Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Web Based Malware Emphasizes on Anti-Debugging Features
October 7, 2008 07:42

    
Following the ongoing development of a particular web based malware, always comes handy in terms of assessing the commoditization of anti-debugging features within modern malware. With plain simple, "managed binary crypting and firewall bypassing verification" on demand in February, to August's overall anti antivirus software mentality as a key differentiation factor of the malware.

So what are they working on? Anti tracing and emulation protection, PeiD and PESniffer protection, as well as anti heuristic scanning with a simple junk data adding feature in order to maintain a smaller binary size.

Here's a translated description :

"- The binary works under admin and under normal user
- The binary is always run as the "current user"
- An unlimited number of bots can be loaded and integrated within the command and control, and with the geolocation feature, filters can be applied for a particular country
-After successful infection, the binary which is tested against popular firewall and proactive protection security ensures that the actions it takes and their order do not trigger protactive protection mechanisms in place
- binary file size is 25k, the size can be reduced once it's crypted


- Doesn't take advantage of BITS protocol
- Doesn't allow an infected host to be infected twice
- Bypassing NAT and supporting "always-on" connections
- A simple, easy to configure web based admin panel"

What if the buyer doesn't care about the quality assurance practices applied? Managed lower AV detection and firewall bypassing service comes into play.

All news for November 19, 2008
  19:33  Schneier on Security: RIAA Lawsuits May Be Unconstitutional
  16:00  Dancho Danchev: The DDoS Attack Against Bobbear.co.uk
  12:14  Schneier on Security: Skein and SHA-3 News
  10:15  Dancho Danchev: New Web Malware Exploitation Kit in the Wild
  04:19  Martin McKeay: Network Security Podcast, Episode 128

All news for November 18, 2008
  19:57  Dancho Danchev: Will Code Malware for Financial Incentives
  19:46  Schneier on Security: Schneier for TSA Administrator
  16:34  Jeff Jones Security Blog: SIRV5 Vulnerability Trends Webcast - 2 of 2 - Microsoft Trends
  12:32  Schneier on Security: The Neuroscience of Cons

All news for November 17, 2008
  11:11  Schneier on Security: Most Spam Came from a Single Web Hosting Firm

All news for November 16, 2008
  03:00  Martin McKeay: Congratulations to April and Jason
Keywords: web, based, malware, emphasizes, on, anti-debugging, features

All news for November, 2008


All news for 2008