April 20, 2016, 12:00 am
in Anti-Malware Research , by Liviu Arsene

The Petya ransomware that has been encrypting the NTFS Master File Table has recently been analyzed by the Bitdefender research team and found to sport similarities with other ransomware families, such as Chimera and Rokku.

6 Comments
March 24, 2015, 12:52 pm
in Anti-Malware Research , by Victor LUNCASU

We have recently came across a piece of malware which is known as HanciTor (as  ESET-NOD32 calls it) or Chanitor (based on the detection name given by Microsoft). The main purpose of this malware is to download other malware and … Continue reading

Comments Off on Hancitor Goes the Extra Mile on the Onion Route
July 9, 2014, 3:11 pm
in Anti-Malware Research , by Bogdan Botezatu

In an ever-connected world, malware thrives and multiplies at an incredible rate. More than 200,000 samples are built, packed and pushed on the market daily. Few of these threats manage to cause widespread havoc and only a meager handful become … Continue reading

7 Comments
November 18, 2013, 4:53 pm
in Anti-Malware Research, Projects , by Razvan Stoica

Bitdefender Labs malware researchers Vlad Bordianu and Tiberius Axinte have created a proof-of-concept exploit for the vulnerable Applovin ad-serving framework (also known as Vulna) versions 2.0.74 through 5.0.3 included. The exploit runs arbitrary code in the context of the affected … Continue reading

7 Comments
November 13, 2013, 3:58 pm
in Anti-Malware Research , by Razvan Stoica

Bitdefender Labs researchers have reverse-engineered the Cryptolocker domain generation algorythm and sinkholed the relevant domains between October 27 and November 1.

13 Comments
January 10, 2011, 3:37 pm
in Anti-Malware Research , by admin

“How to hide a malicious DLL? How about in plain sight?” One can easily imagine such thoughts going through the mind of whoever is churning out new versions of the Lavandos malware. After execution, the malware uses the Windows Registry … Continue reading

Comments Off on Avoiding detection – Lavandos