Login Register






Windows Malware Wants To Add Your PC To A Botnet filter_list
Author
Message
RE: Windows Malware Wants To Add Your PC To A Botnet #4
(06-21-2018, 09:34 AM)mothered Wrote:
Quote:The malware comes equipped with three different layers of evasion techniques which have been described by the researchers at Deep Instinct who uncovered the malware as complex, rare and "never seen in the wild before".

The sophisticated nature of the botnet suggests that those behind it aren't amateurs, with Mylobot incorporating various techniques to avoid detection.

They include anti-sandboxing, anti-debugging, encrypted files and reflective EXE, which is the ability to execute EXE files directly from memory without having them on the disk. The technique is not common and was only uncovered in 2016, and makes the malware ever harder to detect and trace.

On top of this, Mylobot incorporates a delaying mechanism which waits for two weeks before making contact with the attacker's command and control servers -- another means of avoiding detection.

Doesn't sound like anything new. Any decent malware would have everything that this has, heck even public RATs used by skids have some forms of anti-emulation, anti-VM, anti-analysis, anti-whatever and file obfuscation via encryption and compression. I highly doubt reflective executable injection is something as recent as 2016 and it's not exactly the hardest thing to do - any decent author would know how to do this. Delaying mechanisms are also quite common and definitely not something new.

I've only spent a few years self-studying malware and I can implement all of the above features without too much effort. Also, it seems that this "new malware" hasn't popped up in Bleeping Computer yet so I'm still pretty skeptical about this. Yawn

Reply





Messages In This Thread
RE: Windows Malware Wants To Add Your PC To A Botnet - by reGEN - 06-22-2018, 01:59 AM