Powershell

MalwareBytesSecurity

Malware analysis: decoding Emotet, part 2

Credit to Author: Vishal Thakur| Date: Thu, 07 Jun 2018 15:00:00 +0000

In part two of our series on decoding Emotet, we analyze the PowerShell code flow and structure. We also reconstruct the command-line arguments—for fun!

Categories:

Tags:

(Read more…)

The post Malware analysis: decoding Emotet, part 2 appeared first on Malwarebytes Labs.

Read More
MicrosoftSecurity

Now you see me: Exposing fileless malware

Credit to Author: Windows Defender ATP| Date: Wed, 24 Jan 2018 14:00:21 +0000

Attackers are determined to circumvent security defenses using increasingly sophisticated techniques. Fileless malware boosts the stealth and effectiveness of an attack, and two of last years major ransomware outbreaks (Petya and WannaCry) used fileless techniques as part of their kill chains. The idea behind fileless malware is simple: If tools already exist on a device

Read more

Read More
MicrosoftSecurity

Windows Defender ATP machine learning and AMSI: Unearthing script-based attacks that ‘live off the land’

Credit to Author: Windows Defender ATP| Date: Mon, 04 Dec 2017 14:00:07 +0000

Scripts are becoming the weapon of choice of sophisticated activity groups responsible for targeted attacks as well as malware authors who indiscriminately deploy commodity threats. Scripting engines such as JavaScript, VBScript, and PowerShell offer tremendous benefits to attackers. They run through legitimate processes and are perfect tools for living off the landstaying away from the

Read more

Read More
MalwareBytesSecurity

Elaborate scripting-fu used in espionage attack against Saudi Arabia Government entity

Credit to Author: Malwarebytes Labs| Date: Wed, 27 Sep 2017 01:06:51 +0000

In this post, we take apart a clever set of scripts used in a targeted attack against the government of Saudi Arabia.

Categories:

Tags:

(Read more…)

The post Elaborate scripting-fu used in espionage attack against Saudi Arabia Government entity appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Elaborate scripting-fu used in espionage attack against Saudi Arabia Government

Credit to Author: Malwarebytes Labs| Date: Wed, 27 Sep 2017 01:06:51 +0000

In this post, we take apart a clever set of scripts used in a targeted attack against the government of Saudi Arabia.

Categories:

Tags:

(Read more…)

The post Elaborate scripting-fu used in espionage attack against Saudi Arabia Government appeared first on Malwarebytes Labs.

Read More