June 20, 2023, 2:15 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Today, I published the following diary on isc.sans.edu: “Malicious Code Can Be Anywhere“:


My Python hunting rules reported some interesting/suspicious files. The files are named with a “.ma” extension. Some of them have very low VT scores. For example, the one with a SHA256 dc16115d165a8692e6f3186afd28694ddf2efe7fd3e673bd90690f2ae7d59136 has a score of 15/59.


The “.ma” extension refers to animation projects created by Autodesk Maya, a 3D modeling and animation program. The files are typically ASCI files that describe the 3D scenes. …

code edu extension files hunting hunting rules isc low malicious python rules sans sans.edu sans isc score sha256

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States