<<<
Friday, January 25, 2008
>>>
 
Case Closed Posted by Sean @ 15:41 GMT

The volume of malware is increasing and we rely on ever increasing amounts of automation.

Our automated systems are necessary to manage the flow of new samples. The automation also assists us in predicting which samples are malicious and should be detected. We review the likely samples first.

Human analysts use tools such as IDA to view the code.

This sample wasn't very difficult to confirm as malicious:

IDA

The fact that it's a Backdoor is there in the code itself:

IDA

Add detection — case closed in only few minutes — time to move on to the next.






<<< New Symbian Worm in the Wild
|
Studying Malware Analysis >>>