EP_X0FF wrote:Does not really matter now was it collaboration or copy-past :) Pionner title goes to Kaspersky.He-h, that's not good, but better that F-Secure "researches" http://www.f-secure.com/weblog/archives/00002371.html. :facepalm:
A forum for reverse engineering, OS internals and malware analysis
EP_X0FF wrote:Does not really matter now was it collaboration or copy-past :) Pionner title goes to Kaspersky.He-h, that's not good, but better that F-Secure "researches" http://www.f-secure.com/weblog/archives/00002371.html. :facepalm:
EP_X0FF wrote:What funny part of this is that if this malware were detected somewhere other than Middle East - it was never get the same PR impact.Is it not surprising for you that all this researches from Kaspersky, Symantec, Sophos appeared in one day; and in this one day samples gone ITW.
and in this one day samples gone ITWWell Crysys published hash sums, so I assume some guys simple checked their databases and even uploaded files to Virustotal.
EP_X0FF wrote:Well Crysys published hash sumsYou right, respect for Crysys again.
FLAME and Lua are both from Brazil. Was a downloadable software, which uses Lua, just mistaken for a nation sponsored virus? Paranoia and an irresponsible press are a powerful combination. :)
http://martin.lncc.br/main-software-flame
http://wiki.martin.lncc.br/instalacao-flame-en
omer wrote:Hi,http://www.kernelmode.info/forum/viewto ... 675#p13473
I'm looking for sample of W32.Flamer.