Remove ja
article thumbnail

A DDoS attack took down Finnish govt sites as Ukraine’s President addresses MPs

Security Affairs

Puolustusministeriön verkkosivut on avattu ja ne toimivat normaalisti. . “The State Department has taken steps to curb the attack, along with service providers and the Cyber ??Security Security Center.” ” The Finnish authorities mitigated the attack in around one hour. Palvelunestohyökkäys on ohi. To nominate, please visit:?

DDOS 94
article thumbnail

Tips for Reverse-Engineering Malicious Code

Lenny Zeltser

[EBP+8] on 32-bit, RCX on 64-bit. EBP+0xC] on 32-bit, RDX on 64-bit. EBP+0x10] on 32-bit, R8 on 64-bit. EBP+14] on 32-bit, R9 on 64-bit. Decoding Conditional Jumps. Jump if above/jump if greater. Jump if below/jump if less. Jump if equal; same as jump if zero. Jump if not equal; same as jump if not zero.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

A new trojan Lampion targets Portugal

Security Affairs

$miU)e$5k3i]#*[OWHi(jc#-(F$bWHcVWpWe;deW3m$i_$TY%emc^%s&M$Tp^_OfxK”) ur = Decrypt (“{PL^7jj9f)is0D%9%aiXZ~]E^i#k*_+ZW^(eU_-ZNe^]5^;i}ZaYm’Y/wYH$6im)6$tksiw#|[dWNi)ja#*(~$oWzc+Wip@e6d2W&m.ix$uYde&ch%{F,#8’9/T#F(]$`ZdbrbY#”). uYde&ch%{F,#8’9/T#F(]$`ZdbrbY#”).

Malware 98
article thumbnail

Dissecting the 10k Lines of the new TrickBot Dropper

Security Affairs

Technical details, including IoCs and Yara Rules, are available in the analysis published the Yoroi blog. Which, after a little cleanup, becomes: CallByName CreateObject (“wScript.Shell”), “Run”, VbMethod, “powershell wscript /e:jscript “c:usersadminappdataroamingmicrosoftwordstartupstati_stic.inf:com1””, 0.

Banking 80
article thumbnail

Working From Anywhere With Purpose and Openness

Duo's Security Blog

In Dutch we have a saying, “Nee heb je, ja kun je krijgen” that my dad loves to throw at me whenever I’m at a junction — it means “you have a no, but you could get a yes.” Your manager is definitely the right person because they’ll kick off the process with Employee Mobility. Like anything in life, it’s always worth asking the question.