@ochsenmeier It would be easy to add an XML list containing the list of blacklisted MD5 of ICO. Does that make sense?
@ochsenmeier Because it's a small indicator. Normally PE files shouldn't have a PDF icon (besides the legit ones obviously).
-
-
@bartblaze of course! ...but somehow it is used...and fools many people I guess (otherwise,#malware would not use this trick)... -
@bartblaze And this kind trick with "well-known" ICO can be applied to other ones, not only to PDF... - Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.