Join us for the Honeynet Workshop 2024: May 27th–29th, Copenhagen, Denmark

Waledac's Anti-Debugging Tricks

24 May 2010 Tillmann Werner anti-debugging malware waledac
The last spreading malware version of Waledac, a notorious spamming botnet that has been taken down in a collaborative effort lead by Microsoft earlier this year, contained some neat anti-debugging tricks in order to make reverse-engineering more difficult. Felix Leder and I have been presenting about the approach at SIGINT 2010 in Cologne yesterday, and as the method seems to be not publicly known yet, I will quickly describe it here as well.