Source |
Fortinet |
Identifiant |
409162 |
Date de publication |
2017-09-15 12:50:00 (vue: 2017-09-15 12:50:00) |
Titre |
Deep Analysis of New Poison Ivy/PlugX Variant - Part II |
Texte |
This is the second part of the FortiGuard Labs analysis of the new Poison Ivy variant, or PlugX, which was an integrated part of Poison Ivy's code. In the first part of this analysis we introduced how this malware was installed onto victim's systems, the techniques it used to perform anti-analysis, how it obtained the C&C server's IP&Port from the PasteBin website, and how it communicated with its C&C server. |
Notes |
|
Envoyé |
Oui |
Condensat |
analysis anti c&c code communicated deep first fortiguard from how installed integrated introduced ip&port its ivy ivy/plugx labs malware new obtained onto part pastebin perform plugx poison second server systems techniques used variant victim website which |
Tags |
|
Stories |
|
Move |
|