US 11,924,228 B2
Messaging server credentials exfiltration based malware threat assessment and mitigation
Jakub Kroustek, Rajhrad (CZ); and Lukás Zobal, Archlebov (CZ)
Assigned to Avast Software s.r.o., Prague (CZ)
Filed by Avast Software s.r.o., Prague (CZ)
Filed on Jun. 23, 2021, as Appl. No. 17/356,356.
Prior Publication US 2022/0417262 A1, Dec. 29, 2022
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) 41 Claims
OG exemplary drawing
 
1. A method comprising:
enabling a messaging server;
providing credentials for the messaging server;
enabling a computing system;
receiving a first application by the computing system, the first application comprising a malware application;
executing the first application by the computing system;
rendering the credentials accessible to the first application via the computing system;
enabling the first application to transmit the credentials via network transmission from the computing system to a computer;
enabling an actor to access the messaging server over a network in response to the actor applying the credentials;
receiving by the messaging server a first electronic message transmitted by the actor, the first electronic message comprising first content;
enabling a second application on a computing device, the second application comprising an extension to at least one of an email client or a messaging application on the computing device;
transmitting the first content to the second application on the computing device based on the actor applying the credentials and based on the receiving by the messaging server the first electronic message transmitted by the actor;
detecting via the second application a second electronic message comprising second content received by the computing device;
comparing the first content to the second content; and
blocking the second electronic message via the second application based on the comparison of the first content to the second content.