CVE-2014-1761
published 2014-03-25CVE-2014-1761: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation…
PriorityP187high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-08-15
Exploited in the wild
EPSS
77.46%
99.5th percentile
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SID 24974
snort↗
SID 24975
snort↗
SID 30497
snort↗
SID 30498
snort↗
SID 30499
snort↗
SID 30500
snort↗
SID 30501
snort↗
SID 30502
snort↗
SID 30508
snort↗
SID 30509
- →Detect RTF files with invalid 'listoverridecount' values — only legal values are 0, 1, or 9; any other value is indicative of CVE-2014-1761 exploitation. ↗
- ·The ClamAV signature for CVE-2012-2539/CVE-2014-1761 was temporarily converted to a PUA (Potentially Unwanted Application) signature due to false positives from legitimate RTF generators that produce non-standard listoverridecount values; tuning may be required. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Word Memory Corruption Vulnerability
cisa·2022-02-15·CVSS 7.8
CVE-2014-1761 [HIGH] CWE-119 Microsoft Word Memory Corruption Vulnerability
Vulnerability: Microsoft Word Memory Corruption Vulnerability
Affected: Microsoft Word
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-1761
Remediation Due Date: 2022-08-15
GHSA
GHSA-f32r-xw6q-p85m: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automati
ghsa_unreviewed·2022-05-14
CVE-2014-1761 [HIGH] CWE-119 GHSA-f32r-xw6q-p85m: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automati
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
VulnCheck
Microsoft Word Memory Corruption Vulnerability
vulncheck·2014·CVSS 7.8
CVE-2014-1761 [HIGH] CWE-119 Microsoft Word Memory Corruption Vulnerability
Microsoft Word Memory Corruption Vulnerability
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
Affected: Microsoft Word
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2014-1761; https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2014/2014.07.11.Pitty_Tiger/Pitty_Tiger_Final_Report.pdf; https://www.mcafee.com/blogs/other-blogs/mcafee-labs/targeted-attacks-on-french-company-exploit-multiple-word-vulnerabilities/; https://www.fireeye.com/blog/threat-research/2014/07/spy-of-the-tiger.html; https://2014.zeronights.org/assets/files/slides/roaming_tiger_zeronights_2014.pdf; https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2014/b
Suricata
ET MALWARE W32/Antifulai.APT CnC Beacon 1
suricata·2014-05-20
CVE-2014-1761 ET MALWARE W32/Antifulai.APT CnC Beacon 1
ET MALWARE W32/Antifulai.APT CnC Beacon 1
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Antifulai.APT CnC Beacon 1"; flow:established,to_server; http.method; content:"GET"; http.uri; content:".php?secue="; fast_pattern; content:"&pro="; content:"|2c|"; distance:0; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,secureworks.com/resources/blog/research/apt-campaign-leverages-the-cueisfry-trojan-and-microsoft-word-vulnerability-cve-2014-1761/; reference:md5,1c29b24d4d4ef7568f519c470b51bbed; classtype:targeted-activity; sid:2018631; rev:7; metadata:attack_target Client_Endpoint, created_at 2014_05_20, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_21, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration,
Exploit-DB
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
exploitdb·2014-04-10
CVE-2014-1761 Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 "MS14-017 Microsoft Word RTF Object Confusion",
'Description' => %q{
This module creates a malicious RTF file that when opened in
vulnerable versions of Microsoft Word will lead to code execution.
The flaw exists in how a listoverridecount field can be modified
to treat one structure as another.
This bug was originally seen being exploited in the wild starting
in April 2014. This module was created by reversing a public
malware sample.
},
'Author' =>
[
'Haifei Li', # vulnerability analysis
'Spencer McIntyre',
'unknown' # malware author
],
'License' =
Metasploit
MS14-017 Microsoft Word RTF Object Confusion
metasploit
MS14-017 Microsoft Word RTF Object Confusion
MS14-017 Microsoft Word RTF Object Confusion
This module creates a malicious RTF file that when opened in vulnerable versions of Microsoft Word will lead to code execution. The flaw exists in how a listoverridecount field can be modified to treat one structure as another. This bug was originally seen being exploited in the wild starting in April 2014. This module was created by reversing a public malware sample.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-10
ModifiedElephant APT and a Decade of Fabricating Evidence
## ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure o
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-09
ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
- Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
- ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
- ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
- ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
- The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure overlaps that allow us to connect long periods of previou
Unit42
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
blogs_unit42·2016-03-14
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
Unit 42 has collected multiple spear phishing emails, weaponized document files, and payloads that targeted various offices of the Mongolian government during the time period of August 2015 and February 2016. The phishing emails and document files leveraged a variety of geopolitically sensitive subject matters as attractive lures, such as events in Beijing, the Dalai Lama, North Korea relations, the Zika virus, and various legitimate appearing announcements. As we began to analyze and tear down the various samples we collected, we found significant overlaps with previously reported and documented adversary groups, attack campaigns, and their toolsets, exemplifying the concept of the Digital Quartermaster.
The concept of the Digital Quartermaster is not a particularly new one; it is the id
Unit42
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
blogs_unit42·2016-03-14
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
Threat Research Center
Threat Research
Malware
## Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
Josh Grunzweig
Robert Falcone
Bryan Lee
Published: March 14, 2016
Malware
Threat Research
BBSRAT
Cmstar
Digital Quartermaster
Mongolia
Unit 42 has collected multiple spear phishing emails, weaponized document files, and payloads that targeted various offices of the Mongolian government during the time period of August 2015 and February 2016 . The phishing emails and document files leveraged a variety of geopolitically sensitive subject matters as attractive lures, such as events in Beijing, the Dalai Lama, North Korea relations, the Zika virus, and various legitimate appearing announcements. As we began to analyze and tear down the variou
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
Unit42
Super Tuesday: A Patch Tuesday We Won’t Forget
blogs_unit42·2014-10-15·CVSS 7.8
[HIGH] Super Tuesday: A Patch Tuesday We Won’t Forget
Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities, Adobe issued updates for Flash and ColdFusion, and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that three of the Microsoft vulnerabilities were being exploited in targeted attack campaigns.
### Sandworm
The first to drop was the Sandworm Campaign, a report from iSight partners, which described attacks on European and American targets in the month of August using new versions of the BlackEnergy bot, but the group behind the attacks has been operating since at least 2009. The biggest news here was the group’s exploitation of a “new” vulnerability in Windows, CV
Unit42
Super Tuesday: A Patch Tuesday We Won’t Forget
blogs_unit42·2014-10-15·CVSS 7.8
[HIGH] Super Tuesday: A Patch Tuesday We Won’t Forget
## Super Tuesday: A Patch Tuesday We Won’t Forget
Ryan Olson
Published: October 15, 2014
Threat Research
Vulnerabilities
BlackEnergy
ISight
Microsoft
Microsoft Security Bulletin
Patch Tuesday
PowerShell Empire
Sandworm
Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities , Adobe issued updates for Flash and ColdFusion , and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that three of the Microsoft vulnerabilities were being exploited in targeted attack campaigns.
## Sandworm
The first to drop was the Sandworm Campaign , a report from iSight partners, which described attacks on European and American t
Talos
CVE-2014-1761, Oh did you mean CVE-2012-2539?
blogs_talos·2014-04-08·CVSS 8.8
CVE-2014-1761 [HIGH] CVE-2014-1761, Oh did you mean CVE-2012-2539?
When the VRT first received word of a new Microsoft Word 0-day I anxiously awaited details and the ever important hash of the in-the-wild exploit to be able to research it and provide coverage through Snort, ClamAV and the FireAmp suite of products. I was especially interested when word came that it was an RTF vulnerability, as I have spent a lot of time looking at high profile RTF vulnerabilities such as the ever popular CVE-2012-0158.
When the in the wild sample finally arrived I thought someone was playing an early April Fool's joke on us: I knew this vulnerability already. More than that, I had written the coverage for this almost a year and half ago! The vulnerability appeared to be CVE-2012-2539, which was released December 11th 2012 as Microsoft Security Bulletin MS12-079. I checke
Talos
Microsoft Update Tuesday: April 2014, two final XP and Office 2003 fixes
blogs_talos·2014-04-08·CVSS 6.9
[MEDIUM] Microsoft Update Tuesday: April 2014, two final XP and Office 2003 fixes
## Microsoft Update Tuesday: April 2014, two final XP and Office 2003 fixes
It’s the last Microsoft Update Tuesday before the end-of-life of both Windows XP and Office 2003 and Microsoft is patching two vulnerabilities that also impact XP and two that also impact Office 2003 this month. All-in-all it’s a relatively light month this time around with only four bulletins covering eleven CVEs.
The first bulletin this month, MS14-017 , deals with Word and covers three CVEs. One fix is for a 0-day vulnerability, CVE-2014-1761, that Microsoft previously addressed in advisory 2953095 and a “Fix it” that disables support for RTF completely in Word. The vulnerability results from an incorrect “listoverridecount” value in an “overridetable” structure in the RTF file.This value is not properly check
Talos
Microsoft Update Tuesday: April 2014, two final XP and Office 2003 fixes
blogs_talos·2014-04-08·CVSS 6.9
CVE-2014-1761 [MEDIUM] Microsoft Update Tuesday: April 2014, two final XP and Office 2003 fixes
It’s the last Microsoft Update Tuesday before the end-of-life of both Windows XP and Office 2003 and Microsoft is patching two vulnerabilities that also impact XP and two that also impact Office 2003 this month. All-in-all it’s a relatively light month this time around with only four bulletins covering eleven CVEs.
The first bulletin this month, MS14-017, deals with Word and covers three CVEs. One fix is for a 0-day vulnerability, CVE-2014-1761, that Microsoft previously addressed in advisory 2953095 and a “Fix it” that disables support for RTF completely in Word. The vulnerability results from an incorrect “listoverridecount” value in an “overridetable” structure in the RTF file.This value is not properly checked by Word and setting it to an invalid value causes a type confusion bug, whi
Talos
CVE-2014-1761, Oh did you mean CVE-2012-2539?
blogs_talos·2014-04-08·CVSS 8.8
CVE-2014-1761 [HIGH] CVE-2014-1761, Oh did you mean CVE-2012-2539?
## CVE-2014-1761, Oh did you mean CVE-2012-2539?
When the VRT first received word of a new Microsoft Word 0-day I anxiously awaited details and the ever important hash of the in-the-wild exploit to be able to research it and provide coverage through Snort, ClamAV and the FireAmp suite of products. I was especially interested when word came that it was an RTF vulnerability, as I have spent a lot of time looking at high profile RTF vulnerabilities such as the ever popular CVE-2012-0158.
When the in the wild sample finally arrived I thought someone was playing an early April Fool's joke on us: I knew this vulnerability already. More than that, I had written the coverage for this almost a year and half ago! The vulnerability appeared to be CVE-2012-2539, which was released December 11th 2012
Crowdstrike
CVE-2014-1761: STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 0
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] CVE-2014-1761: STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 0
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler discovers MS Office Vulnerability | 03-25-2014
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler discovers MS Office Vulnerability | 03-25-2014
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
CVE-2014-1761: How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] CVE-2014-1761: How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Threat Intel
Inception (Inception, Inception Framework, Cloud Atlas)
threat_intel·CVSS 8.8
[HIGH] Inception (Inception, Inception Framework, Cloud Atlas)
# Threat Actor Profile: Inception
ATT&CK ID: G0100
Also known as: Inception, Inception Framework, Cloud Atlas
Suspected origin: Russia
## Overview
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)
## Techniques (TTPs)
### Resource Development
- T1588.002 Tool
Usage: Inception has obtained and used open-source tools such as LaZagne.(Citation: Kaspersky Cloud Atlas August 2019)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: Ince
arXiv
Bayesian and Multi-Objective Decision Support for Real-Time Incident Mitigation in Critical Infrastructure
arxiv_fulltext·2026-02-18
Bayesian and Multi-Objective Decision Support for Real-Time Incident Mitigation in Critical Infrastructure
frontmatter
Bayesian and Multi-Objective Decision Support for Real-Time Incident Mitigation in Critical Infrastructure
Shaofei Huang
Christopher M. Poskitt
Lwin Khin Shar
Singapore Management University, Singapore
## Abstract
Critical infrastructure increasingly relies on interconnected cyber-physical systems whose security incidents can escalate rapidly into safety and operational failures. Existing decision-support approaches struggle to support real-time incident response because they rely on static assumptions, incomplete vulnerability data, and single-objective risk models that do not adequately capture trade-offs between attack likelihood, impact severity, and system availability. This paper proposes a real-time, adaptive decision-support framework for incident mitigation in cri
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
An Analysis of Malware Trends in Enterprise Networks
arxiv_fulltext·2019-10-01
An Analysis of Malware Trends in Enterprise Networks
An Analysis of Malware Trends in Enterprise Networks
An Analysis of Malware Trends in Enterprise Networks
Abbas Acar1,
Long Lu 2,
A. Selcuk Uluagac 1,
Engin Kirda 2
A. Acar et al.
Florida International University
\aacar001,suluagac\@fiu.edu
Northeastern University
[email protected],[email protected]
## Abstract
We present an empirical and large-scale analysis of malware
samples captured from two different enterprises from 2017 to early 2018. Particularly, we perform threat vector, social-engineering, vulnerability and
time-series analysis on our dataset. Unlike existing malware studies, our
analysis is specifically focused on the recent enterprise malware samples. First
of all, based on our analysis on the combined datasets of two enterprises, our
results confirm the general consensu
arXiv
A Survey of Stealth Malware: Attacks, Mitigation Measures, and Steps Toward Autonomous Open World Solutions
arxiv_fulltext·2016-12-02
A Survey of Stealth Malware: Attacks, Mitigation Measures, and Steps Toward Autonomous Open World Solutions
A Survey of Stealth Malware Attacks, Mitigation Measures, and Steps Toward Autonomous Open World Solutions
Ethan M. Rudd,
Andras Rozsa,
Manuel G\"unther,
and Terrance E. Boult
E. Rudd, A. Rozsa, M. G\"unther, and T. Boult are with the Vision and Security Technology (VAST) Lab, Department
of Computer Science, University of Colorado at Colorado Springs.
E-mail: see http://vast.uccs.edu/contact-us
Manuscript received February 19, 2016. Revised August 21, 2016. Revised September 16th, 2016 . Accepted December 1, 2016.
PRE-PRINT OF MANUSCRIPT ACCEPTED TO IEEE COMMUNICATION SURVEYS & TUTORIALS
Shell et al.: Bare Advanced Demo of IEEEtran.cls for IEEE Computer Society Journals
## Abstract
As our professional, social, and financial existences become increasingly digitized and as our governme
http://technet.microsoft.com/security/advisory/2953095https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-017http://technet.microsoft.com/security/advisory/2953095https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-017https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-1761
2014-03-25
Published
2022-02-15
Added to CISA KEV
Exploited in the wild