Wednesday, April 27, 2016

Dark Seoul Implant with zero detection:

Famous Malware researcher Snorre Fagerland tweeted that dark seoul implant having zero detection in Virustotal.

https://twitter.com/SnorreFagerland/status/725211677277310977

Here is the VT link:
https://www.virustotal.com/en/file/061044ffbebeebab449a13ee74799fd9c58b9b383149cbde7a7f6db77c54f72e/analysis/

At this time of writing, 0/56 in VT. i.e. No antivirus vendor flagged this implant.

No comments:

Setting up breakpoints in VirtualAlloc and VirtualProtect during malware analysis:

 Malware analysts add breakpoints in functions like `VirtualProtect` and `VirtualAlloc` for several key reasons: Understanding Malware Behav...