It would be a bit complicated to hide malware in the binaries when you could just put quite "regular" malware implementations right into the binaries :-P That said, I never came across such a thing here in this board. But I'm very, very surprised that a Windows AV tool's heuristics trigger on a ZIP containing only Lua files and an ARM (!) ELF (!) executable. As for analysis: geekmaster has said it all.
|