Again and again and again… That’s what comes to my mind every time when I see a new variant of the Kavo family and, most recently, also the Hilot family. These malware samples are machine-generated and their authors can develop a “completely new” set of samples based on a simple change made to the generator itself. What’s the problem here? These changes are not random as we earlier thought, they’re precisely targeted against the most popular AV engines.
Let’s describe it with the Hilot case. This malware family is detected algorithmically by our engine and the detection can be called a generic detection (this means not with a fixed signature or checksum). Once the authors notice a higher detection rate of their binaries, they have decided to change the generator. What surprised me was the tight boundary to our detection. We have been checking some characteristics of a significant block inside the binary as a part of our detection process and this block is a part of our cat and mouse game. But, the Hilot authors then shifted this significant block in response.
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts
Tuesday, August 10, 2010
Thursday, March 18, 2010
Spyware, Viruses, Trojans and Malware list of update history
18.3.2010 - 100318-1
This VPS update contains only fixes to existing definitions or removal of false alarms...
18.3.2010 - 100318-0
NSIS:Agent-M [Trj], Win32:Alureon-FT [Rtk], Win32:Crypt-GAS [Drp], Win32:FraudPack-CW [Trj], Win32:FraudPack-CX [Trj], Win32:FraudPack-CY [Trj], Win32:FraudPack-CZ [Trj], Win32:Inject-XP [Trj], Win32:Kates-AJ [Trj], Win32:OnLineGames-FQI [Trj], Win32:Poison-UN [PUP], Win32:SdBot-209 [PUP], Win32:Small-NIB [Trj], Win32:Tiny-AEO [Trj], Win32:VB-ORM [Trj], Win32:VB-ORN [Drp], Win32:VB-ORO [Wrm], Win32:VB-ORP [Wrm], Win32:Virut-AAL, Win32:Zbot-MRX [Trj]
This VPS update contains only fixes to existing definitions or removal of false alarms...
18.3.2010 - 100318-0
NSIS:Agent-M [Trj], Win32:Alureon-FT [Rtk], Win32:Crypt-GAS [Drp], Win32:FraudPack-CW [Trj], Win32:FraudPack-CX [Trj], Win32:FraudPack-CY [Trj], Win32:FraudPack-CZ [Trj], Win32:Inject-XP [Trj], Win32:Kates-AJ [Trj], Win32:OnLineGames-FQI [Trj], Win32:Poison-UN [PUP], Win32:SdBot-209 [PUP], Win32:Small-NIB [Trj], Win32:Tiny-AEO [Trj], Win32:VB-ORM [Trj], Win32:VB-ORN [Drp], Win32:VB-ORO [Wrm], Win32:VB-ORP [Wrm], Win32:Virut-AAL, Win32:Zbot-MRX [Trj]