<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>AZORult on Untrusted Network</title>
    <link>https://untrustednetwork.net/en/tag/azorult/</link>
    <description>Recent content in AZORult on Untrusted Network</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>&amp;copy; Jan Kopriva 2015 - {year}</copyright>
    <lastBuildDate>Mon, 03 Feb 2020 07:45:10 +0100</lastBuildDate>
    <sy:updatePeriod>weekly</sy:updatePeriod>
    <sy:updateFrequency>weekly</sy:updateFrequency>
    
        <atom:link href="https://untrustednetwork.net/en/tag/azorult/index.xml" rel="self" type="application/rss+xml" />
    
    
    

      
      <item>
        <title>SANS ISC Diary - Analysis of a triple-encrypted AZORult downloader</title>
        <link>https://untrustednetwork.net/en/2020/02/03/sans-isc-diary-analysis-of-a-triple-encrypted-azorult-downloader/</link>
        <pubDate>Mon, 03 Feb 2020 07:45:10 +0100</pubDate>
        
        <atom:modified>Mon, 03 Feb 2020 07:45:10 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/02/03/sans-isc-diary-analysis-of-a-triple-encrypted-azorult-downloader/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center. In this one we take a look at analysis of an interesting malicious document which turned out to be AZORult downloader. What made it stand out - among its other aspects - were 3 layers of home-grown encryption&amp;hellip;
EDIT 04/02/2020: Tom from Threat Post liked the diary and wrote an article based on it - you may find it here.</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/forums/diary/Analysis+of+a+tripleencrypted+AZORult+downloader/25768/&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;. In this one we take a look at analysis of an interesting malicious document which turned out to be AZORult downloader. What made it stand out - among its other aspects - were 3 layers of home-grown encryption&amp;hellip;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;EDIT 04/02/2020: Tom from Threat Post liked the diary and wrote an article based on it - you may find it &lt;a href=&#34;https://threatpost.com/azorult-campaign-encryption-technique/152508/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>Malware</category>
            
          
            
              <category>Phishing</category>
            
          
            
              <category>AZORult</category>
            
          
            
              <category>Macro</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      

    
  </channel>
</rss>