TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Dyre Update: Moving to Edge and Windows 10 With Anti-Antivirus

2015-11-11 · Read original ↗

ATT&CK techniques detected

1 predictions
T1547.001Registry Run Keys / Startup Folder
77%
“, fortinet and trend micro. looking for the product path in the registry : figure 4 : looking for antivirus encrypted strings the hardcoded debug strings that used to make analysis much easier are now encrypted. they are decrypted only during runtime, so the static analysis revea…”

Summary

Dyre malware requires little introduction as it has been the focus of many publications, and it is a well-known threat. One of the reasons for it being so infamous is the frequent changes the authors incorporate in...