{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T18:57:14Z","timestamp":1783969034995,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,6,26]],"date-time":"2018-06-26T00:00:00Z","timestamp":1529971200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,6,26]]},"DOI":"10.1145\/3231053.3231097","type":"proceedings-article","created":{"date-parts":[[2018,8,30]],"date-time":"2018-08-30T14:00:37Z","timestamp":1535637637000},"page":"1-5","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["Disguised executable files in spear-phishing emails"],"prefix":"10.1145","author":[{"given":"Ibrahim","family":"Ghafir","sequence":"first","affiliation":[{"name":"Masaryk University, Brno, Czech Republic and Durham University, Durham, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vaclav","family":"Prenosil","sequence":"additional","affiliation":[{"name":"Masaryk University, Brno, Czech Republic"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammad","family":"Hammoudeh","sequence":"additional","affiliation":[{"name":"Manchester Metropolitan University, Manchester, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Francisco J.","family":"Aparicio-Navarro","sequence":"additional","affiliation":[{"name":"Newcastle University, Newcastle upon Tyne, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Khaled","family":"Rabie","sequence":"additional","affiliation":[{"name":"Manchester Metropolitan University, Manchester, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmad","family":"Jabban","sequence":"additional","affiliation":[{"name":"Univ Rennes, INSA Rennes, Rennes, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2018,6,26]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"The-Sun. NHS cyber attack. https:\/\/www.thesun.co.uk\/topic\/nhs-cyber-attack\/. Accessed: 01-09-2017.  The-Sun. NHS cyber attack. https:\/\/www.thesun.co.uk\/topic\/nhs-cyber-attack\/. Accessed: 01-09-2017."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2817560"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISPLC.2016.7476261"},{"key":"e_1_3_2_1_4_1","volume-title":"On the secrecy capacity of fisher-snedecor f fading channels. arXiv preprint arXiv:1805.09260","author":"Badarneh O. S.","year":"2018","unstructured":"O. S. Badarneh , P. C. Sofotasios , S. Muhaidat , S. L. Cotton , K. Rabie , and N. Al-Dhahir . On the secrecy capacity of fisher-snedecor f fading channels. arXiv preprint arXiv:1805.09260 , 2018 . O. S. Badarneh, P. C. Sofotasios, S. Muhaidat, S. L. Cotton, K. Rabie, and N. Al-Dhahir. On the secrecy capacity of fisher-snedecor f fading channels. arXiv preprint arXiv:1805.09260, 2018."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2015.7249501"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCOMM.2016.2573829"},{"key":"e_1_3_2_1_7_1","volume-title":"2016 Cybercrime Report","author":"Morgan S.","year":"2016","unstructured":"S. Morgan . Hackerpocalypse : A cybercrime revelation . 2016 Cybercrime Report , Cybersecurity Ventures , 2016 . S. Morgan. Hackerpocalypse: A cybercrime revelation. 2016 Cybercrime Report, Cybersecurity Ventures, 2016."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2018.8328748"},{"key":"e_1_3_2_1_9_1","volume-title":"Security policy monitoring of bpmn-based service compositions. Journal of Software: Evolution and Process, page e1944","author":"Asim M.","year":"2018","unstructured":"M. Asim , A. Yautsiukhin , A. D. Brucker , T. Baker , Q. Shi , and B. Lempereur . Security policy monitoring of bpmn-based service compositions. Journal of Software: Evolution and Process, page e1944 , 2018 . M. Asim, A. Yautsiukhin, A. D. Brucker, T. Baker, Q. Shi, and B. Lempereur. Security policy monitoring of bpmn-based service compositions. Journal of Software: Evolution and Process, page e1944, 2018."},{"key":"e_1_3_2_1_10_1","first-page":"1","volume-title":"Mobility and Security (NTMS), 2016 8th IFIP International Conference on","author":"Al-Sharif S.","year":"2016","unstructured":"S. Al-Sharif , F. Iqbal , T. Baker , and A. Khattack . White-hat hacking framework for promoting security awareness. In New Technologies , Mobility and Security (NTMS), 2016 8th IFIP International Conference on , pages 1 -- 6 . IEEE, 2016 . S. Al-Sharif, F. Iqbal, T. Baker, and A. Khattack. White-hat hacking framework for promoting security awareness. In New Technologies, Mobility and Security (NTMS), 2016 8th IFIP International Conference on, pages 1--6. IEEE, 2016."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2016.7792460"},{"key":"e_1_3_2_1_12_1","volume-title":"International Journal of Advances in Computer Networks and Its Security (IJCNS)","author":"Ghair I.","year":"2014","unstructured":"I. Ghair and V. Prenosil . Advanced persistent threat attack detection: An overview . International Journal of Advances in Computer Networks and Its Security (IJCNS) , vol. 4(Issue 4):50-- 54 , 2014 . ISSN 2250--3757. I. Ghair and V. Prenosil. Advanced persistent threat attack detection: An overview. International Journal of Advances in Computer Networks and Its Security (IJCNS), vol. 4(Issue 4):50--54, 2014. ISSN 2250--3757."},{"key":"e_1_3_2_1_13_1","volume-title":"Symantec internet security threat report trends for","author":"Wood P.","year":"2011","unstructured":"P. Wood , M. Nisbet , G. Egan , N. Johnston , K. Haley , B. Krishnappa , T.-K. Tran , I. Asrar , O. Cox , S. Hittel , Symantec internet security threat report trends for 2011 . Volume XVII , 2012. P. Wood, M. Nisbet, G. Egan, N. Johnston, K. Haley, B. Krishnappa, T.-K. Tran, I. Asrar, O. Cox, S. Hittel, et al. Symantec internet security threat report trends for 2011. Volume XVII, 2012."},{"key":"e_1_3_2_1_14_1","first-page":"34","volume-title":"Proceedings of International Conference on Distance Learning, Simulation and Communication","author":"Ghafir I.","year":"2015","unstructured":"I. Ghafir and V. Prenosil . Advanced persistent threat and spear phishing emails . In Proceedings of International Conference on Distance Learning, Simulation and Communication , pages 34 -- 41 . University of Defence , 2015 . I. Ghafir and V. Prenosil. Advanced persistent threat and spear phishing emails. In Proceedings of International Conference on Distance Learning, Simulation and Communication, pages 34--41. University of Defence, 2015."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-018-2337-2"},{"issue":"2","key":"e_1_3_2_1_16_1","article-title":"A brief survey of detection and mitigation techniques for clickjacking and drive-by download attacksfi","volume":"138","author":"Nagarhalli T. P.","year":"2016","unstructured":"T. P. Nagarhalli , J. Bakal , and N. Jain . A brief survey of detection and mitigation techniques for clickjacking and drive-by download attacksfi ... International Journal of Computer Applications (0975--8887) , 138 ( 2 ), 2016 . T. P. Nagarhalli, J. Bakal, and N. Jain. A brief survey of detection and mitigation techniques for clickjacking and drive-by download attacksfi... International Journal of Computer Applications (0975--8887), 138(2), 2016.","journal-title":"International Journal of Computer Applications (0975--8887)"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1007\/978-3-319-24584-3_7","volume-title":"Advanced Computer and Communication Engineering Technology","author":"Ghafir I.","year":"2016","unstructured":"I. Ghafir and V. Prenosil . Proposed approach for targeted attacks detection . In Advanced Computer and Communication Engineering Technology , pages 73 -- 80 . Springer , 2016 . I. Ghafir and V. Prenosil. Proposed approach for targeted attacks detection. In Advanced Computer and Communication Engineering Technology, pages 73--80. Springer, 2016."},{"key":"e_1_3_2_1_18_1","first-page":"1","volume-title":"International Conference on Frontiers of Communications, Networks and Applications (ICFCNA)","author":"Ghair I.","year":"2014","unstructured":"I. Ghair , J. Svoboda , and V. Prenosil . Tor-based malware and tor connection detection . In International Conference on Frontiers of Communications, Networks and Applications (ICFCNA) , pages 1 -- 6 . IEEE Xplore Digital Library , 2014 . I. Ghair, J. Svoboda, and V. Prenosil. Tor-based malware and tor connection detection. In International Conference on Frontiers of Communications, Networks and Applications (ICFCNA), pages 1--6. IEEE Xplore Digital Library, 2014."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3102304.3102331"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-81-322-2517-1_63"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPIN.2015.7095337"},{"key":"e_1_3_2_1_22_1","volume-title":"International Conference on Frontiers of Communications, Networks and Applications. IEEE Xplore Digital Library","author":"Ghair I.","year":"2014","unstructured":"I. Ghair and V. Prenosil . DNS query failure and algorithmically generated domain-flux detection . In International Conference on Frontiers of Communications, Networks and Applications. IEEE Xplore Digital Library , 2014 . I. Ghair and V. Prenosil. DNS query failure and algorithmically generated domain-flux detection. In International Conference on Frontiers of Communications, Networks and Applications. IEEE Xplore Digital Library, 2014."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/GCCT.2015.7342657"},{"key":"e_1_3_2_1_24_1","unstructured":"T. M. white paper. The custom defense against targeted attacks. htp:\/\/www.trendmicro.fr\/media\/wp\/custom-defense-against-targeted-attacks-whitepaper-en.pdf. Accessed: 10-11-2017.  T. M. white paper. The custom defense against targeted attacks. htp:\/\/www.trendmicro.fr\/media\/wp\/custom-defense-against-targeted-attacks-whitepaper-en.pdf. Accessed: 10-11-2017."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/FiCloud.2016.28"},{"key":"e_1_3_2_1_26_1","volume-title":"International Journal of Advances in Computer Networks and its security (ICJNS)","author":"Ghafir I.","year":"2015","unstructured":"I. Ghafir , J. Svoboda , and V. Prenosil . A survey on botnet command and control traffic detection . International Journal of Advances in Computer Networks and its security (ICJNS) , vol. 5(Issue 2):75-- 80 , 2015 . I. Ghafir, J. Svoboda, and V. Prenosil. A survey on botnet command and control traffic detection. International Journal of Advances in Computer Networks and its security (ICJNS), vol. 5(Issue 2):75--80, 2015."},{"key":"e_1_3_2_1_27_1","volume-title":"International Journal of Advances in Computer Networks and Its Security (IJCNS)","volume":"7","author":"Ghafir I.","year":"2015","unstructured":"I. Ghafir , V. Prenosil , and M. Hammoudeh . Botnet command and control traffic detection challenges: A correlation-based solution . International Journal of Advances in Computer Networks and Its Security (IJCNS) , vol. 7 , 2015 . I. Ghafir, V. Prenosil, and M. Hammoudeh. Botnet command and control traffic detection challenges: A correlation-based solution. International Journal of Advances in Computer Networks and Its Security (IJCNS), vol. 7, 2015."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/2428696.2428722"},{"key":"e_1_3_2_1_29_1","volume-title":"Pass-the-hash attacks: Tools and mitigation. Last accessed September, 11","author":"Ewaida B.","year":"2013","unstructured":"B. Ewaida . Pass-the-hash attacks: Tools and mitigation. Last accessed September, 11 , 2013 . B. Ewaida. Pass-the-hash attacks: Tools and mitigation. Last accessed September, 11, 2013."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2012.05.003"},{"key":"e_1_3_2_1_31_1","volume-title":"DTIC Document","author":"Jansen R.","year":"2014","unstructured":"R. Jansen , F. Tschorsch , A. Johnson , and B. Scheuermann . The sniper attack: Anonymously deanonymizing and disabling the tor network. Technical report , DTIC Document , 2014 . R. Jansen, F. Tschorsch, A. Johnson, and B. Scheuermann. The sniper attack: Anonymously deanonymizing and disabling the tor network. Technical report, DTIC Document, 2014."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2762162"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2016.7511197"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.10.014"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecurity.2012.16"},{"key":"e_1_3_2_1_36_1","first-page":"1","volume-title":"Mobility and Security (NTMS), 2016 8th IFIP International Conference on","author":"Brogi G.","year":"2016","unstructured":"G. Brogi and V. V. T. Tong . Terminaptor : Highlighting advanced persistent threats through information flow tracking. In New Technologies , Mobility and Security (NTMS), 2016 8th IFIP International Conference on , pages 1 -- 5 . IEEE, 2016 . G. Brogi and V. V. T. Tong. Terminaptor: Highlighting advanced persistent threats through information flow tracking. In New Technologies, Mobility and Security (NTMS), 2016 8th IFIP International Conference on, pages 1--5. IEEE, 2016."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1002\/sam.11296"},{"key":"e_1_3_2_1_38_1","volume-title":"ACM European Workshop on System Security (EuroSec)","volume":"2012","author":"Bencs\u00e1th B.","year":"2012","unstructured":"B. Bencs\u00e1th , G. P\u00e9k , L. Butty\u00e1n , and M. F\u00e9legyh\u00e1zi . Duqu: Analysis, detection, and lessons learned . In ACM European Workshop on System Security (EuroSec) , volume 2012 , 2012 . B. Bencs\u00e1th, G. P\u00e9k, L. Butty\u00e1n, and M. F\u00e9legyh\u00e1zi. Duqu: Analysis, detection, and lessons learned. In ACM European Workshop on System Security (EuroSec), volume 2012, 2012."},{"key":"e_1_3_2_1_39_1","first-page":"1","volume-title":"Power and Computing Technologies (ICCPCT), 2016 International Conference on","author":"Chandra J. V.","year":"2016","unstructured":"J. V. Chandra , N. Challa , and S. K. Pasupuleti . A practical approach to e-mail spam filters to protect data from advanced persistent threat. In Circuit , Power and Computing Technologies (ICCPCT), 2016 International Conference on , pages 1 -- 5 . IEEE, 2016 . J. V. Chandra, N. Challa, and S. K. Pasupuleti. A practical approach to e-mail spam filters to protect data from advanced persistent threat. In Circuit, Power and Computing Technologies (ICCPCT), 2016 International Conference on, pages 1--5. IEEE, 2016."},{"key":"e_1_3_2_1_40_1","first-page":"2001","volume-title":"Communications and Informatics (ICACCI), 2015 International Conference on","author":"Chandran S.","year":"2015","unstructured":"S. Chandran , P. Hrudya , and P. Poornachandran . An efficient classification model for detecting advanced persistent threat. In Advances in Computing , Communications and Informatics (ICACCI), 2015 International Conference on , pages 2001 -- 2009 . IEEE, 2015 . S. Chandran, P. Hrudya, and P. Poornachandran. An efficient classification model for detecting advanced persistent threat. In Advances in Computing, Communications and Informatics (ICACCI), 2015 International Conference on, pages 2001--2009. IEEE, 2015."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/EISIC.2013.37"},{"key":"e_1_3_2_1_42_1","unstructured":"FireEye. Mandiant apt1 report. https:\/\/www.ireeye.com\/content\/dam\/fireeye-www\/services\/pdfs\/mandiant-apt1-report.pdf. Accessed: 26-06-2016.  FireEye. Mandiant apt1 report. https:\/\/www.ireeye.com\/content\/dam\/fireeye-www\/services\/pdfs\/mandiant-apt1-report.pdf. Accessed: 26-06-2016."},{"key":"e_1_3_2_1_43_1","volume-title":"International Journal of Advances in Computer Networks and Its Security (IJCNS)","author":"Svoboda J.","unstructured":"J. Svoboda , I. Ghair , and V. Prenosil . Network monitoring approaches: An overview . International Journal of Advances in Computer Networks and Its Security (IJCNS) , vol. 5(Issue I), 2015 . J. Svoboda, I. Ghair, and V. Prenosil. Network monitoring approaches: An overview. International Journal of Advances in Computer Networks and Its Security (IJCNS), vol. 5(Issue I), 2015."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_45_1","unstructured":"MrForms. Mime types list. http:\/\/www.freeformatter.com\/mime-types-list.html. Accessed: 07-04-2015.  MrForms. Mime types list. http:\/\/www.freeformatter.com\/mime-types-list.html. Accessed: 07-04-2015."},{"key":"e_1_3_2_1_46_1","unstructured":"Best-Practical-Solutions. Rt: Request tracker. https:\/\/www.bestpractical.com\/rt\/. Accessed: 15-02-2017.  Best-Practical-Solutions. Rt: Request tracker. https:\/\/www.bestpractical.com\/rt\/. Accessed: 15-02-2017."}],"event":{"name":"ICFNDS'18: International Conference on Future Networks and Distributed Systems","location":"Amman Jordan","acronym":"ICFNDS'18"},"container-title":["Proceedings of the 2nd International Conference on Future Networks and Distributed Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3231053.3231097","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3231053.3231097","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:07:01Z","timestamp":1750212421000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3231053.3231097"}},"subtitle":["detecting the point of entry in advanced persistent threat"],"short-title":[],"issued":{"date-parts":[[2018,6,26]]},"references-count":46,"alternative-id":["10.1145\/3231053.3231097","10.1145\/3231053"],"URL":"https:\/\/doi.org\/10.1145\/3231053.3231097","relation":{},"subject":[],"published":{"date-parts":[[2018,6,26]]},"assertion":[{"value":"2018-06-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}