Category: Heuristics
MITRE ATT&CK® Technique: T1684/002/
Email headers can reveal important clues about whether a message is legitimate or suspicious. One header that is especially useful in phishing investigations is the Reply-To header.
In legitimate emails, the Reply-To addresses often match or belong to related domains. However, attackers may abuse this mechanism to make an email look like it came from a trusted sender, while redirecting replies to an address they control. If the domain of that header field was also registered recently, the risk increases. Newly registered domains are often used in phishing campaigns because attackers can quickly create disposable infrastructure for impersonation, fraud, or credential theft.
This pattern is a classic social engineering technique. Instead of relying on malware execution, the attacker tries to manipulate the recipient into trusting the message and replying to the wrong party. This can be used to continue a conversation, request sensitive information, redirect payments, or make a fraudulent business request appear legitimate.
Detecting Microsoft device enrollment links
Category: Heuristics
Recently, we observed a phishing page containing a Microsoft device enrollment link. When clicked on a Windows system, this link can open the Microsoft device enrollment application. In legitimate environments, device enrollment is a common IT process. Organizations use it to connect devices to work resources, apply management policies, or other mobile device management solutions.
In a phishing scenario, however, the same mechanism can be abused. A malicious page may instruct the user to click a button, open the device enrollment flow, and follow the displayed steps. If the user completes the process, the device may become enrolled in a management context controlled or abused by the attacker.
This behavior requires careful scoring. A Microsoft device enrollment link is not automatically malicious because the same flow is used by legitimate IT departments. For this reason, VMRay’s new VTI is designed to detect the presence of the enrollment link in the DOM dump as an important signal, rather than treating it as a high-confidence malicious indicator on its own. VMRay can then combine this signal with other analysis results and detection technologies to determine whether the observed behavior is part of a legitimate workflow, a phishing attempt, or a broader account and device compromise scenario.
Detecting malicious documents based on multiple VTI signals
Category: Heuristics
Malicious documents are still a common part of phishing and malware delivery chains. They may contain macros or embedded logic designed to execute commands, contact external infrastructure, write files, or prepare the system for a follow-on payload.
However, document-based malware does not always complete its full execution chain during analysis. In some cases, a macro may fail to execute correctly, require additional user interaction, depend on a specific Office version, or expect conditions that are not present in the analysis environment. As a result, the document may not make a network connection or download its final payload, even though the macro code itself still shows suspicious intent.
To improve detection in these cases, VMRay introduced a new meta VTI for malicious documents. A meta VTI acts as an umbrella detection: instead of relying on one single behavior, it combines multiple smaller VTI signals that each capture a specific suspicious technique.
For example, one supporting VTI triggers when an Office macro performs file operations. File I/O refers to file input and output, meaning that the macro can read from files or write files to disk. In a malicious document, this behavior may be used to extract encoded data, decode it, save it as a script or executable, and then run it. This behavior is just one case of the lower-level signals that can contribute to a meta VTI. When several suspicious macro behaviors are observed together, multiple supporting VTIs may trigger, providing stronger evidence that the document was designed for malicious activity.
Detecting system time queries
Category: Discovery
MITRE ATT&CK® Technique: T1124
System time discovery is a simple behavior, but it can still provide useful context during malware analysis. This VTI triggers when a process retrieves information about the system time or time zone.
In legitimate scenarios, applications may query the system time for many routine purposes. For malware, however, system time can be useful for several reasons. A threat may check the local time or time zone to understand where the system is located, determine whether execution should continue, delay activity until a specific time, or compare expected timing behavior with what it observes in the environment. For example, malware may query the system time to support behaviors such as:
- Checking the victim’s time zone
- Delaying execution
- Running only during business hours
- Detecting unusual sandbox timing
On its own, querying system time is usually not enough to prove malicious intent. However, when system time discovery appears together with other suspicious behaviors, it can become an important supporting signal.
Smart Link Detonation
One of the key component of the VMRay Platform, Smart Link Detonation (SLD), is an automatic evaluation and detonation of hyperlinks embedded in emails and documents. We recently made one important improvement to our SLD feature to keep pace with evolving threats:
New rule for detecting ad-click subdomains
We added a new Smart Link Detonation rule to detect generic domains that use ad-click-style subdomains.
Ad-click infrastructure is commonly used in legitimate online advertising to track when users click on ads, measure campaign performance, and forward users to the intended destination. In these flows, a click may pass through one or more tracking or redirect domains before reaching the final website.
In phishing scenarios, attackers can abuse similar-looking infrastructure or naming patterns to hide the real destination of a link. Instead of sending the user directly to a phishing page, the link may first pass through a generic domain or forwarding point that resembles advertising or click-tracking behavior.
This technique can make malicious links appear less suspicious and can help attackers obscure the final landing page. By detecting ad-click-style subdomains, VMRay’s Smart Link Detonation provides better visibility into redirect chains and helps identify links that may be using forwarding behavior to conceal phishing activity.
Computer Vision
VMRay uses Computer Vision to extract and interpret visual content from analyzed samples. This includes text and brand indicators found in images, screenshots, and QR codes, using Optical Character Recognition (OCR) to detect social engineering techniques commonly used in phishing campaigns.
Improved PayPal brand detection
As part of our latest detection updates, we improved our Computer Vision capabilities to scan images and screenshots for brand-specific indicators. This gives our Platform products more context when analyzing suspicious content and helps strengthen related VTIs and Smart Link Detonation results.
One recent example involved samples impersonating PayPal, where attackers presented content that looked like PayPal invoices. These lures were designed to make recipients trust the message, open linked content, or continue to a phishing page. This allows the VMRay Platform to better recognize PayPal-themed phishing content, even when the brand appears inside an image or screenshot rather than as plain text.
AdaptixC2
AdaptixC2 is a highly modular post-exploitation and adversarial emulation framework mainly used for penetration testing. Threat actors have started abusing it for malicious purposes due to its open-source nature. The framework supports fully encrypted communication and several listener/beacon types.
YARA Rules Update
Our hunt for new, undetected malware samples never stops. In the past month, we added many fresh YARA rules to strengthen detection across a wide range of threats. This month, we’re continuing that momentum with 30+ new rules, focused on delivering a solid drop of high-quality detections. Here’s a quick preview of what we’re shipping this month.
New YARA detections for:
Spyware:
Botnet:
Loaders:
RATs:
-
SeroRAT
-
LimeRAT
-
PulsarRAT
-
Overlord RAT
-
PackClientRAT
RMMs:
Backdoors:
Ransomware:
Phishing:
New YARA signatures for:
Trojans:
Other:
New YARA signatures for: