Backdoor.Win32.UltimateDefender.gtz Reverse Engineering


Very nice analysis. I always enjoy reading reversing material in relation to malware. It's so much fun to go hunting for malware. I've done my share of searching random file sharing sites to find malicious files. My favorites are botnet's. Most of the time the author is using the same password he would use for his own box and if your lucky (and i have been on a few occasions) the little botmaster is running teh 1337 ubutnu and just learned how to apt-get install ircd! Once you crack the bot net and retrieve that weak password from those bots just ssh into the box and sudo yourself into root because it's likely the skiddie is using the same password for his server. Game over... ;-)

what? sudo -rm -rf /etc/* | rm -rf /var/log/*

Good job look forward to some more. Bookmarked your site.

Edited by D1N
