![]() |
|
|
|
#1
|
||||
|
||||
|
Quote:
Certificate Serial number of Foxconn: 256541e204619033f8b09f9eb7c88ef8 Attached from kernelmode.info
__________________
Computer Forensics |
|
#2
|
|||
|
|||
|
Ah, my bad, I was checking only the first batch in the beginning of the thread.
Thanks a lot. |
|
#3
|
||||
|
||||
|
Still wondering why the developers did not transform classic machine code into custom architecture run on custom interpreter (security of critical places).
Considering such a step the analysis we read would be nearly impossible to complete (in reasonable time)... |
|
#4
|
|||
|
|||
|
Maybe such non-x86 blocks (or the corresponding interpreters) are more likely to trigger antivirus heuristics... so while analysis would certainly be harder, the probability of earlier detection could also be higher.
|
|
#5
|
||||
|
||||
|
You might be right, but then they could implement at least custom virtualization (maintaining actual architecture) + stronger data encryption. Anything, which could slow-down the analysis.
|
|
#6
|
|||
|
|||
|
Quote:
Quote:
Can you elaborate how this could be done by linking books/tutorials/topic about making it harder to analysis? (I'm not much but new on this area..) Hope I would get a detailed answer. -Stitch |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware Analysis | ldmd | General Discussion | 7 | 03-09-2025 18:42 |
| ahk malware analysis | dion | General Discussion | 0 | 12-20-2021 08:50 |
| About Android Apps Analysis | Mayo | General Discussion | 5 | 07-23-2014 21:50 |