Ursnif maldocs now checking for hex chars before the extension and will not proceed if so. (think of sha1.doc): https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques …pic.twitter.com/fpapgTr7pP
2:47 AM - 22 Sep 2016
0 replies
10 retweets
8 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.