{"id":17540,"date":"2020-01-24T10:52:20","date_gmt":"2020-01-24T18:52:20","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2020\/01\/24\/news-11275\/"},"modified":"2020-01-24T10:52:20","modified_gmt":"2020-01-24T18:52:20","slug":"news-11275","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/01\/24\/news-11275\/","title":{"rendered":"VB2019 paper: Spoofing in the reeds with Rietspoof"},"content":{"rendered":"<p>The Rietspoof malware was first discovered by <em>Avast<\/em> researchers in August 2018 and publicly disclosed in a <a href=\"https:\/\/blog.avast.com\/rietspoof-malware-increases-activity\" target=\"_blank\">blog post<\/a> in February 2019.<\/p>\n<p>The multi-stage malware utilises different file types throughout its infection chain including in one stage a CAB file. Full details of the malware, including later discoveries, were revealed in a VB2019 paper by <em>Avast<\/em> researchers Jan Sirmer, Luigino Camastra and Adolf St\u0159eda.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"framed\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/1515\/7191\/2383\/Figure2.png\" alt=\"Figure2.png\" width=\"579\" height=\"139\" \/><\/p>\n<p>Today we publish the researchers&#8217; paper in both <a title=\"VB2019 paper: Spoofing in the reeds with Rietspoof\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/2020\/01\/vb2019-paper-spoofing-reeds-rietspoof\/\">HTML<\/a> and <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/magazine\/2019\/VB2019-Sirmer-etal.pdf\" target=\"_blank\">PDF <\/a>format, as well as the recording of the presentation given by Jan and Luigino in London.<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: center;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/lMXJiF4sKdQ\" frameborder=\"0\" width=\"100%\" height=\"420\" style=\"\"> <\/iframe><\/p>\n<p><em>The <a title=\"VB2020 call for papers - now open!\" href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/12\/vb2020-call-papers-now-open\/\">Call for Papers<\/a> for VB2020 in Dublin is open! Submit your abstract before 15 March for a chance to make it onto the programme of one of the most international threat intelligence conferences!<\/em><\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2020\/01\/vb2019-paper-spoofing-reeds-rietspoof\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.virusbulletin.com\/files\/1515\/7191\/2383\/Figure2.png\"\/><br \/>                                 In a VB2019 paper Avast researchers Jan Sirmer, Luigino Camastra and Adolf St\u0159eda revealed full details of the Rietspoof malware. Today we publish their paper and the recording of the presentation given by Jan and Luigino in London.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2020\/01\/vb2019-paper-spoofing-reeds-rietspoof\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-17540","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17540","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17540"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17540\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17540"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}