[nsp-sec] Strange self-obfuscating malware found on one of our webservers

David Freedman david.freedman at uk.clara.net
Tue Jan 29 05:37:16 EST 2008


>Russian spam/proxy software.  Widely used by Russian miscreants.
>Question, what did you use to de-obfuscate?

Oh , since it was self de-obfuscating it contained the code to do so , I just hijacked that ( perl's unpack() function)



John




More information about the nsp-security mailing list