A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20167  by m4lware
 Fri Jul 19, 2013 5:49 am
Hi all,
I just just started analyzing Necurs. if anyone able to find new sample with active CnC please share. and one more question recently seen samples of Necurs were same as old or was there any modified version present?
 #21436  by DeW
 Sat Nov 23, 2013 7:38 am
:arrow: It doesn't allow some processes to run even not included in 2 blacklists...In other words if the program launches any kernel-mode components that does not exists in the whitelist of the malware it wouldn't allow them to launch. If your program wants to load a kernel-mode image that wasn't exist in "REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES", "SystemRoot\System32 " or "SystemRoot\System32\Drivers" during system BOOT, in order to add to the whitelist, its kernel-mode modules execution will be banned by writing failure code in their entries.
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8