Thursday, January 28, 2016

Trust Barracuda?

Yes... we agree that Barracuda is "cost effective".  You too could create cost effective solutions if you leveraged open source tools.  However, the question needs to be asked, are you willing to reduce your risk posture to save a few bucks?  Case in point:

M$ Word file started propagating across the Internet with malicious macros at ~7:45amCST.  This file is actually a Dropper File, as shown via this Forcepoint File Sandbox Report, which is attempting to infect your local files and phone home to a website in the US:


What is the Anti-Virus Coverage Rate you may ask for this Dropper File?  Not good... only 5 companies currently detect it:


OK... lets assume your security controls have not blocked the download of the dropper, is your Barracuda Solution going to protect you from the download of the actual payload?  Ummm... no:


In summary, please contact ESPO Systems if you'd like to implement controls to block the attack across the entire Kill Chain.

Wednesday, January 13, 2016

Symantec + Cisco = Bad Day

Do you have Symantec's AV + Cisco's Web Gateway?  If so, you may be in for a bad day.  Why?  Malware is currently working it's way around the Internet that neither vendor is protecting against:

Per this Raytheon|Websense File Sandbox Report, a malicious Word Document is being propagated that is actually a Dropper File for Dridex.  If you are hoping Symantec will protect your IT Assets against this threat... you will be disappointed:


Next, assuming the Dropper File was not detected, it's now downloading additional malware from a website on the GoDaddy domain:



If you are hoping your Cisco / IronPort Web Gateway is protecting your IT Assets... you will be disappointed again:


In summary, your security solution needs to be holistic... you need to have visibility into all 7 steps of the Kill Chain.  Call ESPO Systems for a free consultation.