Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 16th, 2013, 10:35 GMT · By

BLOG

Obfuscation and Polymorphism Separates “aaeh” Family from Other AutoRun Worms

SHARE:

Adjust text size:


AutoRun worm employs clever obfuscation and polymorphism mechanisms Enlarge picture - AutoRun worm employs clever obfuscation and polymorphism mechanisms
Threats that rely on the AutoRun function to spread are highly common these days, but there’s one worm family that stands out of the crowd because of the obfuscation and polymorphism mechanisms it employs.

According to McAfee experts, the W32/Autorun.worm.aaeh family is very similar to other threats because it’s spread in the same manner.

However, for obfuscation, the malware’s authors are hiding their creation inside open-source VB6 projects taken from repositories.

While this is possibly an attempt to pass the worm off as a legitimate piece of software, experts found that the compiled binaries are encrypted using a randomly generated encryption key.

“The code is obfuscated and the developers appear to have used an automated code scrambler for the binary generation. The generated code uses junk API calls and string functions to further complicate any analysis,” Anti-Malware Researcher Sanchit Karve explained.

The complete technical analysis and advice on how to protect yourself against the threat are available here.

TELL US WHAT YOU THINK:

1,431 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Improved Version of POS Malware Capable of Directly Exfiltrating Data

Facebook Hacked in Sophisticated Attack, Java Zero-Day Used to Push Malware

Fake Corporate Policy Emails Lure Users to Malware-Serving Sites

Moroccan Expert Finds “Unmonitored” Open Redirect Vulnerability in Google

Largest Percentage of 2012 Cyberattacks Originated in Romania, Study Finds

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM