I'm no expert, but I'm also not convinced that the device contained malware.
> We sent the file for proper malware analysis which did confirm that it did indeed contain malware. The malware would collect user data and send it to a remote address. Presumably it would be a way to steal company information such as designs, accounts, and so on. Pretty shady stuff!
Or, you know, it might be doing anything at all on the internet. A reasonable question is "why should this device access the internet?" Good point, but my LAN-controlled "smart plug" connects to an NTP server in France. Who knows.
From the report:
> When verifying the [executable] signature, it was identified that
the malware did not have any signature assigned to it as shown in the figure below. It means that the file has a malicious activity.
Doesn't that mean that the image is not signed? Again, I'm not an expert, but to say "it means that the file has a malicious activity" smells like "I'll consider almost anything suspicious if it will convince you that this report is valuable." On the other hand, maybe that really is suspicious. I don't do this for a living.
> The process explorer and procmon helped to know that the malware created a child
process and then killed the process. It was also identified that the file did not have the signature but had the company name, and the path, confirming that it is a suspicious file from a legitimate organization. The regshot helped in getting the two snapshots of the registry, one before execution and one after malware execution. Therefore, it can be concluded that the file analyzed contains a trojan spyware which creates a child process that kills the original file when run. The malware collects user information and sends it to http://freedns.afraid.org/.
Again, the conclusion does not follow from the premises. Maybe spawning a child and killing the parent is something that you wouldn't normally do unless you were malware. Maybe English is not the author's first language, fine, but it does look like a poorly edited template.
For all I know, it's totally malware built for corporate espionage originating from a country notorious for doing that, but I don't see any compelling evidence.