[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <BAY10-DAV25196894F91398845074CBD9F50@phx.gbl>
Date: Thu Jun 16 15:05:05 2005
From: se_cur_ity at hotmail.com (Morning Wood)
Subject: Sophos Antivirus Advisory
> = Advisory: Sophos doesn't recognize keylogger after string alteration =
>
this technique is not new, and is quite commonly used to fool AV engines,
not just Sophos.
( and yes, Morphine works as well as commercial "executable packers")
If I recall, a certain trojan group ( now defunct ) used a simple string
change to change their standard releases to that of undetected versions they
sold ( for up to $300). I realy dont know why this is being reported here.
my2bits,
mw
Powered by blists - more mailing lists