Vault7: CIA Hacking Tools Revealed
Navigation: » Directory » Knowledge Base » Tech Topics and Techniques Knowledge Base » Personal Security Products (PSPs)
Owner: User #71473
F-Secure
SECRET//NOFORN
F-Secure is a PSPPersonal Security Product (Anti-Virus) vendor headquartered in Helsinki, Finland. In OSB's experience, F-Secure has generally been a lower tier product that causes us minimal difficulty. The only annoyance we have observed is that F-Secure has an apparent entropy-based heuristic that flags Trojaned applications or other binaries containing encrypted/compressed payloads. Two defeats are known to exist: On involves using RARFile compression algorithm file string tables in the resource section, the other involves cloning a RARFile compression algorithm file manifest file – the manifest technique also works against Avira's entropy-based heuristics.
F-Secure Product Line:
F-Secure Processes:
Process Names | |||||||
---|---|---|---|---|---|---|---|
Notes:
Defeats:
F-Secure & Avira Entropy Defeat
('include' missing)
SECRET//NOFORN