4 ms·
They also posted a bunch of hashes for a file which was customized for them, and then remarked that virustotal hadn't seen it. Though it does make me think tha
by colonelxc 9y ago
They also posted a bunch of hashes for a file which was customized for them, and then remarked that virustotal hadn't seen it.
Though it does make me think that it would be a good trick to offer this 'service', but then keep all the proceeds (everyone gets the same ransomware download). Maybe less profitable on the long term though.
- slig 9y ago> They also posted a bunch of hashes for a file which was customized for them, and then remarked that virustotal hadn't seen it. Surely antivirus are not just trying to match the SHA1 of executables with SHA1 of known virus/malware, otherwise it would be trivial to bypass them.
- itsnotlupus 9y agoThey used to do a lot of fancy things, back in the days, including running bits of suspicious executables in heavily sandboxed interpreters to spot behavioral patterns. I'm guessing those kind of approaches have largely gone away, being replaced with signatures that are hopefully fuzzier than a wholesale cryptographic hash, but still essentially only catching things after the fact, which works well with subscription business models.
- csteegz 9y agoNo, AV has capabilities much more sophisticated then that, however from what I understand, within the malware analysis community specific samples are generally identified with their hash. In addition, if the hash of a file is known-bad, you can skip all the binary pattern matching and heuristics and stuff.
- dsfyu404ed 9y agoMost not-shit AV runs checks from easy to hard so it will blacklist/whitelist on easy identifiers (like hash) and only do a more in-depth look at greylist stuff
- qaq 9y agomany modern ones have ML engines. Also some enterprise products can detonate the executable in specially created vms to observe what happens.
- ryanlol 9y agoThe hashes are used to downlod the samples from various sources, not as IoC.