ScatterBrain: Unmasking the shadow of PoisonPlug's obfuscator
cloud.google.com
cloud.google.com
That's some very heavy stuff.
Just as they have supplied IOCs, perhaps they could provide reasonable signatures or heuristic rules that scanners in various places might ingest and apply that might allow for the discovery of some latent copy of the compiler itself, which could be useful in and of itself, as well as for all of the possible breadcrumbs and inferences that could be made based on where/when it was spotted, if it was.
However, you can store a map of how instructions are placed and detecting cases where instructions overlap to different sequences should be a big red flag for an AV tool (that said, it's not impossible to disguise instruction targets enough that an analyser would need to be nearly Turing Complete to find even this).
So, still waiting for full pairipcore (the newer one) writeup.
I am quite reasonably sure this has been happening way before now based on my observation on prior control-flow obfuscators.
I worked on Unicorn, not the startup kind, but the multi-CPU-architecture emulator kind.
Also, I'm surprised there seems to be no mention in the article of why standard decompilation techniques fail (I might have missed it).
https://www.pwc.co.uk/issues/cyber-security-services/insight...
You can then use the hashes with platforms like virustotal to download some samples.