/?pid=17443

Updated:06:15 PM EST Feb 04


this is ggmania.com subsite Windows Malware Tries To Avoid 400 Security Products - TechAmok

Windows Malware Tries To Avoid 400 Security Products - [briefly]
02:48 PM EDT - May,20 2016 - post a comment

The malware's name comes from Latin and means 'stealthy,' Yotam Gottesman, a Senior Security Researcher at enSilo explains, adding that the program goes through great lengths to avoid being caught by security parties: it includes checks for 400 security products. Should any of the products on this extensive list be found on the targeted machine, the malware terminates itself and leaves the computer unharmed.

Built to target Windows computers, the malware was first discovered by a researcher that goes by the name of @hFireF0X, who noticed that none of the 56 anti-virus programs tested by VirusTotal service detected the new threat. It's unclear who is behind the malware as of now, but it is clear that the actor would abort infection rather than being caught.

Furtim is deployed as a binary file named “native.dll,” which is a driver supposedly meant to be loaded by the kernel, researchers explain. The analyzed sample was 295 KB in size, was compiled on October 22, 2015, and came unpacked, although it did show protection mechanisms.

Gottesman explains that strings in the sample are obfuscated, the binary contains other encrypted parts, and calls are made dynamically through a large structure that contains function pointers, albeit anti-debugging protection is not present. The analysis revealed the structure for function calls and a loop that decrypts strings that, when run, reveal plaintext strings and a struct full of function pointers.

The most interesting part of the malware was its ability to search the infected machine for registry entries or service executable names of 400 security programs, including well-known and very rare products. As soon as traces of such a program are discovered on the compromised system, the malware terminates itself.

The malicious program also checks for virtualization environments, being aware of all major virtualization and sandboxing products and avoiding them. Additionally, the malware knows of DNS filtering services due to its scanning of the network interfaces on the infected machine.


Add your comment (free registrationrequired)

Short overview of recent news articles

Feb,04 2026 AI-Powered Breach: Hacker Claims AWS Kingdom in Under 10 Minutes
Feb,04 2026 Microsoft Axes Standalone SharePoint and OneDrive Plans in Push to
Feb,04 2026 Nvidia's $100 billion OpenAI deal has seemingly vanished
Feb,04 2026 The Best 14" Gaming Laptops Right Now
Feb,04 2026 The Solution to the RAM Crisis is... DDR4???
Feb,03 2026 Google Meet can now join Microsoft Teams calls
Feb,03 2026 The Devil Wears Prada 2 - Official Trailer (2026) Meryl Streep, Anne
Feb,02 2026 *EPSTEIN HAD THE SEC SUE RIPPLE/XRP - HOLY SH*T | Gensler Worked For
Feb,02 2026 Mozilla Firefox is making it super easy to turn off its generative
Feb,01 2026 Windows 11 quietly gets a new security feature to protect system
Feb,01 2026 WARNING: TRUMP & RIPPLE/XRP SECRET AGREEMENT AT DAVOS
Feb,01 2026 China's new RAM company, CXMT, is selling RAM at $138
Feb,01 2026 Windows keeps a permanent record of every USB device you've ever
Feb,01 2026 Intel Is BACK - Panther Lake Changes Everything
Jan,31 2026 NVIDIA Releases GeForce Security Update Driver 582.28 for Legacy
Jan,31 2026 AMD 'Zen 6' CCD Packs 12 Cores, 48 MB L3 Cache
Jan,31 2026 Microsoft Set to Disable Legacy NTLM Authentication by Default in
Jan,30 2026 NVIDIA GeForce 591.86 WHQL Driver
Jan,30 2026 iOS 26.3-Important New iPhone Location Privacy Feature Coming Soon
Jan,29 2026 I Made the Ultimate Steam Machine Before Valve
Jan,29 2026 Wardriver - Official Trailer (2026) Dane DeHaan, Sasha Calle,
Jan,28 2026 Apple Intros Improved AirTag
Jan,28 2026 US Version of TikTok off to Bumpy Start; Competitors Surge
Jan,28 2026 Google Chrome no longer needs you, as Gemini takes the driving seat
Jan,27 2026 Premium Subscriptions Coming to Facebook, Instagram, WhatsApp
Jan,25 2026 Windows 11 Best For Gaming? Windows 11 25H2 vs. Windows 10
Jan,24 2026 Microsoft Says Uninstall This Windows Update Immediately (KB5077744
Jan,22 2026 Xbox Developer Direct Livestream 2026 | Fable, Forza Horizon 6,
Jan,22 2026 Iridium Begins Testing its own Satellite Service for Phones
Jan,22 2026 AMD Releases Adrenalin Edition 26.1.1 WHQL Drivers
Jan,18 2026 AI in 2050
Jan,17 2026 iOS 26.2 Fixes Major Security Flaws
Jan,17 2026 Google Links its AI to Your Gmail and Photos for "Personal
Jan,17 2026 Fastest Koenigsegg v Fastest Bugatti: DRAG RACE
Jan,17 2026 Creating a 48GB NVIDIA RTX 4090 GPU
Jan,14 2026 CES was frickin weird, guys
Jan,12 2026 Lee Cronin's The Mummy - Official Teaser Trailer (2026) Jack
Jan,12 2026 Ferrari SF90 XX v Xiaomi SU7 Ultra: DRAG RACE
Jan,10 2026 Welcome to the Wasteland - Fallout (American TV series) fan video
Jan,09 2026 GOOD LUCK, HAVE FUN, DON'T DIE Trailer 2 (2026) Sam Rockwell
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs