all InfoSec news
[SANS ISC] Malicious Code Can Be Anywhere
Malware Analysis, News and Indicators - Latest topics malware.news
Today, I published the following diary on isc.sans.edu: “Malicious Code Can Be Anywhere“:
My Python hunting rules reported some interesting/suspicious files. The files are named with a “.ma” extension. Some of them have very low VT scores. For example, the one with a SHA256 dc16115d165a8692e6f3186afd28694ddf2efe7fd3e673bd90690f2ae7d59136 has a score of 15/59.
The “.ma” extension refers to animation projects created by Autodesk Maya, a 3D modeling and animation program. The files are typically ASCI files that describe the 3D scenes. …
code edu extension files hunting hunting rules isc low malicious python rules sans sans.edu sans isc score sha256