Bypass Antivirus Dynamic Analysis: http://packetstorm.foofus.com/papers/virus/BypassAVDynamics.pdf …
-
-
Replying to @quequero
@quequero@virustotal runs command line scanners which do not employ dynamic analysis. These scanners are not endpoint AV equivalents.1 reply 0 retweets 0 likes -
Replying to @ap0x
@ap0x@quequero To be fair, he did mention that in the paper. That being said, hashes or VT links would be useful :) cc@EmericNasi1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@ap0x@quequero I agree VT is different then endpoint, But Some VT scanners do rely on dynamic analysis (same result as locals)1 reply 0 retweets 0 likes -
Replying to @EmericNasi
@bartblaze@ap0x@quequero Also the basic encrypted stub coud not be detected by another method. Tried also on various local AV.2 replies 0 retweets 0 likes -
Replying to @EmericNasi
@EmericNasi@ap0x@quequero Interesting, which AV's did you try locally?1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@ap0x@quequero Microsoft (surprisingly good), McAffee, Avira, Avast and other free ones.2 replies 0 retweets 0 likes -
Replying to @EmericNasi
@bartblaze@ap0x@quequero If you dont want to compile sources. I can send you binaries to test on your side (choose the method!).1 reply 0 retweets 1 like
@EmericNasi @ap0x @quequero Sounds great, my mail's my twitterhandle at gmail com
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.