Protecting over 230 million PCs, Macs, & Mobiles – more than any other antivirus

Archive

Archive for July, 2009
July 11th, 2009

Inside Win32:Andras

Win32:Andras is simple file infector, that looks for exe files and adds its body to the last section. The entry point is a bit obfuscated, but the code flow is well understandable.

andr_stg0

Read more…

Categories: analyses, Virus Lab Tags:
July 9th, 2009

The learning process of Swizzor

As mentioned in “Swizz with me” article, Swizzor is written by a group of highly skilled coders. They are always ready to improve the generator, make the Swizzor binaries more and more similar to common applications linked with MSVC and make the detection of new variants harder and harder. I can shortly describe the learning process:

  • the very first generation – there were no resources and the obfuscation of code was nicely visible
  • the code obfuscation was diluted to make it less suspicious
  • first attempts to generate resources (an application with resources looks more seriously)
  • inclusion of CRT and a higher dilution of obfuscated code and encrypted data
  • more sophisticated generation of resources

What will follow?

Read more…

Categories: Virus Lab Tags:
Comments off
July 3rd, 2009

Swizz with me

Swizzor is the detection name for a highly sophisticated, long lived piece of malware / adware. It’s based on a huge distribution network and is made by highly skilled bad-guys. At first sight, Swizzor looks like the usual modern software. The bad code is divided into small pieces and is distributed in the whole file by some code-generator. This technique makes analysis and detection difficult.

Let’s look at Swizzor from the other side… What is the first thing the common user sees before running some file? Yes, it’s an icon. The icon is code-generated as well as the whole file. And here inter alia can be seen the mathematical skill of the bad-guys. As Swizzor evolves and each generation becomes harder to detect, the icon becomes more sophisticated too. It’s interesting to see bad-guys producing nice art.

Swizzor icon - 1st generation

Swizzor icon - 1st generation

Read more…

Categories: lab Tags: ,
Comments off