4 ms·
It was a few added characters in a header file to make it possible to deliver the actual payload: 80+ kilobytes of machine code. There's no way to actually tell
by adtac 3y ago
It was a few added characters in a header file to make it possible to deliver the actual payload: 80+ kilobytes of machine code. There's no way to actually tell, but I'd estimate the malware source code to be O(10000) lines in C.
It's actually pretty sophisticated. You don't accidentally write a in-memory ELF program header parser.