn Grooten reviews Charles Arthur's Cyber Wars, which looks at seven prominent hacks and attacks, and the lessons we can learn from them.

Read more  

VB2018 paper: Office bugs on the rise

Posted by   Martijn Grooten on   Dec 14, 2018

At VB2018 Sophos researcher Gábor Szappanos provided a detailed overview of Office exploit builders, and looked in particular at the widely exploited CVE-2017-0199. Today we publish his paper and release the video of his presentation.

Read more  

VB2018 video: The Big Bang Theory by APT-C-23

Posted by   Martijn Grooten on   Dec 12, 2018

Today, we release the video of the VB2018 presentation by Check Point researcher Aseel Kayal, who connected the various dots relating to campaigns by the APT-C-23 threat group.

Read more  

VB2019 London - join us for the most international threat intelligence conference!

Posted by   Martijn Grooten on   Dec 11, 2018

VB calls on organisations and individuals involved in threat intelligence from around the world to participate in next year's Virus Bulletin conference.

Read more  

VB2018 paper: Tracking Mirai variants

Posted by   Martijn Grooten on   Dec 7, 2018

Today, we publish the VB2018 paper by Qihoo 360 researchers Ya Liu and Hui Wang, on extracting data from variants of the Mirai botnet to classify and track variants.

Read more  

VB2018 paper: Hide'n'Seek: an adaptive peer-to-peer IoT botnet

Posted by   Martijn Grooten on   Dec 6, 2018

2018 has seen an increase in the variety of botnets living on the Internet of Things - such as Hide'N'Seek, which is notable for its use of peer-to-peer for command-and-control communication. Today, we publish the VB2018 paper by Bitdefender researchers Adrian Șendroiu and Vladimir Diaconescu, who studied the Hide'N'Seek IoT botnet. We also release the recording of their presentation.

Read more  

New paper: Botception: botnet distributes script with bot capabilities

Posted by   Martijn Grooten on   Dec 4, 2018

In a new paper, Avast researchers Jan Sirmer and Adolf Streda look at how a spam campaign sent via the Necurs botnet was delivering the Flawed Ammyy RAT. As well as publishing the paper, we have also released the video of the reseachers' VB2018 presentation on the same topic.

Read more  

VB2018 video: Behind the scenes of the SamSam investigation

Posted by   Martijn Grooten on   Nov 29, 2018

Today we have published the video of the VB2018 presentation by Andrew Brandt (Sophos) on the SamSam ransomware, which became hot news following the indictment of its two suspected authors yesterday.

Read more  

Search blog

Viruses - Some Good

Just occasionally, a virus infection can have some positive effects...
Just occasionally, a virus infection can have some positive effects... Much like biological viruses, it turns out that infections by computer viruses can lead to increased measures… https://www.virusbulletin.com/blog/2002/09/viruses-some-good/

Bring on the DEET

The latest award for the most tenuous product-pushing story goes to BitDefender, whose marketeers claim a 'mosquito-borne disease could easily become a computer infection.'
The latest award for the most tenuous product-pushing story goes to BitDefender, whose marketeers claim a 'mosquito-borne disease could easily become a computer infection.' The… https://www.virusbulletin.com/blog/2002/09/bring-deet/

Virtually There

The Infosecurity show and exhibition has gone virtual with the launch of the first Infosecurity World Online exhibition. But where are the sweets?
The Infosecurity show and exhibition has gone virtual with the launch of the first Infosecurity World Online exhibition. But where are the sweets? The Infosecurity show and… https://www.virusbulletin.com/blog/2002/09/virtually-there/

September

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/09/

The youth of today...

Five Israeli teenagers have been charged in connection with writing and disseminating W32/Goner.
Five Israeli teenagers have been charged in connection with writing and disseminating W32/Goner. According to Israeli newspaper Ha'aretz, five youngsters have been charged with… https://www.virusbulletin.com/blog/2002/08/youth-today/

Bugs galore

Symantec's acquisition of SecurityFocus last month has unsettled a number of contributors to the BugTraq vulnerability list. So much so that they created a new one.
Symantec's acquisition of SecurityFocus last month has unsettled a number of contributors to the BugTraq vulnerability list. So much so that they created a new one. At the news of… https://www.virusbulletin.com/blog/2002/08/bugs-galore/

Retail Therapy

Symantec has been on a blow-out shopping spree...
Symantec has been on a blow-out shopping spree... Symantec has been on a blow-out shopping spree. Perhaps it was its purchase of Mountain Wave earlier this year that put the… https://www.virusbulletin.com/blog/2002/08/retail-therapy/

Third time unlucky

NAI's third attempt to re-acquire McAfee.com was scuppered yesterday when 96% of McAfee.com shareholders rejected NAI's latest exchange offer for McAfee.com shares.
NAI's third attempt to re-acquire McAfee.com was scuppered yesterday when 96% of McAfee.com shareholders rejected NAI's latest exchange offer for McAfee.com shares.NAI's third… https://www.virusbulletin.com/blog/2002/08/third-time-unlucky/

August

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/08/

Erratum: Windows XP comparative review: McAfee VirusScan

After re-testing, McAfee's VirusScan product gains a VB 100% award.
After re-testing, McAfee's VirusScan product gains a VB 100% award. Unfortunately an error occurred in Virus Bulletin's Windows XP comparative review (see VB June 2002, p.21):… https://www.virusbulletin.com/blog/2002/07/erratum-windows-xp-comparative-review-mcafee-virusscan/

Crying wolf revisited

While one AV vendor comes in for a roasting, the others enjoy the rare taste of the moral high ground.
While one AV vendor comes in for a roasting, the others enjoy the rare taste of the moral high ground. Last month was Network Associates' turn to come in for a roasting over its… https://www.virusbulletin.com/blog/2002/07/crying-wolf-revisited/

Quarter byte squaw?

Worryingly, many sysadmins seemed unaware both of the Apache 'chunked encoding' bug and of their systems' vulnerability...
Worryingly, many sysadmins seemed unaware both of the Apache 'chunked encoding' bug and of their systems' vulnerability... This month has seen the elevation of what was thought… https://www.virusbulletin.com/blog/2002/07/quarter-byte-squaw/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/07/

Windows XP Professional comparative review

After re-testing, Panda Antivirus Platinum's on-access scanner product gains a VB 100% award.
After re-testing, Panda Antivirus Platinum's on-access scanner product gains a VB 100% award. Since the publication of the Windows XP comparative review in the June edition of… https://www.virusbulletin.com/blog/2002/06/windows-xp-professional-comparative-review/

Shakira cynicism

As reports begin to appear of the latest VBSWG variant climbing prevalence tables, VB has received a particularly relevant comment from sys-admin Scott Francis.
As reports begin to appear of the latest VBSWG variant climbing prevalence tables, VB has received a particularly relevant comment from sys-admin Scott Francis. As reports begin… https://www.virusbulletin.com/blog/2002/06/shakira-cynicism/

As complex as Euler's formula

IT news website Slashdot's report of Simile's cross-platform capabilities was met with the usual host of ill-informed, biased and naïve comments from users of the site.
IT news website Slashdot's report of Simile's cross-platform capabilities was met with the usual host of ill-informed, biased and naïve comments from users of the site. IT news… https://www.virusbulletin.com/blog/2002/06/complex-euler-s-formula/

June

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/06/

Outraged of Slovakia

Is there really any need to include virus samples in product tests? CNET seems to think it's not worth the bother.
Is there really any need to include virus samples in product tests? CNET seems to think it's not worth the bother. Recently VB received an email from an outraged user declaring… https://www.virusbulletin.com/blog/2002/05/outraged-slovakia/

Closed source sauce

Microsoft has claimed that open source software threatens security - unlike proprietary software such as its own SQL Server, currently playing vector to a new worm.
Microsoft has claimed that open source software threatens security - unlike proprietary software such as its own SQL Server, currently playing vector to a new worm. Goliath of the… https://www.virusbulletin.com/blog/2002/05/closed-source-sauce/

May

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2002/05/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.