Log in

View Full Version : Malware Analysis: "Skype" Trojan


Kayaker
January 5th, 2007, 21:40
As usual, an excellent reversing analysis from our friend Nico. While the details and techniques used are interesting in themselves, the irony (and lameness factor) are particularly amusing..

http://www.websense.com/securitylabs/blog/blog.php?BlogID=102

Quote:

The file was protected with "NTkrnl Secure Suite", a commercial protection system using anti-cracking techniques, polymorphic engines, and other interesting features.

I won't provide too much details on how I unpacked the sample because it uses a commercial product, but I feel comfortable talking about the copy pasted code.

The main protection scheme I faced was the copy pasted from my Honeynet Scan of The month 33 Challenge. The breakpoint detection was 100% identical, even the numbers I had generated randomly. More importantly, the technique I had written based on SEH + cpuid/rdtsc was also copied. The only difference was that they used the EDX register to compare the timing.

Copy pasting protection code without even changing it a little, provides no security at all and allowed me to unpack it even quicker. (gotta love looking at code you wrote 2 years ago)



'Tis a shame when ones fine work is used for such a twisted end.

K.

Woodmann
January 6th, 2007, 00:26
Howdy,

I am sure nico will either rip them a new asshole or exploit them
for all the money they are worth.

I mean shit, it's nico's work. I am amazed someone would be so bold
as to steal from him. I guess they dont know who/what they are dealing with.

Give'em hell N.

Woodmann

Polaris
January 6th, 2007, 08:55
Excellent analysis, Nico never disappoints . Thanks for pointing this out!

Silkut
January 6th, 2007, 13:10
Nice work NB !

Maximus
January 7th, 2007, 19:28
Nico==Nicolas Brulez?!

wow! ...SOTM 33 made me get terribly curious and pushed me in the RCE world, so my thanks to Nico

Silkut
January 8th, 2007, 14:25
Maximus> See the name at the end of the outro. But don't name him completely, the la-li-lu-le-lo is hunting him, and FoxDie is launched..

Nico
February 26th, 2007, 15:09
I didn't visit this board for a while, and i just noticed a topic about my little write up on that trojan.

Thanks guys , glad you enjoyed it :-)