{"id":2549,"date":"2016-07-13T13:31:36","date_gmt":"2016-07-13T06:31:36","guid":{"rendered":"https:\/\/humanit.asia\/?p=2549"},"modified":"2019-07-22T14:22:36","modified_gmt":"2019-07-22T07:22:36","slug":"a-look-at-the-cerber-office-365-ransomware","status":"publish","type":"post","link":"https:\/\/old.humanit.asia\/th\/a-look-at-the-cerber-office-365-ransomware\/","title":{"rendered":"A Look at the Cerber Office 365 Ransomware"},"content":{"rendered":"<div>\n<p>Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at <a href=\"http:\/\/www.avanan.com\/resources\/attack-on-office-365-corporate-users-with-zero-day-ransomware-virus\">Avanan<\/a>), and the culprit was a new variant of the Cerber ransomware discovered earlier this year. As with the other Zero-day threats that have been popping-up like mushrooms of late, the main methods of infection is through the use of Office\u00a0macros.<\/p>\n<p>This blog provides an analysis on the Cerber variant using traditional reverse-engineering and ThreatTrack\u2019s newest version of our <a href=\"https:\/\/www.threattrack.com\/malware-analysis.aspx\">malware analysis sandbox<\/a>, ThreatAnalyzer 6.1.<\/p>\n<p><strong>Analyzing Cerber<\/strong><\/p>\n<p>Reverse engineering in general, more often than not, requires that one gets a broad view as to what the target is doing. Whether you\u2019re analyzing a malware sample or trying to figure what a function does from an obfuscated code, it is best to get the general \u201cfeel\u201d of your target before narrowing down to the specifics.<\/p>\n<p><em>ThreatAnalyzer<\/em> is a sandbox that executes a program, file or URL in a controlled, monitored environment and provides a detailed report enabling the researcher or analyst to get a good look as to what the sample will do at run time. It is also worth noting that a sandbox is a good tool for generating Threat Intelligence to quickly get IOCs (Indicators of Compromise). The latest version of this sandbox, ThreatAnalyzer 6.1, has a built-in behavioral detection mechanism that enables users to see the general behavior of a sample and based on those particular set of behaviors, predict if the program in question is malicious or benign in nature.<\/p>\n<div id=\"attachment_15836\" class=\"wp-caption aligncenter\" style=\"width: 970px;\">\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-15836 size-large\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png\" sizes=\"(max-width: 960px) 100vw, 960px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png 1024w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-300x163.png 300w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-768x417.png 768w\" alt=\"Fig: ThreatAnalyzer\u2019s unique behavior determination engine\" width=\"960\" height=\"522\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Fig: ThreatAnalyzer\u2019s unique behavior determination engine<\/p>\n<\/div>\n<div id=\"attachment_15837\" class=\"wp-caption aligncenter\" style=\"width: 970px;\">\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-2.png\"><img decoding=\"async\" class=\"size-large wp-image-15837\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-2-1024x586.png\" sizes=\"(max-width: 960px) 100vw, 960px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-2-1024x586.png 1024w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-2-300x172.png 300w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-2-768x439.png 768w\" alt=\"Fig 1: ThreatAnalyzer 6.1 in action\" width=\"960\" height=\"549\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Fig 1: ThreatAnalyzer 6.1 in action<\/p>\n<\/div>\n<p>Looking at the figure above, on the analysis screen, ThreatAnalyzer 6.1 has provided the following vital information on this particular sample:<\/p>\n<ol>\n<li>Determine that the sample is detected as malicious on 3 different fronts:\n<ol>\n<li>ThreatIQ (our integrated <a href=\"https:\/\/www.threattrack.com\/threat-intelligence.aspx\">threat intelligence server<\/a>) observers the sample trying to beacon to blacklisted URLs<\/li>\n<li>The sample is detected by at least 1 or multiple antivirus engine(s)<\/li>\n<li>Based on the behavior that it performed, has a high probability that the sample is malicious<\/li>\n<\/ol>\n<\/li>\n<li>Shows the researcher\/user the changes in Registry, IO (File), Network attempts it made, and processes that it spawned<\/li>\n<li>Compacts all detailed information that it has gathered into a downloadable PDF or XML report. If a user chooses, he can download the archive which includes the detailed report, any significant files that was generated, screenshots of the windows spawned and a copy of the PCAP file if any network activities were logged<\/li>\n<\/ol>\n<p>ThreatAnalyzer also provides a detailed report of the sample you analyzed in XML, JSON or PDF format. These reports contain the processes that were spawned, what files were modified, created or accessed, registries that were manipulated, objects that were created and any network connections that were made.<\/p>\n<p>If we look further at the particular XML file of the sample we analyzed, we can gather the following activities:<\/p>\n<ul>\n<li>Spawned WINWORD.EXE (normal since we fed a DOTM file), but the process tree shows that it spawned\n<ul>\n<li>Cmd.exe<\/li>\n<li>Wscript.exe<\/li>\n<\/ul>\n<\/li>\n<li>Created a randomly named VBS file in %appdata%\n<ul>\n<li>%appdata%15339.vbs<\/li>\n<\/ul>\n<ul>\n<li>Cmd.exe \/V \/C set \u201cGSI=%APPDATA%%RANDOM%.vbs\u201d (for %i in (\u201cDIm RWRL\u201d \u201cFuNCtioN GNbiPp(Pt5SZ1)\u201d \u201cEYnt=45\u201d \u201cGNbiPp=AsC(Pt5SZ1)\u201d \u201cXn1=52\u201d \u201ceNd fuNCtiON\u201d \u201cSUb OjrYyD9()\u201dSeeded another cmd.exe calling the VBS file<\/li>\n<\/ul>\n<\/li>\n<li>Made an attempt to connect to\n<ul>\n<li>httx:\/\/solidaritedeproximite.org\/mhtr.jpg<\/li>\n<\/ul>\n<\/li>\n<li>Made a randomly named .TMP in %appdata% and executed it\n<ul>\n<li>Hash: ee0828a4e4c195d97313bfc7d4b531f1<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>These are highly suspicious activities given that we were trying to analyze an Office document file. The behavior above cannot be classified as normal. So the next time you\u2019re nervous on opening an attachment, even if it came from a person or organization you know, feed it to a sandbox like ThreatAnalyzer and have a look before running it on your production machine.<\/p>\n<p><strong>Good ol\u2019 reverse engineering<\/strong><\/p>\n<div id=\"attachment_15838\" class=\"wp-caption aligncenter\" style=\"width: 709px;\">\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-3.jpg\"><img decoding=\"async\" class=\"size-full wp-image-15838\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-3.jpg\" sizes=\"(max-width: 699px) 100vw, 699px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-3.jpg 699w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-3-300x114.jpg 300w\" alt=\"Office 365 Enable Content\" width=\"699\" height=\"265\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Office 365 Enable Content<\/p>\n<\/div>\n<p>Looking at how this ransomware was coded, it will not only infect Office 365 users but users of Office 2007 and above. The macro inside the Document_Open function will auto-execute once the malicious office attachment is opened. But this is also dependent on whether the macro settings is enabled or in earlier Office versions, security is set to low. And quite possibly in an attempt to slow down the analysis process and bypass traditional AV signatures, each iteration of this Cerber macro variant is obfuscated.<\/p>\n<div id=\"attachment_15839\" class=\"wp-caption aligncenter\" style=\"width: 649px;\">\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-4.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-15839 size-full\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-4.jpg\" sizes=\"(max-width: 639px) 100vw, 639px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-4.jpg 639w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-4-300x231.jpg 300w\" alt=\"Auto-execution macro inside Cerber macro\" width=\"639\" height=\"492\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Auto-execution macro inside Cerber macro<\/p>\n<\/div>\n<p>The macro will then proceed to the creation of a script located in %appdata%. The VBS is also obfuscated but luckily not encrypted. It is interesting to note a particular action that may or may not be an intended feature to bypass behavioral detection. It uses the Timer function to generate a random integer and compare it to a self-generated variable, all the while; this action will be the condition when code to download the cryptor component will ensue.<\/p>\n<p>Using built in network features of VBS; it will attempt to connect to a remote server and attempt to download a particular file.<\/p>\n<p style=\"padding-left: 30px;\">httx:\/\/solidaritedeproximite.org\/mhtr.jpg<\/p>\n<p>This may seem harmless as it is just a simple JPG file, right? Well, the VBS code also indicates that it will write whatever the contents of that file, save it to a .TMP in %appdata% and execute it. Although this technique has been used by other malware and dates back years ago, this seems interesting.<\/p>\n<div id=\"attachment_15840\" class=\"wp-caption aligncenter\" style=\"width: 970px;\">\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-5.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-15840\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-5-1024x395.jpg\" sizes=\"(max-width: 960px) 100vw, 960px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-5-1024x395.jpg 1024w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-5-300x116.jpg 300w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-5-768x296.jpg 768w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-5.jpg 1302w\" alt=\"Download the file, save it, then Run\" width=\"960\" height=\"370\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Download the file, save it, then Run<\/p>\n<\/div>\n<p>Md5 Hash: ee0828a4e4c195d97313bfc7d4b531f1<\/p>\n<p>The downloaded file is the cryptor part of the Cerber ransomware. This program is the one responsible for scanning and encrypting target files on a victim\u2019s system. <em>The full analysis of this component will be discussed on a separate blog<\/em>. It is interesting to note that the downloaded cerber executable will encrypt your files even in the absence of internet connection. The code inside the EXE indicates that it does not connect to a remote server (unlike the ones before it e.g. crytowall, locky, Teslacrypt, etc.) to encrypt the victim\u2019s files.<\/p>\n<p>Once a system is successfully infected it will display the following in the desktop.<\/p>\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-15841\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-6-1024x502.png\" sizes=\"(max-width: 960px) 100vw, 960px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-6-1024x502.png 1024w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-6-300x147.png 300w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-6-768x377.png 768w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-6.png 1121w\" alt=\"\" width=\"960\" height=\"471\" \/><\/a><\/p>\n<p>And spawn an instance of your browser containing the message:<\/p>\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-15842\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7.jpg\" sizes=\"(max-width: 800px) 100vw, 800px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7.jpg 800w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7-300x225.jpg 300w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7-768x576.jpg 768w\" alt=\"\" width=\"800\" height=\"600\" \/><\/a><\/p>\n<p>And play a sound \u201c<em>your documents, photos, databases, and other important files have been encrypted<\/em>\u201d in a robot voice.<\/p>\n<p><strong>Infection Summary<\/strong><\/p>\n<div id=\"attachment_15843\" class=\"wp-caption aligncenter\" style=\"width: 658px;\">\n<p><a href=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-15843\" src=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7.png\" sizes=\"(max-width: 648px) 100vw, 648px\" srcset=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7.png 648w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7-300x200.png 300w, https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/fig-7-75x50.png 75w\" alt=\"Flow of the Cerber attack scenario\" width=\"648\" height=\"432\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Flow of the Cerber attack scenario<\/p>\n<\/div>\n<ol>\n<li>A spear-phishing email that contains a malicious Office attachment arrives.<\/li>\n<li>If the user opens the email, executed the attachment AND the macro setting for Office is set to enabled, the macro will execute spawning another VBS script.<\/li>\n<li>The script will contact a remote server, downloads and execute the cryptor part of the Cerber ransomware.<\/li>\n<li>Proceeds on scanning and encrypting the user\u2019s files.<\/li>\n<li>Displays a notice that your system has been infected by Cerber ransomware.<\/li>\n<\/ol>\n<p>The post <a href=\"https:\/\/blog.threattrack.com\/closer-look-cerber-office-365-attack\/\" rel=\"nofollow\">A Look at the Cerber Office 365 Ransomware<\/a> appeared first on <a href=\"https:\/\/blog.threattrack.com\/\" rel=\"nofollow\">ThreatTrack Security Labs Blog<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/threattracksecurity\/~4\/Ll-nSucmhxQ\" alt=\"\" width=\"1\" height=\"1\" \/><\/p>\n<\/div>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Reports of a Zero-day attack affecting numerous Office  [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[110],"tags":[],"class_list":["post-2549","post","type-post","status-publish","format-standard","hentry","category-security-th"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>A Look at the Cerber Office 365 Ransomware - humanit managed services<\/title>\n<meta name=\"description\" content=\"Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at Avanan), and the culprit was a new variant of the Cerber ransomware discovered earlier this year.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/old.humanit.asia\/ll-nsucmhxq\/\" \/>\n<meta property=\"og:locale\" content=\"th_TH\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Look at the Cerber Office 365 Ransomware - humanit managed services\" \/>\n<meta property=\"og:description\" content=\"Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at Avanan), and the culprit was a new variant of the Cerber ransomware discovered earlier this year.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/old.humanit.asia\/ll-nsucmhxq\/\" \/>\n<meta property=\"og:site_name\" content=\"humanit managed services\" \/>\n<meta property=\"article:published_time\" content=\"2016-07-13T06:31:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-22T07:22:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 \u0e19\u0e32\u0e17\u0e35\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/a-look-at-the-cerber-office-365-ransomware\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"headline\":\"A Look at the Cerber Office 365 Ransomware\",\"datePublished\":\"2016-07-13T06:31:36+00:00\",\"dateModified\":\"2019-07-22T07:22:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/a-look-at-the-cerber-office-365-ransomware\\\/\"},\"wordCount\":1162,\"image\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.threattrack.com\\\/wp-content\\\/uploads\\\/2016\\\/07\\\/Fig-1-1024x557.png\",\"articleSection\":[\"Security\"],\"inLanguage\":\"th\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/a-look-at-the-cerber-office-365-ransomware\\\/\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/\",\"name\":\"A Look at the Cerber Office 365 Ransomware - humanit managed services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.threattrack.com\\\/wp-content\\\/uploads\\\/2016\\\/07\\\/Fig-1-1024x557.png\",\"datePublished\":\"2016-07-13T06:31:36+00:00\",\"dateModified\":\"2019-07-22T07:22:36+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"description\":\"Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at Avanan), and the culprit was a new variant of the Cerber ransomware discovered earlier this year.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#breadcrumb\"},\"inLanguage\":\"th\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.threattrack.com\\\/wp-content\\\/uploads\\\/2016\\\/07\\\/Fig-1-1024x557.png\",\"contentUrl\":\"https:\\\/\\\/blog.threattrack.com\\\/wp-content\\\/uploads\\\/2016\\\/07\\\/Fig-1-1024x557.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ll-nsucmhxq\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/old.humanit.asia\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Look at the Cerber Office 365 Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\",\"url\":\"https:\\\/\\\/old.old.humanit.asia\\\/\",\"name\":\"humanit managed services\",\"description\":\"making technology easy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/old.old.humanit.asia\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"th\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"caption\":\"Admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A Look at the Cerber Office 365 Ransomware - humanit managed services","description":"Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at Avanan), and the culprit was a new variant of the Cerber ransomware discovered earlier this year.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/","og_locale":"th_TH","og_type":"article","og_title":"A Look at the Cerber Office 365 Ransomware - humanit managed services","og_description":"Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at Avanan), and the culprit was a new variant of the Cerber ransomware discovered earlier this year.","og_url":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/","og_site_name":"humanit managed services","article_published_time":"2016-07-13T06:31:36+00:00","article_modified_time":"2019-07-22T07:22:36+00:00","og_image":[{"url":"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png","type":"","width":"","height":""}],"author":"Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Admin","Est. reading time":"6 \u0e19\u0e32\u0e17\u0e35"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#article","isPartOf":{"@id":"https:\/\/old.humanit.asia\/th\/a-look-at-the-cerber-office-365-ransomware\/"},"author":{"name":"Admin","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"headline":"A Look at the Cerber Office 365 Ransomware","datePublished":"2016-07-13T06:31:36+00:00","dateModified":"2019-07-22T07:22:36+00:00","mainEntityOfPage":{"@id":"https:\/\/old.humanit.asia\/th\/a-look-at-the-cerber-office-365-ransomware\/"},"wordCount":1162,"image":{"@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png","articleSection":["Security"],"inLanguage":"th"},{"@type":"WebPage","@id":"https:\/\/old.humanit.asia\/th\/a-look-at-the-cerber-office-365-ransomware\/","url":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/","name":"A Look at the Cerber Office 365 Ransomware - humanit managed services","isPartOf":{"@id":"https:\/\/old.old.humanit.asia\/#website"},"primaryImageOfPage":{"@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#primaryimage"},"image":{"@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png","datePublished":"2016-07-13T06:31:36+00:00","dateModified":"2019-07-22T07:22:36+00:00","author":{"@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"description":"Reports of a Zero-day attack affecting numerous Office 365 users emerged late last month (hat tip to the researchers at Avanan), and the culprit was a new variant of the Cerber ransomware discovered earlier this year.","breadcrumb":{"@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#breadcrumb"},"inLanguage":"th","potentialAction":[{"@type":"ReadAction","target":["https:\/\/old.humanit.asia\/ll-nsucmhxq\/"]}]},{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#primaryimage","url":"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png","contentUrl":"https:\/\/blog.threattrack.com\/wp-content\/uploads\/2016\/07\/Fig-1-1024x557.png"},{"@type":"BreadcrumbList","@id":"https:\/\/old.humanit.asia\/ll-nsucmhxq\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/old.humanit.asia\/"},{"@type":"ListItem","position":2,"name":"A Look at the Cerber Office 365 Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/old.old.humanit.asia\/#website","url":"https:\/\/old.old.humanit.asia\/","name":"humanit managed services","description":"making technology easy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/old.old.humanit.asia\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"th"},{"@type":"Person","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c","name":"Admin","image":{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","caption":"Admin"}}]}},"_links":{"self":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/comments?post=2549"}],"version-history":[{"count":2,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2549\/revisions"}],"predecessor-version":[{"id":2854,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2549\/revisions\/2854"}],"wp:attachment":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media?parent=2549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/categories?post=2549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/tags?post=2549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}