8 ms·
The reason they are having this discussion is for the purposes of attribution or blame. The point was whether notPetya had been recompiled from source i.e. it w
by nthcolumn 9y ago
The reason they are having this discussion is for the purposes of attribution or blame. The point was whether notPetya had been recompiled from source i.e. it was Janus or his source was stolen/bought or they had a sample of the ransomware binary (too easy to get unfortunately) and had tweaked it using an editor. Malware also employs 'shellcode' - low level code which can be inserted into a return point in a running process to branch and open a shell (usually) and do something like creating a reverse shell to an attackers' machine or wiping your hard drive. In theory you could use a tested one like petya and change the payload to do something else. You are correct it is daunting - it is rockhard - you can't just hack away at the image and shellcode is often much more complex than plain old assembly as it needs to be obfuscated and tries to avoid using null bytes.