查看: 2461|回复: 7
收起左侧

[砖头] F-PROT对加壳的理解和认识

[复制链接]
The EQs
发表于 2007-4-20 22:23:33 | 显示全部楼层 |阅读模式
1. Regarding a variant of
There's nothing wrong with naming something "a variant of". It all boils down how was the original sample distributed. If it was UPX packed and it gets repacked for example by ASPACK than it's indeed a variant. Reason is being that the file looks completely different from a binary point of view, even if it performs exactly the same actions. So nothing wrong with calling repacked versions "a variant of".

2. Packer Detections
There are 3 types of packers: Whitelist Packers, Greylist Packers and Blacklist Packers.

Whitelist Packers are mainly used by non-malicious applications. (However, that doesn't mean that malware isn't using them) Example: UPX

Greylist Packers are packers which are not really common for "industrial use" they are mostly used for cracks and maybe "strange" freeware/shareware and malware. Example: Exeprotector

Blacklist Packers are packers which are mainly used only for malware. Of course you can pack a clean program with a blacklisted packer but you shouldn't be suprised if a lot of antivirus apps flagging it. Example: Several patched Morphine versions, NSANTI Combinations and so on.

Flagging white-listed packers is ridiculous. Even if you only report a suspicious. A whitelisted packer should never ever been flagged regardingless of the heuristic level.

Flagging greylisted packers is very risky and leads to a lot of false positives.

Flagging blacklisted packers is basically "ok", however it's always better to take some other heuristic flags into the conclusion before flagging such files.

2.1 Combinations of Runtime Packers

Similar to point 2 there are so called blacklisted combinations of runtime packers. UPX + Yoda for example.
jpzy
发表于 2007-4-20 22:33:06 | 显示全部楼层
EQ,你就不能简单翻译一下吗?虽然很多人看得懂,但是看着很难受啊!!
buycard
发表于 2007-4-21 00:56:09 | 显示全部楼层
F-prot的意思是,报壳不是错误的……有些壳加入黑名单就要报,有些是白名单,报白名单的话是愚蠢的,报黑名单是可以的,另外有些灰色名单,可报可不报…………

唉,现在欧洲的反病毒公司,连F-prot这么老牌的都开始报壳……


F-prot这么说,是因为他们自己也报壳的缘故。

[ 本帖最后由 buycard 于 2007-4-21 00:57 编辑 ]
hkc
发表于 2007-4-21 00:57:43 | 显示全部楼层
学习了啊
solcroft
发表于 2007-4-21 01:12:19 | 显示全部楼层
原帖由 buycard 于 2007-4-21 02:26 发表
F-prot的意思是,报壳不是错误的……有些壳加入黑名单就要报,有些是白名单,报白名单的话是愚蠢的,报黑名单是可以的,另外有些灰色名单,可报可不报…………

唉,现在欧洲的反病毒公司,连F-prot这么老牌的 ...

因为报壳菜这么说,和因为这么认为才报壳,是有差别的
jlennon
头像被屏蔽
发表于 2007-4-21 01:16:18 | 显示全部楼层
F-PROT早就承认报壳了
klinxun
发表于 2007-4-21 14:49:10 | 显示全部楼层
不错,很诚实。
bojinov
发表于 2007-4-21 16:09:35 | 显示全部楼层
也没啥,错杀3000,不放一个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-4 15:10 , Processed in 0.114894 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表