EternalPetya – yet another stolen piece in the package?

Credit to Author: Malwarebytes Labs| Date: Fri, 30 Jun 2017 16:53:36 +0000

Since 27th June we’ve been investigating the outbreak of the new Petya-like malware armed with an infector similar to WannaCry. Since the day one, various contradicting theories started popping up. Some believed, that it is a rip-off the original Petya, others – that it is another step in its evolution. However, so far, those were just different opinions, and none of them was backed up with enough evidence. In this post, we will try to fill this gap, by making a step-by-step comparison of the current kernel and the one on which it is based (Goldeneye Petya).

Categories:

Tags:

(Read more…)

The post EternalPetya – yet another stolen piece in the package? appeared first on Malwarebytes Labs.

Read more

The numeric Tech Support Scam campaign

Credit to Author: Jérôme Segura| Date: Tue, 13 Jun 2017 14:00:21 +0000

A new tech support scam campaign is being pushed in lieu of exploit kits. We take a look at its distribution method and how it is able to bring browsers to their knees.

Categories:

Tags:

(Read more…)

The post The numeric Tech Support Scam campaign appeared first on Malwarebytes Labs.

Read more

New social engineering scheme triggers on mouse movement

Credit to Author: Jérôme Segura| Date: Thu, 08 Jun 2017 18:49:21 +0000

No macro, no exploit. This attack uses mouse movement to launch malicious code in booby-trapped documents.

Categories:

Tags:

(Read more…)

The post New social engineering scheme triggers on mouse movement appeared first on Malwarebytes Labs.

Read more

LatentBot piece by piece

Credit to Author: Malwarebytes Labs| Date: Thu, 08 Jun 2017 15:00:53 +0000

LatentBot is a multi-modular Trojan written in Delphi and known to have been around since 2013. Recently, we captured and dissected a sample distributed by RIG Exploit Kit. In this post we will describe its modules by taking apart several layers of obfuscation and encryption in order to reveal their true nature.

Categories:

Tags:

(Read more…)

The post LatentBot piece by piece appeared first on Malwarebytes Labs.

Read more

Spotting fake reviews – have healthy online skepticism

Credit to Author: Jean Taggart| Date: Thu, 01 Jun 2017 14:00:01 +0000

In this blog, we discuss techniques to detect fake reviews, fake reviewers, and shady online image management techniques.

Categories:

Tags:

(Read more…)

The post Spotting fake reviews – have healthy online skepticism appeared first on Malwarebytes Labs.

Read more

The worm that spreads WanaCrypt0r

Credit to Author: Zammis Clark| Date: Fri, 12 May 2017 22:02:24 +0000

WanaCrypt0r is a ransomware infection that has spread through many corporate networks. Read a technical analysis of the worm that allowed it to do this.

Categories:

Tags:

(Read more…)

The post The worm that spreads WanaCrypt0r appeared first on Malwarebytes Labs.

Read more

HandBrake hacked to drop new variant of Proton malware

Credit to Author: Thomas Reed| Date: Mon, 08 May 2017 17:04:43 +0000

The website of the popular HandBrake DVD-ripping app has been hacked, and for 4 days, a maliciously-modified copy of the app was installing a new variant of the mysterious Proton malware.

Categories:

Tags:

(Read more…)

The post HandBrake hacked to drop new variant of Proton malware appeared first on Malwarebytes Labs.

Read more