home *** CD-ROM | disk | FTP | other *** search
-
- N U K E E N C R Y P T I O N D E V I C E D E T E C T O R
-
- D E M O N S T R A T I O N V E R S I O N
-
- (C) 1993 by CSE Ltd.
-
- Computer Security Engineers Ltd. Computer Security Engineers Ltd.
- Main Office Reserach & Developement
- St. James House, New St. James Plc P.O. Box 45610
- St. Helier, Jersey JE4 8WH 2504 BA The Hague
- Canal Islands The Netherlands\n"
- Phone: +44 534 500 400 Phone: +31 70 3622269
- Fax : +31 534 500 450 Fax : +31 70 3652286
-
-
-
- N U K E E N C R Y P T I O N D E V I C E D E T E C T O R
-
- D E M O N S T R A T I O N V E R S I O N
-
- (C) 1993 by CSE Ltd.
-
-
- In 1992, a virus-author using the name Dark Avenger released a highly
- mutating polymorphic module called the Mutation Engine (MtE). Anti-virus
- developers all spent months to develope an accurate solution for this
- problem as vira using the MtE are able to have several million 'faces'.
- Even after one year since the MtE was first used, several notorious
- anti-virus programs are still not able to detect the MtE-based vira
- reliable.
-
- In January 1993, a new mutation engine called Trident Polymorphic
- Engine (TPE) was written and released by somebody calling himself
- 'Masud Khafir of the TridenT virus research group'. The TPE is based on
- the MtE, but solved several bugs which are present in the MtE. Furthermore
- the TPE has the ability to use almost every instruction within its
- decryption routine thus making it more difficult to detect it. There are
- no holes inside the generated decryption-routines like MtE generated
- decryption-routines which makes it less difficult to detect.
-
-
- In March 1993, the Research and Developemt Department of CSE receives
- another mutation engine called Nuke Encryption Device (NED) which is
- written by someone calling himself Nowhere Man. The source of NED, which
- also is received at CSE's R&D, show that the engine, version 0.90-beta,
- was written in October 1992. The engine has a length of 1355 bytes and
- covers, like TPE, some holes which were present in MtE. However, NED is
- not as sophisticated as TPE.
-
- "N.E.D. is easily be added to a virus. Every infection with
- that virus will henceforth be completely different from all
- others, and all will be unscannable, thanks to the Cryptex(C)
- polymorphic mutation algorithm."
-
- Despite the above quote from the source-listing, this detection-
- demonstration version proves that detection is possible. Though detecting
- NED-based vira is more difficult than MtE-based vira, it certainly is
- not as difficult as detecting TPE-based vira.
-
- The algorithm, which has been developed by Righard Zwienenberg of
- Computer Security Engineers Ltd, does detect the NED-based vira. The next
- version of PCVP-SCAN (Version 1.16) will include the algorithm which do
- detect these vira.
-
- Since users always want to test scanners and its algorithms, this
- special demonstration program has been created. The algorithm used within
- this program is almost equal to the one used in the scanner, but
- has been limited. It will detect all samples created by NED_DEMO.COM but
- might miss some NED-based vira. Needless to say that the scanner,
- PCVP-SCAN will detect these vira.
-
- Information about CSE and its products may be obtained from
- the above mail and telephone numbers. The author of the algorithm can
- be reached at these numbers as well.
-
- April 15, 1993 Righard Zwienenberg
-
-
-