<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Vesselin Bontchev</style></author><author><style face="normal" font="default" size="100%">Veneta Yosifova</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Analysis of the Global Attack Landscape Using Data from a Telnet Honeypot</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">botnet</style></keyword><keyword><style  face="normal" font="default" size="100%">honeypot</style></keyword><keyword><style  face="normal" font="default" size="100%">malware</style></keyword><keyword><style  face="normal" font="default" size="100%">Mirai</style></keyword><keyword><style  face="normal" font="default" size="100%">Telnet</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">264-282</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">After the Mirai botnet was discovered in 2016, we decided to set up a honeypot for it and see how widespread it really was. In the process we discovered that many other malicious attackers were using similar attack vectors. This paper outlines the process we went through to pick the right honeypot and the supporting infrastructure (backend database, visualization). This article presents the statistics we have collected from this honeypot, the conclusions we have drawn from these statistics, as well as the tools we have developed to share the data. </style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">264</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>47</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Veneta Yosifova</style></author><author><style face="normal" font="default" size="100%">Vesselin Bontchev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Possible Instant Messaging Malware Attack Using Right-to-Left Unicode Overriding Characters</style></title><secondary-title><style face="normal" font="default" size="100%">DIGILIENCE 2019</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">file name obfuscation</style></keyword><keyword><style  face="normal" font="default" size="100%">Instant messaging malware attack</style></keyword><keyword><style  face="normal" font="default" size="100%">Microsoft Skype for Linux</style></keyword><keyword><style  face="normal" font="default" size="100%">right-to-left Unicode override</style></keyword><keyword><style  face="normal" font="default" size="100%">Wine</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2-4 October</style></date></pub-dates></dates><pub-location><style face="normal" font="default" size="100%">Sofia, Bulgaria</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;The right-to-left special Unicode character has a legitimate use for languages that are transcribed in a right-to-left direction or in an environment that combines both right-to-left and left-to-right languages, like web pages, emails, desktop documents and text messages. These writing systems include right-to-left languages such as Persian, Arabic and Hebrew. The &amp;ldquo;right-to-left&amp;rdquo; attacks have been used for many years for malicious purposes, mostly in email communications. Early in 2018, Kaspersky Lab published an article described a vulnerability in the Windows client of the popular instant messenger Telegram. This vulnerability uses the Unicode &amp;ldquo;right-to-left&amp;rdquo; character to obfuscate the name of the malware file. This paper describes a possible attack that we discovered. It uses a combination of the &amp;ldquo;right-to-left&amp;rdquo; override attack and instant messaging malware attack and presents a realistic threat for another widely used messenger - Microsoft&amp;rsquo;s Skype for Linux. The purpose for conducting this research was to describe an exploit that we discovered and to warn the people who use this communication application about it, as well as to appeal to the producer for fixing it. Additionally, it is important to emphasize that the attack scenario developed by us also impacts other applications that allow file transfer (e.g., e-mail clients) and run on Linux systems with Wine installed.&lt;/p&gt;&lt;p&gt;This paper is included in the program of &lt;a href=&quot;https://digilience.org&quot;&gt;DIGILIENCE 2019&lt;/a&gt; and will be published in the post-conference volume.&lt;/p&gt;</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>47</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Vesselin Bontchev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A VBA P-Code Disassembler</style></title><secondary-title><style face="normal" font="default" size="100%">DIGILIENCE 2019</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Macros</style></keyword><keyword><style  face="normal" font="default" size="100%">malware</style></keyword><keyword><style  face="normal" font="default" size="100%">Microsoft Office</style></keyword><keyword><style  face="normal" font="default" size="100%">VBA</style></keyword><keyword><style  face="normal" font="default" size="100%">Visual Basic for Applications</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2-4 October</style></date></pub-dates></dates><pub-location><style face="normal" font="default" size="100%">Sofia, Bulgaria</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;Recently, we have observed a significant increase in the frequency with which Microsoft Office macros are being used as an attack vector. Microsoft Office uses a macro programming language called Visual Basic for Applications (VBA), which is powerful enough to do whatever the attacker needs. Usually, the malicious VBA macros are used to download the second stage of the malware (ransomware, banking Trojan, backdoor, etc.). They can be relatively small and are easy to modify or even to completely rewrite them each time, thus making them difficult to detect at the perimeter defenses (e.g., with an e-mail scanner) with known-malware detection tools.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; So far, we have seen malicious VBA macros being distributed with Microsoft Word, Excel, PowerPoint, Access, Visio, Project and Publisher documents. Microsoft Office has built-in protections against execution of foreign macros, but unless properly administered, they are easy for the user to disable and the malicious documents usually use some form of social engineering to convince the user to do so. Therefore, we need proper tools for inspecting the macro content of the received documents, in order to decide whether it contains any malicious code. During our research we have discovered that the publicly available tools lack the capability to discover all forms in which a malicious macro can exist. We have applied our findings from reverse-engineering the formats of Microsoft Office documents and have created a tool, which allows disassembling of the p-code into which VBA is compiled.&lt;/p&gt;&lt;p&gt;This paper is included in the program of &lt;a href=&quot;https://digilience.org&quot;&gt;DIGILIENCE 2019&lt;/a&gt; and will be published in the post-conference volume.&lt;/p&gt;</style></abstract></record></records></xml>