View Single Post
  #9  
Old 02-20-2017, 19:17
foosaa foosaa is offline
Friend
 
Join Date: Dec 2005
Posts: 106
Rept. Given: 36
Rept. Rcvd 13 Times in 11 Posts
Thanks Given: 163
Thanks Rcvd at 84 Times in 32 Posts
foosaa Reputation: 14
In fact there are multiple methods to keep the file portion to persist across reboots. Some of the ways tried for POC were:
- Writing beyond the partition boundaries
- Writing in between the partition spaces
and they do not get scanned using any of the file system scanners, but nevertheless, there needs to be a driver which will load portions of the malware from the unreadable locations and it needs to exist on the normal file system. With the advancement in the file-less method and combining it with the older, known rootkit techniques, it is still possible to create a malware than can persist yet undetectable.
Reply With Quote