4/4/08

Analysis of a Win32.Delf Variant

We have been noticing quite a few <strong class="keyword">malware</strong> samples having references to or communicating with Google’s SMTP servers ... DeDe is typically used, we chose DE Decompiler for experimental purposes. If you open the <strong class="keyword">malware</strong><br /><br />Posted in <strong><a rel="nofollow" target="_blank" href="http://technorati.com/blogs/http://www.pcsympathy.com">PC Sympathy - PC News and Technical Support</a></strong> (<a rel="nofollow" target="_blank" href="http://technorati.com/search/http%3A%2F%2Fwww.pcsympathy.com" style="color:#390;"><img src="http://static.technorati.com/images/bubble_h11.gif" alt="View Technorati URL search" style="border:none;"/> 17 links from 6 sites</a>) <br /><br /><img width="1" height="1" src="http://static.technorati.com/y/675425179.gif?anM9MCZyZWY9YXBpfC9zZWFyY2g/cXVlcnk9bWFsd2FyZSZsYW5ndWFnZT1lbiZrZXk9YmYyMjQ5ZjVhOTRmMzY1MmZjNjc0ODBjZWExYjg0MjQmZm9ybWF0PXJzc3wxfGh0dHA6Ly93d3cucGNzeW1wYXRoeS5jb20vMjAwOC8wNC8wNC9hbmFseXNpcy1vZi1hLXdpbjMyZGVsZi12YXJpYW50LyZ2aXNpdG9yaWQ9LSZ1c2VyaWQ9LSZzZXNzaW9uaWQ9ZjcxNWFkNzczNzYxNDcwNDc0NGMxYmUwZDQyZThkODQmdXNlcmNsYXNzPTEmYWJjbGFzcz1hJmFic3dpdGNoPTUmbWVtYmVyPS0="/>