Securing the .pl domain

Dissecting Smoke Loader

Data publikacji: 18/07/2018, Michał Praszmo

Smoke Loader (also known as Dofoil) is a relatively small, modular bot that is mainly used to drop various malware families. Even though it’s designed to drop other malware, it has some pretty hefty malware-like capabilities on its own. Despite being quite old, it’s still going strong, recently being dropped from RigEK and MalSpam campaigns. [...] Read more

Technical aspects of CTF contest organization

Data publikacji: 09/07/2018, Michał Leszczyński

CTF competitions often turn out to be a great amusement, but they also play a very important role in training of IT security specialists. Such kinds of challenges are challenging both to contestants and organizers. This article will describe organizational aspects related to such competitions, taking European Cyber Security Challenge 2018 qualifications as an example.
Read more

n6 released as open source

Data publikacji: 21/06/2018, pp

We are happy to announce that another system developed by our team, n6 (Network Security Incident eXchange), has been released to the community on an open source licence.
Read more

Backswap malware analysis

Data publikacji: 19/06/2018, Hubert Barc

Backswap is a banker, which we first observed around March 2018. It’s a variant of old, well-known malware TinBa (which stands for “tiny banker”). As the name suggests, it’s main characteristic is small size (very often in the 10-50kB range). In the summary, we present reasoning for assuming it’s the same malware.
Read more