Deep Analysis of New Poison Ivy/PlugX Variant – Part II

Credit to Author: Xiaopeng Zhang| Date: Fri, 15 Sep 2017 12:50:00 +0000
This is the second part of the FortiGuard Labs analysis of the new Poison Ivy variant, or PlugX, which was an integrated part of Poison Ivy’s code. In the first part of this analysis we introduced how this malware was installed onto victim’s systems, the techniques it used to perform anti-analysis, how it obtained the C&C server’s IP&Port from the PasteBin website, and how it communicated with its C&C server.
Read More



