Hacker News new | ask | show | jobs
by Terr_ 2448 days ago
I think that's less likely, if MS gets a thousand identical copies of a binary, they probably aren't going to bother test-analyzing more than one. There also might be some rate-limiting on what they'll do from a particular machine.

So your attack might require first controlling a swam of Windows 10 machines, in which case you might as well do it directly :P

1 comments

Who said anything about identical binaries? It's trivial to make two completely differently obfuscated binaries that do the same thing. If it were possible to determine behavior by static analysis, they wouldn't need to run it...