Friday, January 25, 2008
Case Closed Posted by Sean @ 15:41 GMT

The volume of malware is increasing and we rely on ever increasing amounts of automation.

Our automated systems are necessary to manage the flow of new samples. The automation also assists us in predicting which samples are malicious and should be detected. We review the likely samples first.

Human analysts use tools such as IDA to view the code.

This sample wasn't very difficult to confirm as malicious:


The fact that it's a Backdoor is there in the code itself:


Add detection — case closed in only few minutes — time to move on to the next.

<<< New Symbian Worm in the Wild
Studying Malware Analysis >>>