NEWS FROM THE LAB - Friday, January 25, 2008

Case Closed Posted by Sean @ 15:41 GMT

The volume of malware is increasing and we rely on ever increasing amounts of automation.

Our automated systems are necessary to manage the flow of new samples. The automation also assists us in predicting which samples are malicious and should be detected. We review the likely samples first.

Human analysts use tools such as IDA to view the code.

This sample wasn't very difficult to confirm as malicious:


The fact that it's a Backdoor is there in the code itself:


Add detection — case closed in only few minutes — time to move on to the next.