Encrypted Malware Analysis
Secure Science Corporation (www.securescience.net) and Michael Ligh of http://mnin.org put together a paper on an interesting piece of malware. We include a removal kit and snort signatures. Source code and decryptor are available by request.
The paper can be found at:
http://ip.securescience.net/advisories/pubMalwareCaseStudy.pdfEnjoy.