Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Macro documents with XOR Encoded Payloads

released on 2015-11-09 @ 02:32:34 PM
When reversing malware samples, one of the things that we as analysts look for are places where the attackers slip up. This can be anywhere from using the same strings, to weak obfuscation routines, or re-using the same snippet of code. When we talk about the attackers, there is this misconception that they are these super villains who can only do evil, but keep in mind they are humans too. This pulse contain IOC's related to phishing campaigns using the technique described above.