<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System7 &#187; malware</title>
	<atom:link href="http://www.system7.org/category/security/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.system7.org</link>
	<description>Spread the word, information is free.</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:56:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>REMnux: Distro for Reversers</title>
		<link>http://www.system7.org/2010/07/26/remnux-distro-for-reversers/</link>
		<comments>http://www.system7.org/2010/07/26/remnux-distro-for-reversers/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 12:09:52 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ir]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=586</guid>
		<description><![CDATA[Lenny Zeltser, SANS Instructor, has released a customized distribution targeted at malware reverse engineers.  From the REMnux page: REMnux is designed for running services that are useful to emulate within an isolated laboratory environment when performing behavioral malware analysis. As part of this process, the analyst typically infects another laboratory system with the malware sample [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://zeltser.com">Lenny Zeltser</a>, SANS Instructor, has released a customized distribution targeted at malware reverse engineers.  From the <a title="REMnux: Reverse Engineering Malware Distribution" href="http://zeltser.com/remnux/">REMnux page</a>:</p>
<p><em>REMnux is designed for running services that are useful to emulate  within an isolated laboratory environment when performing behavioral  malware analysis. As part of this process, the analyst typically infects  another laboratory system with the malware sample and directs  potentially-malicious connections to the REMnux system that&#8217;s listening  on the appropriate ports.</em></p>
<p><em>REMnux is also useful for analyzing web-based malware, such as  malicious JavaScript, Java programs, and Flash files. It also has tools   for <a href="http://zeltser.com/reverse-malware/analyzing-malicious-documents.html">analyzing  malicious documents</a>, such as Microsoft Office and Adobe PDF files,  and utilities for reversing malware through memory forensics. In these  cases, malware may be loaded onto REMnux and analyzed directly on the  REMnux system without requiring other systems to be present in the lab.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/07/26/remnux-distro-for-reversers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Analyzers</title>
		<link>http://www.system7.org/2010/06/17/malware-analyzers/</link>
		<comments>http://www.system7.org/2010/06/17/malware-analyzers/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 16:22:45 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=212</guid>
		<description><![CDATA[(This article was originally published on June 9, 2009 &#8212; new resources added below) Do you ever receive a suspicious file via email or hesitant to download software from a webpage?  You can upload the executable to one of the malware analyzers below and they&#8217;ll run it through several different AVs and give you the [...]]]></description>
			<content:encoded><![CDATA[<p>(This article was originally published on June 9, 2009 &#8212; new resources added below)</p>
<p>Do you ever receive a suspicious file via email or hesitant to download software from a webpage?  You can upload the executable to one of the malware analyzers below and they&#8217;ll run it through several different AVs and give you the results. CWsandbox will also take a basic attempt to reverse engineering the app and let you know what type of handles it&#8217;s creating. Some very neat tools&#8230;.</p>
<ul>
<li><a href="http://www.virustotal.com/">http://www.virustotal.com/</a></li>
<li><a href="https://cwsandbox.org/">https://cwsandbox.org/</a></li>
<li><a href="http://anubis.iseclab.org">http://anubis.iseclab.org</a>/</li>
<li><a href="http://sandbox.norman.no/">http://sandbox.norman.no/</a></li>
<li><a href="http://www.joebox.org/">http://www.joebox.org/</a></li>
<li><a href="http://fileadvisor.bit9.com/">http://fileadvisor.bit9.com/</a></li>
<li><a href="http://www.mwanalysis.org/">http://www.mwanalysis.org/</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/06/17/malware-analyzers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>win32 memory capture &amp; analysis cheat sheet</title>
		<link>http://www.system7.org/2010/06/14/win32-memory-capture-analysis-cheat-sheet/</link>
		<comments>http://www.system7.org/2010/06/14/win32-memory-capture-analysis-cheat-sheet/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 12:33:25 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ir]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=518</guid>
		<description><![CDATA[A high level overview to perform live memory captures and analysis: capture memory via moonsol&#8217;s win32dd parse memory snapshot with mandiant&#8217;s memoryze analyze results via audit viewer or analyze using the volatility framework &#8212; neatly packaged in SAN&#8217;S Sift Workstation]]></description>
			<content:encoded><![CDATA[<p>A high level overview to perform live memory captures and analysis:</p>
<ol>
<li><strong>capture</strong> memory via <a href="http://moonsols.com/product">moonsol&#8217;s</a> <a href="http://moonsols.com/component/jdownloads/view.download/3/2">win32dd</a></li>
<li>parse memory snapshot with mandiant&#8217;s <a href="http://www.mandiant.com/products/free_software/memoryze/">memoryze</a></li>
<li><strong>analyze</strong> results via <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer/download">audit viewer</a></li>
<li>or <strong>analyze</strong> using the <a title="Volatility Framework" href="https://www.volatilesystems.com/default/volatility" target="_blank">volatility framework</a> &#8212; neatly packaged in <a title="SIFT Workstation Image" href="https://computer-forensics2.sans.org/community/siftkit/" target="_blank">SAN&#8217;S Sift Workstation</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/06/14/win32-memory-capture-analysis-cheat-sheet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing Malicious PDF Documents</title>
		<link>http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/</link>
		<comments>http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 11:50:00 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[re]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=513</guid>
		<description><![CDATA[So you want to get your feet wet? Grab Didier Stevens tools here: http://blog.didierstevens.com/programs/pdf-tools/ Grab malicious PDF samples here: http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&#38;colsearch=All&#38;quantity=50 *Be careful, these are live samples! Video Tutorial: Didier on analyzing a PDF Document: http://www.youtube.com/v/tHVi2wKCkTc You&#8217;re going to run into some heavily obfuscated JavaScript.  Read this article: http://isc.sans.org/diary.html?storyid=2358 Other deobfuscation tools: Malzilla, SpiderMonkey (need to [...]]]></description>
			<content:encoded><![CDATA[<p>So you want to get your feet wet?</p>
<ol>
<li>Grab Didier Stevens tools here: <a href="http://blog.didierstevens.com/programs/pdf-tools/">http://blog.didierstevens.com/programs/pdf-tools/</a></li>
<li>Grab malicious PDF samples here: <a href="http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&amp;colsearch=All&amp;quantity=50http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&amp;colsearch=All&amp;quantity=50">http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&amp;colsearch=All&amp;quantity=50</a> *Be careful, these are live samples!</li>
<li>Video Tutorial: Didier on analyzing a PDF Document: <a title="YouTube: Analyzing a malicious PDF document" href="http://www.youtube.com/v/tHVi2wKCkTc">http://www.youtube.com/v/tHVi2wKCkTc</a></li>
<li>You&#8217;re going to run into some heavily obfuscated JavaScript.  Read this article: <a href="http://isc.sans.org/diary.html?storyid=2358">http://isc.sans.org/diary.html?storyid=2358</a></li>
<li>Other deobfuscation tools: <a href="http://malzilla.sourceforge.net/">Malzilla</a>, <a href="http://www.mozilla.org/js/spidermonkey/">SpiderMonkey</a> (need to handle document.write), debug via <a href="http://www.mozilla.org/rhino/">Rhino</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/10345">Firefox add-on</a> (haven&#8217;t tried this one)</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware authors: Best storage / hiding locations</title>
		<link>http://www.system7.org/2010/01/26/malware-authors-best-storage-hiding-locations/</link>
		<comments>http://www.system7.org/2010/01/26/malware-authors-best-storage-hiding-locations/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:11:11 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=446</guid>
		<description><![CDATA[Have you just injected a running process&#8217; memory?  In most cases, unless your an adept author and have written a root-kit you want your malware to remain persistent via auto-run, registry, start-up etc.  Where do you store your persistent launcher?  A clever idea would be to determine what AV the victim is running &#8212; if [...]]]></description>
			<content:encoded><![CDATA[<p>Have you just injected a running process&#8217; memory?  In most cases, unless your an adept author and have written a root-kit you want your malware to remain persistent via auto-run, registry, start-up etc.  Where do you store your persistent launcher?  A clever idea would be to determine what AV the victim is running &#8212; if any <img src='http://www.system7.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />   Once you determine which AV is running you should check whether or not <a href="http://lmgtfy.com/?q=anti+virus+exclusion+locations">any files or directories are excluded from scanning</a>.  If so you&#8217;ve just found the perfect location for your loader.</p>
<p>Here&#8217;s what I&#8217;ve come up with so far:</p>
<p>AVG &#8211; Configuration files in binary format; No registry entries</p>
<p>Microsoft Security Essentials:  HKLM\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths</p>
<p>Trend: Check out these registry locations:</p>
<ul>
<li>HKLM\SOFTWARE\TrendMicro\NSC\TmProxy\WhiteList\;</li>
<li>HKLM\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Prescheduled Scan Configuration (ExcludedFile &amp; Excluded Folder keys)</li>
<li>HKLM\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration (ExcludedFile &amp; Excluded Folder keys)</li>
<li>HKLM\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Scan Now Configuration (ExcludedFile &amp; Excluded Folder keys)</li>
</ul>
<p>**Here&#8217;s a Microsoft KB article about their recommended locations for exclusion: <a title="Microsoft Recommended Anti-Virus Exclusion Locations" href="http://support.microsoft.com/kb/822158">http://support.microsoft.com/kb/822158</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/01/26/malware-authors-best-storage-hiding-locations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Analyzing Malicious Documents&#8217; cheat sheet</title>
		<link>http://www.system7.org/2009/12/07/analyzing-malicious-documents-cheat-sheet/</link>
		<comments>http://www.system7.org/2009/12/07/analyzing-malicious-documents-cheat-sheet/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 12:24:28 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=403</guid>
		<description><![CDATA[Just saw this at the Internet Storm Center&#8230;Analyzing Malicious Documents Cheat Sheet Some really great info covering Microsoft Office documents and PDFs.  Mentions some useful tools to help with analysis and the general approach to be followed depending on type of document.]]></description>
			<content:encoded><![CDATA[<p>Just saw this at the Internet Storm Center&#8230;<a href="http://zeltser.com/reverse-malware/analyzing-malicious-documents.html">Analyzing Malicious Documents Cheat Sheet</a> Some really great info covering Microsoft Office documents and PDFs.  Mentions some useful tools to help with analysis and the general approach to be followed depending on type of document.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/12/07/analyzing-malicious-documents-cheat-sheet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus/Zbot Information and Tracking the Banking Trojan</title>
		<link>http://www.system7.org/2009/10/20/zeuszbot-information-and-tracking-the-banking-trojan/</link>
		<comments>http://www.system7.org/2009/10/20/zeuszbot-information-and-tracking-the-banking-trojan/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 15:39:18 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=326</guid>
		<description><![CDATA[Zeus is a crimeware kit, which steals credentials for various online services like social networks, online banking accounts, ftp accounts, email accounts and other (phishing). The web admin panel can be bought for $700  and the exe builder for $4000. The dangerous thing is anyone with resources can use the Zbot builder and package new [...]]]></description>
			<content:encoded><![CDATA[<p><em>Zeus is a crimeware kit, which  steals credentials for various online services like social networks, online  banking accounts, ftp accounts, email accounts and other (phishing). The web  admin panel can be bought for $700  and the exe  builder for $4000. </em></p>
<p>The dangerous thing is anyone with resources can use the Zbot builder and package new variants making creating a definition difficult.</p>
<p>Once Zeus is on a system it uses covert methods of injecting additional fields into online Internet  banking websites, asking users to answer questions that the authentic website  would not ask. The collected details are then silently delivered to remote  websites, and added into remote databases. The databases are then sold to other  criminal elements down the chain who specialize in withdrawing the funds. The  money laundering groups anonymously hire physical people to withdraw money from  their personal accounts &#8211; in the criminal world these people are called &#8220;drops&#8221;,  and their accounts are called &#8220;drop accounts&#8221;.</p>
<p>The purchased builder is very granular; can you imagine logging in to your online banking website and additional fields appear that seem to blend into the page:</p>
<ul>
<li>Due to security measures, please provide the answers to all the security  questions listed below:</li>
</ul>
<ul>
<li>Your first school</li>
<li>Your mother&#8217;s maiden name</li>
</ul>
<ul>
<li>What is the first letter of the name of your high school?</li>
<li>What is the first letter of the name of your pet?</li>
<li>etc&#8230;</li>
</ul>
<p><a href="https://zeustracker.abuse.ch/">Zeus Tracking Project</a> (C&amp;C servers overlayed w/ Google Maps)</p>
<p><a href="http://blog.threatexpert.com/2009/09/time-to-revisit-zeus-almighty.html">Detailed Zeus reverse engineering</a></p>
<p><a href="http://www.veeple.com/link/48wBrdiCKJg%253D">Webinar about the bot</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/10/20/zeuszbot-information-and-tracking-the-banking-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Analyzers Part deuce</title>
		<link>http://www.system7.org/2009/07/17/malware-analyzers-part-deuce/</link>
		<comments>http://www.system7.org/2009/07/17/malware-analyzers-part-deuce/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 14:35:10 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[hardware & software]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=270</guid>
		<description><![CDATA[Several weeks ago I posted about different free malware analyzers (sandbox environments).  I&#8217;ve stumbled across another free tool from Mandiant which is their Red Curtain offering. Red Curtain will scan a given local directory or drive and analyze each file assigning it a threat score. It takes into effect whether the file is signed, packing, [...]]]></description>
			<content:encoded><![CDATA[<p>Several weeks ago I posted about different <a title="Malware Analyzers" href="http://www.system7.org/2009/06/09/malware-analyzers/">free malware analyzers (sandbox environments)</a>.  I&#8217;ve stumbled across another free tool from Mandiant which is their <a title="Mandiant Free Software" href="http://www.mandiant.com/software/freesoftware.htm">Red Curtain</a> offering. Red Curtain will scan a given local directory or drive and analyze each file assigning it a threat score. It takes into effect whether the file is signed, packing, and the entropy which could be suspicious.</p>
<p>Another plus is the tool can be remotely deployed which is great for LAN &amp; enterprise environments.</p>
<p>*I believe all their tools only run on Windows.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/07/17/malware-analyzers-part-deuce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
