Using Machine Learning to Name Malware
lqdc.github.io
lqdc.github.io
This malware definitely isn't called kkrunchy. .kkrunchy is farbrausch's perfectly good executable packer for their 64k/etc demos. It is not malware, and it doesn't obfuscate (that wastes bytes!). ryg would probably be disappointed people are using it to wrap crappy hosts-file malware, and every AV should have a library of depackers handy anyway - the AVs detecting it as a generic are being disappointingly 1990s-era dumb.
People did the same with fsg and even UPX, of course, as well as a various commercial packers/obfuscators. I think the relinker generation of crunchers (crinkler, MEW, etc) tend to even have "please do not pack malware with this" licences as a result.
Would have been cooler if the content was also taken into account.
Regarding packers I agree, but it is kind of the same situation with every other packer, including Themida and VMProtect. So some AVs decided to call it by the name of the packer since they probably see a lot of malware packed with that packer and not much else.