Here's the version the AV companies have dubbed ipatre....
Few upatre samples in attach, payload is Dyre. This one just spins up svchost and overwrites the oep with a push ret or a jmp to the injected code section.
Few upatre samples in attach, payload is Dyre. This one just spins up svchost and overwrites the oep with a push ret or a jmp to the injected code section.
Attachments
pw:infected
(63.32 KiB) Downloaded 50 times
(63.32 KiB) Downloaded 50 times