Recent Twats
- @PatrickElOso Today I don't feel like doing anything I just wanna lay in my bed Don't feel like picking up my phone, so leave a message...
- RT @RealGilbert: The RIP Eddie Murphy reports are false! The cops found a dead black guy and just assumed it was either Eddie Murphy or ...
- Why Twitter’s new policy is helpful for free-speech advocates - http://t.co/lMFgD7F1
Archives
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
Category Archives: malware
wtf
Posted in apple, hardware & software, malware, microsoft
Tagged anti-virus, apple, vmware
Leave a comment
REMnux: Distro for Reversers
Lenny Zeltser, SANS Instructor, has released a customized distribution targeted at malware reverse engineers. From the REMnux page: REMnux is designed for running services that are useful to emulate within an isolated laboratory environment when performing behavioral malware analysis. As … Continue reading
Malware Analyzers
(This article was originally published on June 9, 2009 — new resources added below) Do you ever receive a suspicious file via email or hesitant to download software from a webpage? You can upload the executable to one of the … Continue reading
win32 memory capture & analysis cheat sheet
A high level overview to perform live memory captures and analysis: capture memory via moonsol’s win32dd parse memory snapshot with mandiant’s memoryze analyze results via audit viewer or analyze using the volatility framework — neatly packaged in SAN’S Sift Workstation
Analyzing Malicious PDF Documents
So you want to get your feet wet? Grab Didier Stevens tools here: http://blog.didierstevens.com/programs/pdf-tools/ Grab malicious PDF samples here: http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&colsearch=All&quantity=50 *Be careful, these are live samples! Video Tutorial: Didier on analyzing a PDF Document: http://www.youtube.com/v/tHVi2wKCkTc You’re going to run into … Continue reading
Posted in forensics, malware, news, security
Tagged javascript, malware, pdf, re, tools
Leave a comment
Malware authors: Best storage / hiding locations
Have you just injected a running process’ memory? In most cases, unless your an adept author and have written a root-kit you want your malware to remain persistent via auto-run, registry, start-up etc. Where do you store your persistent launcher? … Continue reading
Posted in malware, security
Leave a comment
‘Analyzing Malicious Documents’ cheat sheet
Just saw this at the Internet Storm Center…Analyzing Malicious Documents Cheat Sheet Some really great info covering Microsoft Office documents and PDFs. Mentions some useful tools to help with analysis and the general approach to be followed depending on type … Continue reading
Posted in malware
Leave a comment
Zeus/Zbot Information and Tracking the Banking Trojan
Zeus is a crimeware kit, which steals credentials for various online services like social networks, online banking accounts, ftp accounts, email accounts and other (phishing). The web admin panel can be bought for $700 and the exe builder for $4000. … Continue reading
Posted in malware
Leave a comment
Malware Analyzers Part deuce
Several weeks ago I posted about different free malware analyzers (sandbox environments). I’ve stumbled across another free tool from Mandiant which is their Red Curtain offering. Red Curtain will scan a given local directory or drive and analyze each file … Continue reading
Posted in hardware & software, malware
Leave a comment