Wednesday, November 5, 2008

First Check Home Drug Test Faint Pink Line

The rootkit that is much fear.

Rustock.C. The name tells you nothing can be and yet it would be better! lol. At the security conference Hack.lu , Boldewin Frank gave a presentation on this rootkit son who gives a lot of headaches for analysts. For the protection of this malware in our program:
  • Anti-debugging
  • of ofuscation code
  • engines polymorphic and metamorphic (Morpheus, is that you?: Op)
  • and garbage collection .
All for this little rootkit does not deliver all its secrets. My god that's scary. I will not sleep a wink the night!

Sources: SecuObs.com
Presentation Frank Boldewin: reconstructer.org (PDF)

0 comments:

Post a Comment