Remove ja
article thumbnail

A DDoS attack took down Finnish govt sites as Ukraine’s President addresses MPs

Security Affairs

Puolustusministeriön verkkosivut on avattu ja ne toimivat normaalisti. . “The State Department has taken steps to curb the attack, along with service providers and the Cyber ??Security Security Center.” ” The Finnish authorities mitigated the attack in around one hour. Palvelunestohyökkäys on ohi.

DDOS 97
article thumbnail

Unofficial patches released for Java flaws disclosed by Google Project Zero

Security Affairs

“Note that these patches only apply to Java 8 update 202, which is a “PSU” (“Patch Set Update”, see (link: [link] oracle.com/ technetwork /ja… ), since this is the version Project Zero’s @j00ru did his analysis on. The patches only work on Java 8 update 202. ” continues 0patch.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Tips for Reverse-Engineering Malicious Code

Lenny Zeltser

[EBP+8] on 32-bit, RCX on 64-bit. EBP+0xC] on 32-bit, RDX on 64-bit. EBP+0x10] on 32-bit, R8 on 64-bit. EBP+14] on 32-bit, R9 on 64-bit. Decoding Conditional Jumps. Jump if above/jump if greater. Jump if below/jump if less. Jump if equal; same as jump if zero. Jump if not equal; same as jump if not zero.

article thumbnail

Dissecting the 10k Lines of the new TrickBot Dropper

Security Affairs

Which, after a little cleanup, becomes: CallByName CreateObject (“wScript.Shell”), “Run”, VbMethod, “powershell wscript /e:jscript “c:usersadminappdataroamingmicrosoftwordstartupstati_stic.inf:com1””, 0.

Banking 81
article thumbnail

A new trojan Lampion targets Portugal

Security Affairs

$miU)e$5k3i]#*[OWHi(jc#-(F$bWHcVWpWe;deW3m$i_$TY%emc^%s&M$Tp^_OfxK”) ur = Decrypt (“{PL^7jj9f)is0D%9%aiXZ~]E^i#k*_+ZW^(eU_-ZNe^]5^;i}ZaYm’Y/wYH$6im)6$tksiw#|[dWNi)ja#*(~$oWzc+Wip@e6d2W&m.ix$uYde&ch%{F,#8’9/T#F(]$`ZdbrbY#”). uYde&ch%{F,#8’9/T#F(]$`ZdbrbY#”).

Malware 98
article thumbnail

A new secret stash for “fileless” malware

SecureList

43<KakjaiPA8$#ja key. HTTPS connection options are set to accept self-signed certificates on the server side. The C2 communication in this case is encrypted with an RC4 algorithm with the Dhga(81K1!392-!(43<KakjaiPA8$#ja In the case of the named pipes- based Trojan, the common commands are: Code. Command features.

Malware 138
article thumbnail

Working From Anywhere With Purpose and Openness

Duo's Security Blog

In Dutch we have a saying, “Nee heb je, ja kun je krijgen” that my dad loves to throw at me whenever I’m at a junction — it means “you have a no, but you could get a yes.” Your manager is definitely the right person because they’ll kick off the process with Employee Mobility. Like anything in life, it’s always worth asking the question.