A research that covers the structural aspects of CPL files & how criminals are using it to spread malware in Brazil:http://bit.ly/1f6DoU3
-
-
Replying to @TrendMicroRSRCH
@TrendLabs@MenteBinaria this is not limited to ZIP files & Brazil, also seen CPL in RTF in Switzerland (in German) https://www.virustotal.com/en/file/28e08c2174e341cca03662b31aaa540780cb8e39e7e309164a61c4a8d6244b72/analysis/1390838824/ …2 replies 0 retweets 0 likes -
Replying to @c_APT_ure
@c_APT_ure@TrendLabs We've seen that in Brazil toohttp://blog.trendmicro.com/trendlabs-security-intelligence/control-panel-files-used-as-malicious-attachments/ …1 reply 1 retweet 2 likes -
Replying to @mer0x36
@MenteBinaria@TrendLabs seen some w/ DarkKomet & TROJ_FORUCON.BMC detections. Is that really DarkKomet or some RAT? https://www.virustotal.com/en/file/28e08c2174e341cca03662b31aaa540780cb8e39e7e309164a61c4a8d6244b72/analysis/1390997554/ …1 reply 0 retweets 0 likes -
Replying to @c_APT_ure
@c_APT_ure Hi there! We'll check with our experts on this and get back to you as soon as we can.@MenteBinaria1 reply 0 retweets 0 likes -
Replying to @TrendMicroRSRCH
.
@c_APT_ure. Looks like it's neither -- It's an RTF file (TROJ_ARTIEF.KVV) with a ZBOT attachment (TSPY_ZBOT.KVV)@MenteBinaria3 replies 2 retweets 2 likes -
Replying to @TrendMicroRSRCH
@TrendLabs So no exploit but embedded file?@c_APT_ure@MenteBinaria1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@TrendLabs@MenteBinaria correct, no exploit!#malware embedded in RTF (or .doc) file, user needs to run it (just like in ZIP)1 reply 0 retweets 0 likes -
Replying to @c_APT_ure
@c_APT_ure Pretty lame tactic indeed. Thanks Tom, I'll check it out.@TrendLabs@MenteBinaria2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@c_APT_ure Honestly, I can't understand why .rtf, .cpl, .com and other odd creations still exist and work! :@1 reply 0 retweets 1 like
@MenteBinaria I can see use in all of these - unfortunately, so do the bad guys. @c_APT_ure
-
-
Replying to @bartblaze
@bartblaze@c_APT_ure But they're too old and totally replaceable IMHO.1 reply 0 retweets 0 likes -
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.