4 ms·
I'm no expert, but I'm also not convinced that the device contained malware. > We sent the file for proper malware analysis which did confirm that it did indee
by MathMonkeyMan 5y ago
I'm no expert, but I'm also not convinced that the device contained malware.
> We sent the file for proper malware analysis which did confirm that it did indeed contain malware. The malware would collect user data and send it to a remote address. Presumably it would be a way to steal company information such as designs, accounts, and so on. Pretty shady stuff!
Or, you know, it might be doing anything at all on the internet. A reasonable question is "why should this device access the internet?" Good point, but my LAN-controlled "smart plug" connects to an NTP server in France. Who knows.
From the report:
> When verifying the [executable] signature, it was identified that
the malware did not have any signature assigned to it as shown in the figure below. It means that the file has a malicious activity.
Doesn't that mean that the image is not signed? Again, I'm not an expert, but to say "it means that the file has a malicious activity" smells like "I'll consider almost anything suspicious if it will convince you that this report is valuable." On the other hand, maybe that really is suspicious. I don't do this for a living.
> The process explorer and procmon helped to know that the malware created a child
process and then killed the process. It was also identified that the file did not have the signature but had the company name, and the path, confirming that it is a suspicious file from a legitimate organization. The regshot helped in getting the two snapshots of the registry, one before execution and one after malware execution. Therefore, it can be concluded that the file analyzed contains a trojan spyware which creates a child process that kills the original file when run. The malware collects user information and sends it to http://freedns.afraid.org/ http://freedns.afraid.org/.
Again, the conclusion does not follow from the premises. Maybe spawning a child and killing the parent is something that you wouldn't normally do unless you were malware. Maybe English is not the author's first language, fine, but it does look like a poorly edited template.
For all I know, it's totally malware built for corporate espionage originating from a country notorious for doing that, but I don't see any compelling evidence.
- csmpltn 5y agoThere's nothing in this analysis report which proves beyond doubt that this is malware. There's plenty of software out there that behaves this way. I don't think they have solid ground for claiming they've been hit with malware here.
- tekknik 5y agoThe next question is why are people defending China so hard here? Near 1/2 the posts here look like they’re from the $0.50 party.
- MathMonkeyMan 5y agoBecause claims need to be backed up by evidence, even if we love to proceed with prejudice.
- tekknik 5y agoSo this means we promote the positive side of a gov that tramples daily on human rights? Are people on this forum literal robots?
- csmpltn 5y agoPlease, let's not go down that road. It's unnecessary to politicize everything and turn to hyperboles. Nobody here is promoting anything when we're saying that from a purely technical perspective this report alone is not enough to justify the claims being made. Extraordinary claims require extraordinary evidence, but no evidence has been provided whatsoever, so it's perfectly fair to challenge the validity of the claims.
- tekknik 5y agoWhat extraordinary claims? And what evidence has not been provided unless you don’t watch the news? It’s quite public the atrocities the chinese gov has committed. So no, it’s very necessary to politicize this and using your own logic you’ve provided no evidence as to why we shouldn’t.