Articles Archive for 28 June 2009

New Anti-analysis Technique for Script Malware
Posted in Information and Removal on 28 June 2009

Recently, we came across JS_VIRTOOL which uses certain Javascript techniques so that encrypted code may not be decrypted and analyzed by a malware analyst.
Here is how this is done:

It retrieves the URL where the malicious script is located.
It retrieves its own function and adds the string of the URL.
It computes the CRC of the function [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

New Anti-analysis Technique for Script Malware

WORM_IRCBOT.GAT
Posted in Trend Micro on 28 June 2009

Malware: WORM_IRCBOT.GAT

WORM_BLAZEBOT.A
Posted in Trend Micro on 28 June 2009

Malware: WORM_BLAZEBOT.A

WORM_KOOBFACE.JG
Posted in Trend Micro on 28 June 2009

Malware: WORM_KOOBFACE.JG

OSX_JAHLAV.C
Posted in Trend Micro on 28 June 2009

Unknown: OSX_JAHLAV.C