rkhunter wrote:http://www.circl.lu/pub/tr-25/The only problem with this "article" - it is not needed.
1) They used old samples dated back few years ago and full of debug.
2) They copy-pasted everything about them from different sources. Just like Turla authors did with their crapware code base.
3) Every idiot can do F5 over code in HexRays. The question here - why this needed?
4) And finally - they didn't provided anything new. So reasons behind this document? Self-PR of yet another security-shit-company?
TR-25 wrote:This document is not considered a final release but a work-in-progress document.Kill yourself and burn this Ctrl-C/Ctrl-V shit.
Lol at diagrams at the end. Time zones? Never heard about them.
In a reality the only interesting part of this malware family is their used vbox exploit.
Ring0 - the source of inspiration