

persistence
scanning
automatic updates
upload (exfiltration) of files
self defense & anti-analysis
My goal was simple: reverse Kaspersky's product to gain the knowledge necessary to create a signature which would flag classified documents, presumably for exfiltration. 









I wanted to compose signature to detect classified documents without modifying the executable code of the the AV-product (either on-disk, or in-memory). 
As Kaspersky appears to distribute signatures that contain executable code (i.e. self-contained signature detection routines), which are dynamically linked into the the core anti-virus engine at runtime, we'll still constrain ourselves by only patching such code. 


| 欢迎光临 中神通公司交流论坛 (http://www.trustcomputing.com.cn/bbs/) | Powered by Discuz! 6.0.0 |