3 ms·
Wouldn't this be easily solved by behavioural analysis? I'm not even sure what AVs do these days but I'm sure at least one sandboxes all executables for a while
by rainforest 13y ago
Wouldn't this be easily solved by behavioural analysis? I'm not even sure what AVs do these days but I'm sure at least one sandboxes all executables for a while to see if they do anything suspicious before letting them run normally.
The re-encrypted malware would presumably make the same system and library calls in the same order - you don't need to know what the code looks like, just how it behaves.
As far as I can tell this method presents the same problem to signature detection as randomly inserting noise into code caves in the binary. The real target of this obfuscation is making reverse engineers lives difficult.