To name a few:
Symantec, Symantec.
Kaspersky, Kaspersky.
F-Secure.
In my opinion, Regin is your typical malware that expands outside of the reverse engineer/security community due to its original goal. Journalists or researchers with little kernel-level knowledge/background get a hold of it and before you know it, it's the next biggest sophisticated piece of malware and all that matters is PR. At this point, writing accurate and detailed articles doesn't matter anymore. What am I referring to, and what will I instead talk about with Regin?
Secret Malware in European Union Attack Linked to U.S. and British Intelligence.
Let's quickly talk about a short few things the whitepapers haven't mentioned (as far as I am aware), and the above article. Respectfully, I have absolutely no idea who reviewed the above article before it was pushed. You have to wonder if The Intercept rushed like hell to publish this article because Symantec released their whitepaper and didn't care about what half of it even said. Note the dates:
There's a lot of strange and irrelevant information in that article you can pick at, but the absolute best is:
This Regin driver recurrently checks that the current IRQL (Interrupt Request Level) is set to PASSIVE_LEVEL using the KeGetCurrentIrql() function in many parts of the code, probably in order to operate as silently as possible and to prevent possible IRQL confusion. This technique is another example of the level of precaution the developers took while designing this malware framework.Since its publication date this has yet to have been changed, so I guess they don't care after all about its inaccuracies. Anyway, if it's not a surprise, calling KeGetCurrentIrql over and over again throughout the code is just a PAGED_CODE macro. It has absolutely nothing to do with stealth, and PASSIVE_LEVEL doesn't automatically imply obfuscation or stealth. For an example, here's an excerpt from db405ad775ac887a337b02ea8b07fddc (kernel driver - stage 1).
call KeGetCurrentIrql
test al, al
jnz short loc_FDEFAA3D
push dword ptr [esi] ; Handle
call ZwClose
test eax, eax
jnz short loc_FDEFAA3D
push 18h
push ebx
push esi
call sub_FDEFA2EC
add esp, 0Ch
mov bl, 1
Again taking a look at db405ad775ac887a337b02ea8b07fddc, there's another interesting tidbit throughout the code:
push 43726150h
push 20h
push edi
call ds:ExAllocatePoolWithTag
The above is the kernel mode driver's pool tag, the # of bytes to allocate for the memory request, the pool type, and finally its call to ExAllocatePoolWithTag allocate pool memory. Okay, so what's the big deal? If we convert the pool tag operand to a character, we get the following result:
push 'CraP'
push 20h
push edi
call ds:ExAllocatePoolWithTag
The pooltag is CraP : ) This is probably how many of us feel about this malware being so hyped by the media. There are of course others throughout the code, for example:
push 'CraP'
push eax
push 1
call ds:ExAllocatePoolWithTag
Overall, I guess the moral is to take time to get as much accurate information as you can for your articles. I cannot speak for anyone but myself, but as someone with a love for reverse engineering, malware, and debugging, I appreciate in-depth whitepapers and articles that provide thorough analysis. If all you're worried about is competition for views and hyping malware, chances are you're not going to appeal to the people who really care about the written content.
PS: Thanks to KernelMode as always for the hilarious discussion.
test dpc android
ReplyDeletetest dpc app
test dpc apk
download test dpc
test dpc downloading
test dpc user guide
https://sattaking2018.co/
ReplyDeletesatta king in
satta king 2018
satta king2018
https://wikiweb.co.in
ReplyDeletevizer tv apk
vidmate apk
showbox apk
lucky patcher
hotstar apk
moviebox apk
YoWhatsApp d g f d h f
ReplyDelete
ReplyDeleteshareit
shareit download
shareit install
shareit app download
Every time we use modern technology we are worried that our data security will be violated and that information will be leaked.
kingroot apk
ReplyDeletekingroot apk download
download kingroot apk
kingroot apps for android
kingroot for android
I appreciate in-depth whitepapers and articles that provide thorough analysis.
Thanks for sharing, very informative blog.
ReplyDeleteReverseEngineering
Great sharing! Thank you for sharing! Keep up the great work mate! Cheers!
Delete
ReplyDeletehttps://acmarket.xyz/
Ac market
Ac market apk
Ac market downloading
ac market download cracked apps store
Nice blog!!!!!!!.
ReplyDeleteReverse Engineering in USA
Great read guys! Thank you for sharing! Anyway anyone from Singapore here? Interested in property investment? I saw a few property launches that has got huge potential. Anyway keen to know more? Click on the link below!
DeleteDaintree Residence Location
DainTree Residence Singapore
daintree residence balance unit
whistler grand condo
whistler grand singapore
whistler grand site plan
jadescape location
jadescape singapore
jadescape condo
Hey, this is amazing content. thank you for sharing.
ReplyDeleteReverseEngineering
Thanks for info
ReplyDeleteauto cad drawing in UK
thanks for sharing information.....
ReplyDeleteReverse Engineering in UK
Reverse Engineering in India
reverse engineering services in Bangalore
ReverseEngineering
ReplyDeleteExcellent Blog! I would like to thank for the efforts you have made in writing this post. I am hoping the same best work from you in the future as well.
I wanted to thank you for this websites! Thanks for sharing. Great websites!
pubg mobile apk
pubg lite
pubg apk
pubg mobile lite
pubg
https://filmetriks.com/technology/vidmate-apk/
ReplyDeletevidmate apk
vidmate download apk
https://filmetriks.com/technology/tutuapp-apk/
tutuapp apk
tutuapp download apk
https://filmetriks.com/technology/xmodgames-apk/
xmodgames apk
xmodgames download apk
https://filmetriks.com/technology/uc-browser-apk
uc browser apk
uc browser download apk
https://filmetriks.com/technology/kodi-apk-latest-version-download-for-android/
kodi apk
kodi download apk
https://filmetriks.com/technology/tubemate-apk
tubemate apk
tubemate download apk
https://filmetriks.com/technology/tiktok-apk/
tiktok apk
tiktok download apk
https://filmetriks.com/technology/happychick-apk/
happychick apk
happychick download apk
https://filmetriks.com/technology/happymod-apk/
happymod apk
happymod download apk
https://filmetriks.com/technology/mx-player-apk/
mx player apk
mx player download apk
live net tv apk
ReplyDeletelive nettv app
framerootapk apk
framerootapk app
fmwhatsapp apk
fmwhatsapp app
appvn apk
appvn app
https://apkmist.com/
redbox tv apk
redbox tv app
This comment has been removed by the author.
ReplyDeleteWow, that’s what I was exploring for, what a data! present here
ReplyDeleteat this weblog, thanks admin of this web page.
shareit for pc
xender for pc
Great sharing! Thank you for sharing! Keep up the great work mate! Cheers!
ReplyDelete
ReplyDeletevideoder apk download
videoder for windows
videoder for pc
vidoder for android
The app does what you can do using Bluetooth or NFC, but faster.
Tekken 3 for pc get download all games pc game
ReplyDeleterevdl for best apps and games free download apk revdl
gamekiller for windows
ReplyDeletegamekiller for android
gamekiller for ios
more quickly for data transfer between PCs and mobile devices, compared to USB drive transfer.
framaroot
ReplyDeleteframaroot apk
The app does what you can do using Bluetooth or NFC, but faster.
framaroot
ReplyDeleteframaroot apk
videoder apk download
videoder for windows
videoder for pc
videoder for android
All you have to do is visit the website and find the video. This tool does the rest.
Happy new year wishes
ReplyDeletehappy new year quotes
happy new year images
happy new year wishes
Happy new year messages
new year messages
kingroot
ReplyDeletekingroot apk
to do or get any app download this app
Maintain the printer intact by regularly accessing the test print page option by visiting the link print test page simple printer test page
ReplyDeletepubg apk
ReplyDeletepubg mod apk
pubg mobile hack
pubg themes
pubg ringtone download
pubg hack tool download
apk apps
ReplyDeletedownload lucky patcher apk
subway surfer hack-apk download
MX player pro-apk download
This comment has been removed by the author.
ReplyDeleteExcellent Blog! I would like to thank for the efforts you have made in writing this post. I am hoping the same best work from you in the future as well.
ReplyDeleteI wanted to thank you for this websites! Thanks for sharing. Great websites!
APK Apps for fire stick
whatsapp war apk
whatsapp yo apk
whatsapp faud apk
whatsapp latest gb apk
good post am impressed
ReplyDeletegb whatsapp
whatsapp mod
Excellent Blog! I would like to thank for the efforts you have made in writing this post.
ReplyDeletedownload pubg ringtone song for android device
pubg mobile hack
why pubg mobile hack
whatsapp mod apk
whatsapp gb apk
pubg whatsapp group
Good Post Amm Impressed
ReplyDeleteMuzamil
gb whatsapp apk
whatsapp group link app
ReplyDeletewhatsapp group link download
whatsapp group link app download
whatsapp group link app apk download
ReplyDeleteRushian girls pictures
Hot indian Girls
Dating Online
Macthing online
uk online registration
USA Dating Girls
Asian Girls Matching
Full Form
ReplyDeletefouad whatsapp
fouad whatsapp
whatsapp apk
Great read guys! Thank you for sharing! Anyway anyone from Singapore here? Interested in property investment? I saw a few property launches that has got huge potential. Anyway keen to know more? Click on the link below!
ReplyDeleteDaintree Residence Location
DainTree Residence Singapore
daintree residence balance unit
whistler grand condo
whistler grand singapore
whistler grand site plan
jadescape location
jadescape singapore
jadescape condo
GOOD Day !
ReplyDeleteUSA Fresh & Verified SSN Leads with best connectivity
All Leads have genuine & valid information
**HEADERS IN LEADS**
First Name | Last Name | SSN | Dob | DL Number |Address | State | City | Zip | Phone Number | Account Number | Bank NAME
*Price for SSN lead $2
*You can ask for sample before any deal
*If anyone buy in bulk, we can negotiate
*Sampling is just for serious buyers
==>ACTIVE & FRESH CC FULLZ ALSO AVAILABLE<==
->$5 PER EACH
->Hope for the long term deal
->Interested buyers will be welcome
**Contact Information 24/7**
Whatsapp > +923172721122
Email > leads.sellers1212@gmail.com
Telegram > @leadsupplier
ICQ > 752822040
whatsapp group link
ReplyDeletewhatsapp group link
whatsapp group link
whatsapp group link
whatsapp group link
whatsapp group link
whatsapp group link
ReplyDeleteBumblebee Vs Optimus Prime
Optimus Prime Vs BumbleeBee
Transformers 5 the last knight
Transformers bumblebee vs optimus prime
gb whatsapp
ReplyDeletear.wikipedia.org
ReplyDeleteFullforms
ReplyDeleteFullforms
Fullforms
Fullforms
guidance corner
ReplyDeleteTiktok hile mi arıyorsunuz? Tıklayın: tiktok para hilesi
ReplyDeleteI will be looking forward to your next post. Thank you
ReplyDeleteส่องความเเซ่บ ชิปปี้ ศิรินทร์ งานนี้มีคนหวง
MBA
ReplyDeleteMBA in London
Business School in London
Business School
how to fix printer in error state
ReplyDeleteHow to deal with Microsoft Word not opening error
Good PGกดเพื่อดู
ReplyDelete
ReplyDeleteThis is default IP address that is used by most of the router companies like the PTCL, TP-Link, D-Link, in order to access the admin page of the router
192.168.10.1
192-168-l0-1.club
ReplyDeleteThis configuration can also be used for devices like Router, Modem etc. and they are all having the initial IP address
192.168.254.254
192.168.l78.1
192.168.0.1
I procrastinate a lot and don’t manage to get nearly anything done. waiting for your further write ups thanks once again. 카지노사이트
ReplyDelete온라인카지노 Great blog here! Also your website loads up fast! What web host are you using? Can I get your affiliate link to your host? I wish my web site loaded up as fast as yours lol
ReplyDelete토토사이트 Good day very cool web site!! Man .. Beautiful
ReplyDelete.. Wonderful .. I'll bookmark your website and take the feeds also?
I am satisfied to find so many helpful info here in the put up, we want
work out more strategies on this regard, thank you for sharing.
Thanks for sharing these post. https://packagessite.pk/ufone-internet-packages/
ReplyDeleteThis is by far the best post I've seen recently. This article, which has been devoted to your efforts, has helped me to complete my task. Feel free to visit my website; 온라인카지노
ReplyDeleteThanks for Sharing This amazing Post.
ReplyDeleteBest Sex Condoms
Oil For Pennis
I wanted to thank you for this site Thanks for sharing. Great websites! Bookmark site The Upcut News Portal
ReplyDeleteThis is really interesting, You’re a very skilled blogger. 바카라사이트
ReplyDeleteI’m not that much of a internet reader to be honest but your blogs really nice, keep it! 온라인바둑이
ReplyDeleteSo good indeed! Glad to have found your page!! This is such great work!! Interesting to read for sure!! 파칭코
ReplyDeleteIts an amazing website, really enjoy your articles. Helpful and interesting too. Keep doing this in future. I will support you. 블랙잭사이트
ReplyDeleteYour article is very interesting. I think this article has a lot of information needed, looking forward to your new posts.
ReplyDelete마사지블루
It was an awesome post to be sure. I completely delighted in understanding it in my noon. Will without a doubt come and visit this blog all the more frequently. A debt of gratitude is in order for sharing
ReplyDelete마사지블루
Can I simply say what a relief to find somebody who really understands what they are discussing on the web.
ReplyDelete마사지블루
That is a great tip particularly to those new to the blogosphere.
ReplyDeleteSimple but very accurate info? Thank you for sharing this one.
A must read post!
Appreciating the hard work you put into your site and detailed information you present.
Wonderful read!
토토사이트
Some really useful stuff on here, keep up posting. Cheers.
ReplyDelete야설
Some really useful stuff on here, keep up posting. Cheers.
ReplyDelete건마탑
I think your website has a lot of useful knowledge. I'm so thankful for this website.
ReplyDeleteI hope that you continue to share a lot of knowledge.
This is my website.
넷마블머니상
I’ve read this post and if I may I want to suggest you some attention-grabbing things or suggestions. 국산야동
ReplyDeleteThese are actually impressive ideas in concerning blogging. You have touched some nice factors here. Any way keep up wrinting
ReplyDelete바카라사이트윈
Good post however I was wanting to know if you could write a litte more on this subject? I’d be very thankful if you could elaborate a little bit further. Cheers!
ReplyDelete토토사이트링크
I definitely enjoying every little bit of it. It is a great website and a nice share. I want to thank you. Good job! You guys do a great blog and have some great contents. Keep up the good work.
ReplyDelete토토사이트웹
Wonderful article. Fascinating to read. I love to read such an excellent article. Thanks! It has made my task more and extra easy. Keep rocking.
ReplyDeleteDumb And Dumber Suits
Thanks for sharing such a Great Information with us
ReplyDelete바카라사이트윈
Great Post! I look forward to seeing more from you in the future. There are some very great ideas above. Feel free to visit my website; 바카라사이트
ReplyDeleteVery good written information. It will be valuable to anybody who employess it, as well as yours truly :). Keep up the good work – for sure i will check out more posts. Feel free to visit my website; 바카라사이트
ReplyDeleteIt's fantastic that you are getting ideas from this article as well as from our argument made at this time.
ReplyDelete토토사이트링크
I really enjoyed reading this blog. It was explained and structured with perfection.
ReplyDelete토토사이트
I’m quite sure I’ll learn plenty of new stuff right here! Good luck for the next
ReplyDelete토토
먹튀검증
Thanks for your marvelous posting! I actually enjoyed reading it, you can be a great author.
ReplyDelete온라인카지노
카지노
It’s nice to come across a blog every once in a
ReplyDeletewhile that isn’t the same outdated rehashed material. Wonderful read!
바카라사이트
온라인카지노
Admiring the dedication you put into your site and detailed information you provide.
ReplyDelete카지노
바카라사이트