Malware Activity
RSS Feed

mwcollect.org Blog

Malware Observations and Recent Threats

Defeating Allaple DB Polution

The pesky Allaple worm has bugged us long enough. Since it is polymorphic, each instance of this binary has a new, unique MD5 hash and hence appears as a new binary in the mwcollect Alliance repository. However, developing a certain hash function, I was able to group most of the Allaple binaries together, now appearing as a mere of 33 distinct entries in the Browse Specimens view:

PE Hash based Allaple grouping

I will disclose some of the details behind this in my talk on DeepSec.

Georg Wicherski // 2007-10-16 19:07 CET