Ire identifies another LOTUSLITE specimen
microsoft.com原文 ↗
Microsoft Research 用 Project Ire 分析一个 LOTUSLITE 变体,重点是行为级 reverse engineering 能抓住 IOC 列表之外的样本。文章给出具体检测状态:该 DLL 在 5 月 28 日 VirusTotal 仅 1/72 vendor 标记,6 月 4 日变为 7/70;Ire 单次 decompiler-based run 输出 install routine、C2 packet layout、command IDs、persistence 和 obfuscation 等 function-by-function report。它展示了 agentic malware analysis 在 signature matching 之外的价值,也指出误读可疑函数名会带来 calibration 风险。
–浏览
评论 · Comments