Remove tag targeted-advertising
article thumbnail

Analyzing the APT34’s Jason project

Security Affairs

APT 34, also referred to as “ OilRig ” or Helix Kitten , has been known to target regional corporations and industries. The attacker used an old version of Microsoft.Exchange.WebService.dll tagged as 15.0.0.0 Last Microsoft Exchange WebServices dll version dates to 2015. Original Leak. WebService.dll assemply version.

article thumbnail

Malware researcher reverse engineered a threat that went undetected for at least 2 years

Security Affairs

There is an interesting difference although, this stage builds up a new in-memory stage (let’s call Stage 4) by adding static GZIpped contents at the end of encrypted section (light blue tag on image). The attacker enumerates 571 possible analysis tools that should not be present on the target machine (Victim).

article thumbnail

TA505 Cybercrime targets system integrator companies

Security Affairs

In such a case the redirection script pushes to one of the following domains by introducing the HTML meta “refresh” tag, pointing the browser URL to a random choice between 4 different entries belonging to the following two domains: http[://com-kl96.net I am a computer security scientist with an intensive hacking background.