Anyone know of more info on why this would be left in? A simple oversight? False-flag propaganda?
Where would I look for more information on fingerprinting binaries? I.e. perhaps identifying compiler and even build environment.
Thanks!
Anyone know of more info on why this would be left in? A simple oversight? False-flag propaganda?
Where would I look for more information on fingerprinting binaries? I.e. perhaps identifying compiler and even build environment.
Thanks!
https://securelist.com/blog/research/69203/inside-the-equati...
False flag is possible, but it's not unreasonable to think that these were uncaught mistakes, just ones that have no functional effect. The Mandiant APT1 report shows a similar pattern of bread crumbs, though in that case they felt more intentional (ego flourishes) to me.
As to your final question, that field is reverse engineering. If you're looking for tools, IDA Pro is a very powerful disassembler.
[0] https://www.google.com/url?q=https://securelist.com/files/20...