A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #26955  by EP_X0FF
 Thu Oct 15, 2015 4:50 am
Detection name of dropper actually means absolutely nothing and it will be indifferent most of time. It maybe detected as ANYTHING.Malware or as Trojan.Downloader or as IDontKnowWhatIsItMalware, which only mean AV will kill this file because of it presence in signatures no matter how it named. Once dropped malware can extract/download additional components which will be detected differently. The only meaning of name comes when this specified malware need EXTRA attention on cleaning like for example Sirefef or Alureon in past when AV will execute it scripts specially written for EXACTLY this malware, so AV maybe unable to cleanup malware detected with improper name. Everything else can be killed by simple removing file and performing standard generic registry cleanup. Also *proper* naming required for malware collectors. For end-user in most cases it means nothing.
 #26984  by unixfreaxjp
 Fri Oct 16, 2015 4:41 pm
EP_X0FF wrote:The only meaning of name comes when this specified malware need EXTRA attention on cleaning...
Good point. As long it was detected it makes much sense.
This downloader purpose is only to expand the peers, once this gets FUD the nodes will spread since the infection efforts are rapidly sent aiming specific countries. Herder is aiming for this chance (miss).
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10