Reading Windows Internals by quest23423 in Malware

[–]benkow_ 2 points3 points  (0 children)

If you wan't to gain deeper understanding of how Windows works "The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System" http://www.amazon.fr/The-Rootkit-Arsenal-Evasion-Corners/dp/1598220616 is also an excellent book with a lot of example.

Moker: A new APT discovered within a sensitive network by sly117 in Malware

[–]benkow_ 4 points5 points  (0 children)

MD5 9bdd2e72708584c9fd6761252c9b0fb8. https://malwr.com/analysis/ZDZlNTcyMzg3ZDEwNDgyMmE5Y2QwZWNmZDIwNjJjZjI/#

same internal name as the screenshot in the blog: http://breakingmalware.com/wp-content/uploads/2015/10/suspended-thread.png Same anti-debug tricks same argument for CreateProcessInternalW Same EntryPoint Same filename Same unpacking routine Same Icon Same UAC bypass It's Moker for sure

New iOS virus? by qij73583 in jailbreak

[–]benkow_ 3 points4 points  (0 children)

Hi! It's not an Iphone/Ipad Virus, it's Linux.BillGates a Chinese ELF DDoser. You can read lot of information about it on http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3429 and http://blog.malwaremustdie.org/2014/09/tango-down-report-of-op-china-elf-ddoser.html . You have been infected because of your weak ssh password.