Saturday, August 19, 2017

Status of - is it malicious or non malicious?

This site is found in many malware communication. So we are writing this post to clear the mist that it is not malicious. Please refer the below status from the security researcher community and look at the conclusion section for our comments.

Comments from security researchers: is being used by malware C&C. As of the date of this post, the site itself is not currently malicious, instead it is being abused by malicious software.

To find related malware which at some point makes use of this API, use virustotal's search feture and enter these into it. Do not visit these sites with your browser!!! 

Many ransomware families used this public API to collect or gather the IP address of the infected machines aka victim machine details. But in many real world applications using this public API for legitimate purpose. So it can't be blocked. But keep an eye on this API and check for what it is used in your network.

Post made by

Monday, August 7, 2017

Malspam Email Analysis by Malware Traffic Analysis Team:

In recent post of malware traffic analysis, they done a good analysis on malspam emails and how that spam campaign works. Please refer their post:

Please refer the following links to download the files of email, pcap, etc.
Zip archive of the emails:   11.5 kB (11,482 bytes)

Zip archive of the pcap:   54.6 kB (54,572 bytes)

Zip archive of the malware and artifacts:   1.01 MB (1,008,835 bytes)

Note: ZIP files are password-protected with the standard password.

Post made by

Setting up breakpoints in VirtualAlloc and VirtualProtect during malware analysis:

 Malware analysts add breakpoints in functions like `VirtualProtect` and `VirtualAlloc` for several key reasons: Understanding Malware Behav...