Johann's Blog
Johann's Blog

Whatever I want to share
Rating 0
Entries on 1-December 10

Whitehat Cracks Notorious Rootkit Wide Open

Posted by Johann, 1 Dec 2010, 03:28 AM

A malware analyst has deconstructed a highly advanced piece of crimeware believed to be the work of the notorious Russian Business Network

The step-by-step instructions for reverse engineering the stealthy ZeroAccess rootkit is a blow to its developers, who took great care to make sure it couldn't be forensically analyzed. The tutorial means other malware researchers may also study the malware to close in on the people behind it and to better design products that can safeguard against it.


The analysis was written by Giuseppe Bonfa, a malware researcher specializing in reverse engineering at InfoSec Institute, an information security services company. It documents a rootkit that's almost impossible to remove without damaging the host operating system and uses low-level programming calls to create hard disk volumes that are virtually impossible to detect using normal forensic techniques.



Comments

There are no comments on this entry


 
« Next Oldest · Johann's Blog · Next Newest »