Threat Research

A Brazilian Trojan Using A Jar File, VB Scripts And A DLL For Its Multi-Stage Infection

As part of Fortinet’s continued efforts to protect its customers, we carry out a variety of tests to improve the detection of malicious content, whether it’s file or network related. While checking out some HTTPS phishing websites last month, one URL stood out. It wasn’t a phishing site, but it downloaded a file called (which is detected as “Java/Banload.BD!tr” by Fortinet AntiVirus service) from a file sharing website. The compressed file also contained a Jar that downloaded additional files,...

By Lilia Elena Gonzalez MedinaOctober 14, 2016

Industry Trends

A Crash Course In DLL Hijacking

Overview This week, we heard a lot about a DLL hijacking vulnerability from the security community. It began with a 0-day DLL hijacking in Microsoft Office which was discovered by an independent security researcher named Parvez Anwar. Shortly after, the website published an article detailing this kind of attack and discussing the vast potential attack surface associated with DLLs and OLE. A dynamic link library (DLL) is a basic component in the Windows operating system. Certain DLLs will be loaded into Windows applications...

By Tien PhanDecember 10, 2015