View Topics

Research
12 minutes
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families
Attacks from the online groups Lazarus, Silent Chollima, Group 123, Hidden Cobra, DarkSeoul, Blockbuster, Operation Troy, and 10 Days of Rain are believed to have come from North Korea. But how can we know with certainty? And what connection does a DDoS and disk-wiping attack from July 4, 2009, have with WannaCry?

Research
6 minutes
Mitigating Emotet, The Most Common Banking Trojan
The popular banking trojan Emotet is constantly evolving to evade detection. Stripped down to its genetic core, malware analysis reveals Emotet's code remains largely the same from generation to generation.

Malware Analysis
5 minutes
Product Updates for June 2018
We’ve recently added to our product, support for Dynamic Execution and Static Extraction and we wanted our user interface to reflect these additions.

Research
3 minutes
Digital Certificates- When the Chain of Trust is Broken
As stated in a previous blog entry, it is common for malware authors to sign malicious files with “legitimate” digital certificates in order to bypass security products.

Malware Analysis
8 minutes
Executable and Linkable Format 101 Part 3: Relocations
This post is part of Intezers blog series about executable and linkable formats. In this post, we will introduce the concept of ELF relocations and their relationship with symbols. Later we will explain more advanced concepts, such as dynamic linking.

Malware Analysis
3 minutes
Unpacking reveals a file’s true DNA
After launching Intezer community edition in November 2017, we noticed that many of our users uploaded packed samples. Yet packed files don’t reveal the true ‘DNA’ of the files.

Research
2 minutes
Yet Another Distraction? A New Version of North Korean Ransomware Hermes Has Emerged

Malware Analysis
8 minutes
Executable and Linkable Format 101. Part 2: Symbols
In our previous post, we focused on understanding the relationship between sections and segments, which serve as the foundation for understanding the ELF file format.

Research
6 minutes
Executable and Linkable Format 101 - Part 1 Sections and Segments
Let's dive into Executable and Linkable Format files. Learn about ELF relocation and segments, and how cyber attacks can use this file format.

Malware Analysis
3 minutes
Don’t Be Fooled By Malware Signed with Stolen Certificates
Recent research conducted by the Cyber Security Research Institute (CSRI) demonstrates how easy and common it is for threat actors to purchase stolen digital certificates in order to bypass security solutions.

Research
2 minutes
IcedID Banking Trojan Shares Code with Pony 2.0 Trojan
IBM X-Force recently released an excellent report on a new banking trojan named IcedID that is being distributed using computers already infected with Emotet. We took the MD5 of one of the droppers from the IBM report and extracted the payload.

Research
2 minutes
Silence of the Moles
Kaspersky Labs published a technical analysis of a new malware, Silence that is aimed at attacking financial institutions. After uploading the loader of this malware to Intezer Analyze™, we have found a possible connection through code reuse to the loader of another campaign of malware.





