Search found 116 matches

by TETYYSs
Thu Jul 27, 2017 10:16 am
Forum: General Discussion
Topic: Protomail --statistic
Replies: 1
Views: 8887

Re: Protomail --statistic

if this isn't a good place to ask then why did you ask http://www.kernelmode.info/forum/viewto ... =20&t=1950
by TETYYSs
Thu Nov 10, 2016 6:25 pm
Forum: Malware
Topic: Point-of-Sale malwares / RAM scrapers
Replies: 244
Views: 862540

Re: Point-of-Sale malwares / RAM scrapers

bsteo wrote:No PDO in XXI century? :)
shh, dont give them ideas
by TETYYSs
Tue Sep 20, 2016 1:13 pm
Forum: Newbie Questions
Topic: Why is Malware in C++ (Hard) and not simple Python
Replies: 20
Views: 30311

Re: Why is Malware in C++ (Hard) and not simple Python

EP_X0FF wrote:About year ago a bunch of Cisco "virus analysts" spend few months reversing Borland Delphi Visual Component Library thinking they are reversing obfuscation of super-puper APT
oh my god is this true?
by TETYYSs
Sun Aug 28, 2016 12:53 pm
Forum: Tools/Software
Topic: software for analyze goznym
Replies: 5
Views: 11138

Re: software for analyze goznym

NO .You recommend me use Process Hacker .I took it from this website.But after install it this software made connection here. This software all software not should make any connection.!! Do you use is .Did you noticed Process Hacker did connection here . http://162.243.25.33/wp/ AS62567 Digital Oce...
by TETYYSs
Sun Aug 28, 2016 11:44 am
Forum: Tools/Software
Topic: software for analyze goznym
Replies: 5
Views: 11138

Re: software for analyze goznym

ikolor wrote:ok but why this software try connect here 162.243.25.33
you mean malware
by TETYYSs
Sat Aug 27, 2016 9:06 pm
Forum: Tools/Software
Topic: software for analyze goznym
Replies: 5
Views: 11138

Re: software for analyze goznym

first of all, use process hacker instead of process explorer
by TETYYSs
Sat Aug 27, 2016 9:22 am
Forum: Newbie Questions
Topic: Code golfing to trigger false positives?
Replies: 4
Views: 6863

Re: Code golfing to trigger false positives?

browse some yara rules and throw a dozen of them to one binary