Hi.
In relation to this thread http://www.kernelmode.info/forum/viewto ... 5&start=70 (Comodo5, PrivateFirewall7, Outpost 7.6, Kaspersky 2013, Dr.Web 8, Prevx 3, NOD32 6 termination concepts working from user mode).
I'm currently writing an article for the magazine in my country and I would like to ask for help in finding malware which utilize killav features. Yes, I am aware of the numerous IRC/Zeus-like bots that use blacklists of antivirus software (e.g. Zonebac) and try to complete brute attack on the forehead. I'm not looking for such type of malware. I was primarily interested in the malware, using targeting of the specific antiviruses.
It can be not limited by user mode. For an overview of the methods used in the wild I presently use:
KM
I'm not asking for samples, names or links to description will be enough to find them for me.
Thank you (-.-)
Best Regards,
-rin
In relation to this thread http://www.kernelmode.info/forum/viewto ... 5&start=70 (Comodo5, PrivateFirewall7, Outpost 7.6, Kaspersky 2013, Dr.Web 8, Prevx 3, NOD32 6 termination concepts working from user mode).
I'm currently writing an article for the magazine in my country and I would like to ask for help in finding malware which utilize killav features. Yes, I am aware of the numerous IRC/Zeus-like bots that use blacklists of antivirus software (e.g. Zonebac) and try to complete brute attack on the forehead. I'm not looking for such type of malware. I was primarily interested in the malware, using targeting of the specific antiviruses.
It can be not limited by user mode. For an overview of the methods used in the wild I presently use:
KM
- Old ZeroAccess AV trap tricks (APC to user mode thread with ExitProcess, triggered by trap process / registry key)
- BlackEnergy blacklisting (PsSetLoadImageNotifyRoutine)
- Peacomm.C blacklist (PsSetLoadImageNotifyRoutine)
- PlusDriver (targets G-Buster Browser Defender, Avast4, Avira, forced deletion from malware driver)
- ZeroAccess backdoor AntiMSE/AntiWD (frankly speaking it is too primitive)
- Trojan AuxSpy (WINMM.dll codecs exploiting injection)
I'm not asking for samples, names or links to description will be enough to find them for me.
Thank you (-.-)
Best Regards,
-rin