Packer (r)evolution

Pedro Bustamante at  19 March 08 06:21    
We know for sure that cyber-criminals use private tools to check AV detection prior to releasing new malware in the wild, making sure it goes undetected by AV signatures at the time of release. As AV companies identify new packers and are able to inspect
Read More...

Post a Comment: 7 Comments    Category: ,     


Mal(ware)formation statistics

Pedro Bustamante at  28 May 07 12:02    
While catching up on an old but excellent post by jason geffner on reconstructing import tables I remembered that I've been wanting to study the real impact of packers on the latest malware received at our labs. Many of us AV companies are now more
Read More...

Post a Comment: 7 Comments    Category: , ,     


Packing a punch (II)

Pedro Bustamante at  20 March 07 08:11    
Following up on the Packing a punch post, we recently came across a couple of banking targeted attack Trojans that use interesting signature-based detection evading techniques. There's packers (UPX, FSG, etc.) and cryptors or protectors (ASProtect,
Read More...

Post a Comment: 2 Comments    Category:     


Packing a punch

Pedro Bustamante at  12 February 07 07:35    
" 80% of new malware defeats antivirus " according to AusCERT . Runtime packers and cryptors are some of the main tools in a malware writers' toolbox. By slightly modifying and exepacking their creations they manage to rapidly create new
Read More...

Post a Comment: 9 Comments    Category: