Using cryptographic hashes to find malware, especially on Linux, works very poorly. In this video we will show you how trivial it is to change a binary to evade detection using hashes. With open source malware, it is simple and common to change malware to evade detection on Linux which makes hashes almost worthless for the job.
If you are going to hunt for malware on Linux, we recommend not using hashes and instead focusing on the tactics and techniques that make the malware work. For threat hunting it is vitally important to move away from using hashes to hunt for intruder activity.
Be sure to subscribe and follow us:
https://www.sandflysecurity.com
/ sandflysecurity
/ sandfly