Security

FortinetSecurity

Teardown of Android/Ztorg (Part 2)

Credit to Author: Axelle Apvrille| Date: Wed, 15 Mar 2017 08:21:55 -0700

In the part 1 of this blog, we saw that Android/Ztorg.AM!tr silently downloads a remote encrypted APK, then installs it and launches a method named c() in the n.a.c.q class. In this blog post, we’ll investigate what this does. This is the method c() of n.a.c.q: This prints "world," then waits for 200 seconds before starting a thread named n.a.c.a. I'll spare you a few hops, but among the first things we notice is that the sample uses the same string obfuscation routine, except this time it is not…

Read More
FortinetSecurity

Teardown of a Recent Variant of Android/Ztorg (Part 1)

Credit to Author: Axelle Apvrille| Date: Wed, 15 Mar 2017 08:20:51 -0700

Ztorg, also known as Qysly, is one of those big families of Android malware. It first appeared in April 2015, and now has over 25 variants, some of which are still active in 2017. Yet, there aren't many technical descriptions for it – except for the initial Ztorg.A sample – so I decided to have a look at one of the newer variants, Android/Ztorg.AM!tr, that we detected on January 20, 2017. The sample poses a "Cool Video Player" and its malicious activity was so well hidden I initially thought I had run into…

Read More
SecurityTrendMicro

Five Questions with University of Florida Health

Credit to Author: Justin Foster| Date: Wed, 15 Mar 2017 13:00:48 +0000

With the growing number of threats, technologies, and responsibilities, security teams have no shortage of challenges they face daily. Now more than ever, it is important that security providers offer tools that work with these teams instead of against them; solutions that allow for opportunities in place of constraints. This is why customers were directly…

Read More
SecurityTrendMicro

Celebrating the One Year Anniversary of Acquiring TippingPoint

Credit to Author: Steve Quane| Date: Wed, 15 Mar 2017 12:00:35 +0000

The month of March marks the one year anniversary of Trend Micro closing our acquisition of TippingPoint from Hewlett Packard Enterprise (HPE). In that past year, we made a commitment to continue to innovate the TippingPoint solution while at the same time solidly executing for our customers and seamlessly continuing business operations. I’m pleased to…

Read More