On January 18 a colleague of mine (Luca) called me telling a malicious email was targeting Italian companies. This is the beginning of our new analysis adventure that Luca and I run together. The email pretended to be sent by “Ministero dell’ Economia e delle Finanze” the Italian Department of Treasury and it had a […]Read more "Huge Botnet Attacking Italian Companies"
Attack attribution is always a very hard work. False Flags, Code Reuse and Spaghetti Code makes impossible to assert “This attack belongs to X”. Indeed nowadays makes more sense talking about Attribution Probability rather then Attribution by itself. “This attack belongs to X with 65% of attribution probability” it would be a correct sentence. I […]Read more "Info Stealing: a new operation in the wild"
Hi folks, today I’d like to share a nice trick to unprotect password protected VB scripts into Office files. Nowadays it’s easy to find out malicious contents wrapped into OLE files since such a file format has the capability to link objects into documents and viceversa. An object could be a simple external link, a […]Read more "Unprotecting VBS Password Protected Office Files"
Introduction. Today I want to share a nice Malware analysis having an interesting flow. The “interesting” adjective comes from the abilities the given sample owns. Capabilities of exploiting, hard obfuscations and usage of advanced techniques to steal credentials and run commands. The analyzed sample has been provided by a colleague of mine (Alessandro) who received […]Read more "Advanced ‘all in memory’ CryptoWorm"
Hi folks, today I want to share a quick but intensive experience in fighting cybercrime. I wish you would appreciate the entire process from getting an email attachment to powning the ransom server trying to stop the infection and to alert everybody about the found threats. As a second step I would try to identify […]Read more "TOPransom: From eMail Attachment to Powning the Attacker’s Database"
Everything started from a well edited Italian language email (given to me from a colleague of mine, thank you Luca!) reaching out many Italian companies. The Italian language email had a weird attachment: ordine_065.js (it would be “Order Form” in English) which appeared “quite malicious” to me. By editing the .js attachment it becomes clear that […]Read more "False Flag Attack on Multi Stage Delivery of Malware to Italian Organisations"
During the past few weeks some people asked me how to build a “cyber security offensive team”. Since the recurring question I decided to write a little bit about my point of view and my past experiences on this topic without getting into details (no: procedures, methodologies, communication artifacts and skill set will be provided). […]Read more "The Offensive Cyber Security Supply Chain"
During the past few weeks I read a lot of great papers, blog posts and full magazine articles on the ShadowBrokers Leak (free public repositories: here and here) released by WikiLeaks Vault7. Many of them described the amazing power of such a tools (by the way they are currently used by hackers to exploit systems […]Read more "ShadowBrokers Leak: A Machine Learning Approach"
Another free weekend, another suspicious link provided by a colleague of mine and another compelling feeling to understand “how it works”. The following analysis is made “just for fun” and is not part of my professional analyses which have to follows a complete different process before being released. So please consider it as a “sport […]Read more "A quick REVENGE Analysis"
A couple of days ago a colleague of mine gave me a “brand new” malicious content delivered by a single HTML page. The page was sent to an email box as part of a biggest attack. I found that vector particularly fun and so I’d like to share some of the steps who took me […]Read more "Crypt0l0cker Revival !"