4 ms·
Isn't it possible, that without matching file hashes, that the malware you found a sample of had a different encrypted payload versus the ones referred to by th
by DominoTree 10y ago
Isn't it possible, that without matching file hashes, that the malware you found a sample of had a different encrypted payload versus the ones referred to by the report?
I'm just thinking that an entity could've downloaded some commodity malware (instead of writing their own from scratch) and modified it to suit their purposes, but the YARA sig would've hit on a lot of different variants of the same webshell versus a higher-fidelity match based on file hash.