Skip to content

Improve output quality of real malware samples #16

@PeterMatula

Description

@PeterMatula

Investigate problems in these samples. solve them, and add regression tests: samples.zip(MALWARE!).

89442e72227b209b7fcbe467a6b202c1788b850bdfbb52fa22c7762a45b1737c

  • Strings in function calls:
OutputDebugStringW(L"It was a joke about heroin, but now im going to sell heroin to your mother :P");
CreateMutexW(0, 0, L"Local\\Fabiansomware");
StrStrW(&ExistingFileName, L"winlogon.exe");
  • Overall quality.

20AE07CC27965D330314776C16E8FAA3FA021AB7E4C6FFC86A3593AC4010BDFE.dat:

  • Empty functions bodies: WinMain, sub_4018E0, sub_401870, etc.
  • Overall quality.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions