|
|
|
|
|
by KGIII
3170 days ago
|
|
Could UPX put something in the header that said something akin to, 'I am not a signifier of malware, perform your check on the internal contents instead.' Then AV companies could see that and not flag it as malware unless they had additional reason to think it was. That doesn't seem like it'd be terribly difficult but there's a good chance I'm missing something. |
|
They know it very well, but adding code to do decompression while performing scan is more complex and will surely reduce performance.
If the AV is already slow, they might decide to just label any UPX binary, since (let's not lie) most malware will be compressed with UPX or other tools.