每日 Harness 开源 · Source
返回本期 · Back to 2026-06-13

行业动态 · Industry News2026-06-13 · Saturday, June 13, 2026

Ire identifies another LOTUSLITE specimen

microsoft.com原文 ↗

Microsoft Research 用 Project Ire 分析一个 LOTUSLITE 变体,重点是行为级 reverse engineering 能抓住 IOC 列表之外的样本。文章给出具体检测状态:该 DLL 在 5 月 28 日 VirusTotal 仅 1/72 vendor 标记,6 月 4 日变为 7/70;Ire 单次 decompiler-based run 输出 install routine、C2 packet layout、command IDs、persistence 和 obfuscation 等 function-by-function report。它展示了 agentic malware analysis 在 signature matching 之外的价值,也指出误读可疑函数名会带来 calibration 风险。
浏览

评论 · Comments