Re: Code golfing to trigger false positives?

drop the EICAR string in there :D

WMI persistence in C++

Hi, I was fiddling around with WMI to see how it all works and I'm having problems achieving WMI persistence in C++. What I'm trying to do is get calc.exe to launch every time the system has booted up. I've found a good explanation about what is needed to achieve this on slide 27 here: https://files...

Dridex/Locky downloader/dropper

Hi, I'm looking for the following docm: https://virustotal.com/en/file/1a6859d2 ... /analysis/


Re: Malware collection

https://www.virustotal.com/en/file/80f5 ... 470845487/
Jacksbot multiplatform java backdoor by redpois0n from hackforums (lol)
https://www.intego.com/mac-security-blo ... iscovered/


New APT discovered by Kaspersky Features: Unique footprint: Core implants that have different file names and sizes and are individually built for each target – making it very difficult to detect since the same basic indicators of compromise would have little value for any other target. Running in me...

Bromium malware challenge

https://www.bromium.com/challenge.html If you can bypass bromium endpoint security, you will get £10K which is around 14470 dollars. Does anybody have any experience with the sandboxing technique that they use? They claim to be using CPU-enforced isolation. The target computers would run unpatched v...

Re: Kovter

kovter is polymorphic, this could be the reason why you can't find the sample by hash attached is dropper I think, didn't look at it yet but that's what it looks like from this HA report: https://www.hybrid-analysis.com/sample/129e10d5f18cb0ae5b6a61c13128fa6e753efcb80fcfdcf4d5a28c76e1215f0d?environm...


Looking for sample of this malware, more info in following blog post:
https://www.fireeye.com/blog/threat-res ... cards.html

Finding samples for these might be hard as they were used in spear phishing campaigns, also no hashes seem to have been shared

Re: Android Malware(All Android malware goes here)

Viking horde botnet http://blog.checkpoint.com/2016/05/09/viking-horde-a-new-type-of-android-malware-on-google-play/ 5 of the apks in attach Most popular one has 50k - 100k downloads https://apkscan.nviso.be/report/show/ac16f99ddb36534bebd1034e7e1f599a (analysis failed) https://apkscan.nviso.be/repo...

Re: Backdoor Andromeda (waahoo, alias Gamarue)

