?

Log in

почетный шаман

Июль 2017

Вс Пн Вт Ср Чт Пт Сб
      1
2345678
9101112131415
16171819202122
23242526272829
3031     

Метки

Разработано LiveJournal.com
почетный шаман

На почитать. Честно говоря охренеть.

https://www.welivesecurity.com/2017/07/04/analysis-of-telebots-cunning-backdoor/
...
Conclusions

As our analysis shows, this is a thoroughly well-planned and well-executed operation. We assume that the attackers had access to the M.E.Doc application source code. They had time to learn the code and incorporate a very stealthy and cunning backdoor. The size of the full M.E.Doc installation is about 1.5GB, and we have no way at this time to verify that there are no other injected backdoors.

There are still questions to answer. How long has this backdoor been in use? What commands and malware other than DiskCoder.C or Win32/Filecoder.AESNI.C has been pushed via this channel? What other software update supply chains might the gang behind this attack have already compromised but are yet to weaponize?

Апд:https://m.habrahabr.ru/company/drweb/blog/332444/.e.doc-soderzhit-bekdor--d

Comments