Fin7 is a cybercrime group that employs spear phishing attacks to deliver malware that uses fileless malware techniques, sophisticated evasions and persistence. They mostly target the financial sector. In this blog, we are going to take a high-level look at one such sample seen in the wild, which employs several layers of obfuscated JScript, powershell and DLL embedded within a Microsoft Word document. The sample analyzed has the MD5 hash 29a3666cee0762fcd731fa663ebc0011. Through a series of deeply embedded base64 encoded scripts, obfuscated code and use of powershell, this strain achieves stealth and evasion. The document arrives as an email attachment in…
Healthy growth is something every company strives for. As with human development, the rate of growth can impact a business’s well-being: Grow too slowly, and the business can become stagnant or obsolete. Grow too quickly, and the business will experience growing pains that could threaten its overall health. In every sector, managing growth effectively can ensure longevity for the business. In the healthcare space, however, it can mean the difference between life and death—for the business and its customers. As a medical practice or healthcare facility expands, either organically or through acquisition, is its existing network capable of handling the…
Several Security Vulnerability have been patched in recently in Apache Tomcat. The list of fixed flaws recently addressed also included code execution vulnerabilities. Apache Tomcat is the most widely used web application server, with over one million downloads per month and over 70% penetration in the enterprise datacenter. The Apache Tomcat development team publicly disclosed the presence of a remote code execution vulnerability, tracked as CVE-2017-12617, affecting the popular web application server. The Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 are affected. The vulnerability is classified as “important” severity, has been…
Banks and financial institutions are more technology-reliant than ever before as they seek to be more customer-centric in their offerings. As such, the branch plays a major role in their quest for customer service excellence, giving customers a place to conduct transactions, receive personalized attention from bank reps and take advantage of next-generation technologies such as video how-to’s or chatbots to further enhance their banking experience. Some banks have taken customer-centricity one step further, opening their branches to act as neighborhood community centers or gathering places for organizations. Some bank branches make their videoconferencing systems available for customers to use,…
Apache’s gaps has been in news for quite a while, and this has led to the massive milestone of Equifax being compromised to the tune of 143 million records. This has been a difficult year for Apache, with so many vulnerabilities being reported. Refer to the link for a list of Apache vulnerabilities reported in 2017. Though previous years also accounted for large chunks of Apache vulnerability, this year it has been in news for two particular vulnerabilities, CVE-2017-5638 (which led to the compromise of user data through the Equifax breach) and CVE-2017-9805 (due to the fact that the public…
In our last post, we talked about the benefits of network function virtualization (NFV) for managed service providers. Taking a step further, we’ll now examine how providers that deploy NFV can further benefit from this rapidly growing industry trend of evolving previously hardware-centric networks by leveraging security technologies into software-based services. A core element of NFV is the virtualized network function (VNF), which is a software-based or virtualized version of a specific function such as a next-generation firewall (NGFW). Employing VNFs goes far beyond just converting from point hardware to virtualized software instances such as an NGFW. VNFs, which are…
In February, Versa announced major feature and performance enhancements to the software-defined security (SD-Security) used in its branch security offering. The enhanced SD-Security enables service providers and large enterprise IT teams to deliver a wide range of layered security services for branch offices, including advanced functions such as domain name system (DNS) security and secure web gateways (SWG), coupled with full multi-tenancy. Analysts Understand the Need for SD-Security According to industry analysts, branch offices are increasingly becoming a targeted point of entry into corporate networks, with attack volume growing more than 500 percent over the last three years. Gartner’s 2012…
Industry analysts have noted that branch offices are increasingly becoming a targeted point of entry into corporate networks, with attack volume growing more than 500 percent over the last three years. This is due in large part to three major trends/issues: the increasing adoption of cloud- vs. data center-hosted apps, the adding of Internet circuits as additional (and lower cost) connectivity for branch offices, and the largely unchanged and static architecture of branch office networks. The latter point is compounded by the need to deploy a multitude of siloed security appliances and/or software packages to enforce any kind of defense-in-depth…
Subscribe to the Versa Blog