<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>New Reversing and Visualization Tools Released this Summer</title><description>2009-06-24 14:12:21 - Offensive Computing  Community Malicious code research and analysis :    A few conference acceptances are in so I can now lift the cone ofsilence and share some of the research I've been doingLately I've been using Artem Dinaburg and Paul Royal's excellent EtherMalware Analysis system they presented at ACM CCS last year This issome very good work that allows you to instrument a running binaryextremely well The paper they have written is very good I'vesubmitted some patches to the project and overall it's in good shapeI'll write up a more detailed post about using the Ether frameworklater Those of you that have been using Saffron should check out thissystem Even though it requires dedicated hardware it's a much morerobust systemUsing Ether I've been working on my visualization tool for betterdynamic and static analysis integration I call it VERA: VisualizingExecution for Reversing and Analysis Using the dynamic trace data andunpacking capabilities of Ether, VERA helps you to better unpackunknown binaries, reduce the reversing time, and generally make thewhole process easier I've shown it to a pretty limited set of people,mainly the students in my Reverse Engineering courses, and it seems tobe reasonably well receivedI will be talking about VERA at some conferences and workshops thissummer and fall The first is the Blackhat USA Briefings 2009 andDefcon 17 This talk will show how to integrate the reversing processinto using Ether and also demonstrating VERA I'll be giving a livedemo and release the tool hereA more formal treatment will be at the Workshop on Visualization andSecurity 2009 VizSec This paper will outline the nitty-grittydetails of the Reverse Engineering process and how VERA fits into itI hope to see you this summer Several former OC members will begiving talks too so it should be a worthwhile experienceread more</description><link>http://www.secuobs.com/revue/news/113101.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113101.shtml</guid></item>
<item><title>OfficeMalScanner released</title><description>Secuobs.com : 2009-06-01 05:56:22 - Offensive Computing  Community Malicious code research and analysis -    OfficeMalScanner is a MS office forensic tool to scan for malicioustraces, like shellcode heuristics, PE-files or embedded OLE streamsIt supports disassembly and hexview as well as an easy brute forcemode to detect encrypted files Next to this, an office file is beingscanned for VB-macro code and if found, it will be extracted forfurther analysishttp://wwwreconstructerorg/code/OfficeMalScannerzipEnjoyread more</description><link>http://www.secuobs.com/revue/news/104318.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104318.shtml</guid></item>
<item><title>Cyber Security Act of 2009</title><description>Secuobs.com : 2009-05-23 07:15:18 - Offensive Computing  Community Malicious code research and analysis -    The Cyber Security Act of 2009 submitted by US senators John JayRockefeller and Olympia Snowe looks like it is geared up to be somepoor US policy Joe Stewart has written up a response to it Joe makessome very valid observationsTo recap the criticism of the bill, there are two big complaints:First is that it gives the president the power to turn off theInternet in an emergency Second it requires mandatory licensing for"Infosec professionals" The second point is the one I take the mostissue withRequiring mandatory licensing for a field as dynamic and changing asours is just a bad idea There are already a couple of governmententities that require the CISSP as a condition of employmentSide-stepping a long winded rant about the CISSP, it is not anaccurate measure of knowledge There has been a concerted effort toliken our field to others such as electricians and generalcontractors The problem is that things are changing so fast, anycertification is basically worthless as soon as it is issuedSo if you're a US citizen please write your senators and encouragethem to revise this billread more</description><link>http://www.secuobs.com/revue/news/100927.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/100927.shtml</guid></item>
<item><title>Detecting Packers in Network Streams with Pynids and Pefile</title><description>Secuobs.com : 2009-05-21 00:54:52 - Offensive Computing  Community Malicious code research and analysis -    To step away from using snort as a base for detecting binary packers,I decided to go with a more direct approach and use a library thathandled stream reassembly within python I then simply took the dataonce the connection had closed, and scanned the data with PeFile Thepython script, which I call nPeID network peid, can either scan apcap if passed in as an argument, or sniff on an interface default iseth0http://wwwmalforgecom/node/12read more</description><link>http://www.secuobs.com/revue/news/99743.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/99743.shtml</guid></item>
<item><title>Reverse Engineering Sub-Reddit</title><description>Secuobs.com : 2009-05-08 08:34:41 - Offensive Computing  Community Malicious code research and analysis -    This might be considered old; but Rolf Rolles on OpenRCE has setup asub-Reddit dedicated to Reverse Engineeringredditcom/r/ReverseEngineeringIt's updated pretty often and has a lot of great articles Justthought I'd pass it alongread more</description><link>http://www.secuobs.com/revue/news/93540.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/93540.shtml</guid></item>
<item><title>Talk on Analyzing exploitable file formats at PH-Neutral</title><description>Secuobs.com : 2009-05-08 04:08:39 - Offensive Computing  Community Malicious code research and analysis -    Thorsten Holz and me are giving a talk at the next PH-Neutral A 31337invite-only conference from FX and the gang in Berlin Thorsten and iwill introduce several ways to analyze exploitable file formats,ranging from PDF and Flash to malicious Office files like PPT, DOC orXLS We will show some of the popular tools used for analysis and willalso present 2 new tools developed especially for maliciousOffice-file analysisI hope to meet a lot of interesting people again this yearCya on 29th and 30th May 2009 in Berlinread more</description><link>http://www.secuobs.com/revue/news/93455.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/93455.shtml</guid></item>
<item><title>Vista Wireless Power Tools</title><description>Secuobs.com : 2009-05-03 22:39:41 - Offensive Computing  Community Malicious code research and analysis -    Josh Wright from Inguardians has written a paper on Vista's wirelessstack He describes the NDIS6 command line interfaces and how to usethem in a pentest From the paper:"With the introduction of Windows Vista, Microsoft has put forthconsiderable effort in revamping the IEEE 80211 wireless stackthrough the Network Driver Interface Specification NDIS 6 modelWith considerably greater functionality and capability than wasprovided in Windows XP, Vista's wireless capabilities shine with newfreedom for developers, a robust development framework, richinformation sources for wireless analysis and end-user tools foranalyzing and controlling wireless parameters"I'm looking forward to doing some wifi research again and this papercertainly provides a healthy kick in the pants to do soread more</description><link>http://www.secuobs.com/revue/news/91565.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/91565.shtml</guid></item>
<item><title>On the Legitimacy of Obfuscated Code</title><description>Secuobs.com : 2009-04-18 04:02:12 - Offensive Computing  Community Malicious code research and analysis -    Chris Wysopal has written an article about different uses ofobfuscation inside of executables Malicious or not, it is a usefultool for hiding or at least raising the bar on reverse engineeringeffort required It's a good article and I recommend you read it Itdid get me to thinking about a couple of things in reverseengineeringOne thing that Chris mentions is that users should be able to decidewhether or not they want obfuscated code on their system In many waysthis is similar to the open vs closed source debate I have longargued that having the assembly for a program is equivalent to havingthe source code for a skilled reverse engineer Looking at enoughassembly and work with different compiler variations and one can workout what the original code looked likeRegarding the question about whether obfuscation is a bad thing, RolfRolles recently commented that Bitdefender decided wholesale that theVMProtect packer is malware and anything obfuscated with it should beremoved Now the Bitdefender developers are smart guys, and maybe theydecided that any legitimate software has no need to use this Otheranti-virus software takes a similar tactic During the Race To Zerocontest at Defcon last year, the winning team noticed that removingall the imports from an executable caused multiple AV vendors toautomatically flag an executable as being suspiciousThe choice about the legitimacy of packers and obfuscation has alreadybeen made for us by the AV community: It's bad This may be narrowsighted but hey, that's what the industry is all aboutread more</description><link>http://www.secuobs.com/revue/news/84974.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/84974.shtml</guid></item>
<item><title>iTunes Anti-debugging Circumvention</title><description>Secuobs.com : 2009-04-17 04:02:04 - Offensive Computing  Community Malicious code research and analysis -    David Maynor at Erratasec has written an article about how tocircumvent the debugging prevention inside of iTunes"I noticed iTunes kept crashing, predictably and reliably in thesame place I decided to use gdb to see what the hubbub was all aboutHowever I got dissed and iTunes would not allow itself to bedebugged"http://erratasecblogspotcom/2009/04/ode-to-50centhtmlread more</description><link>http://www.secuobs.com/revue/news/84536.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/84536.shtml</guid></item>
<item><title>Code injection</title><description>Secuobs.com : 2009-04-16 14:53:54 - Offensive Computing  Community Malicious code research and analysis -    Not a new concept for sureA new wave of more difficult to remove malware A new way of stealinginformation MaybeIn the last 6 months to a year it seems code injection and fileinfectors have "opened a new door" It's still seems to be the"replicate and destroy" but recently with infections like "Scribble""sality" "alman" and "virut" some changes have begun to show in this"angle of attack"Now instead of just replicating out of control the infections arereplicating crazily, but also bringing down fake-alerts and othernasty thingsread more</description><link>http://www.secuobs.com/revue/news/84210.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/84210.shtml</guid></item>
<item><title>Conficker Causes Global Meltdown and Thermonuclear War</title><description>Secuobs.com : 2009-04-01 19:29:23 - Offensive Computing  Community Malicious code research and analysis -    As usual, Brian Krebs from the Washington Post has done some finereporting bringing us news about the Conficker Worm Strike Here aresome choice excerpts of the horror that is raining down upon theworld:"A nuclear missile installation near Elmendorf Air force Base outsideof Anchorage, Alaska briefly went on a full-scale military alert aftertechnicians manning the bunker suspected that several of their controlsystems were infected with Conficker""According to local news reports, shortly after midnight local time,an ATM in the capital city of Reykjavik began spewing 100-Kronanotes"It's time to auger in with an AR-15 and your favorite dog Will Smith"I Am Legend" styleread more</description><link>http://www.secuobs.com/revue/news/78054.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/78054.shtml</guid></item>
<item><title>ConfickerC domain list for 1st April 2009</title><description>Secuobs.com : 2009-03-29 23:58:34 - Offensive Computing  Community Malicious code research and analysis -    http://wwwannysoftcom/confi/Domains_ConfickerCtxtby Taneja Vikashttp://wwwannysoftcom</description><link>http://www.secuobs.com/revue/news/76617.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/76617.shtml</guid></item>
<item><title>Analysis of Conficker C</title><description>Secuobs.com : 2009-03-20 06:36:56 - Offensive Computing  Community Malicious code research and analysis -    Phillip Porras, Hassen Saidi, and Vinod Yegneswaran from SRI haspublicly posted an excellent overview of the Conficker malware Theyeven have a great analysis of the C variant as well I highlyrecommend reading this excellent work"Conficker is one of a new interesting breed of self-updating wormsthat has drawn much attention recently from those who track malwareIn fact, if you have been operating Internet honeynets recently,Conficker has been one very difficult malware to avoid In the lastfew months this worm has relentlessly pushed all other infectionagents out of the way, as it has infiltrated nearly every Windows 2Kand XP honeypot that we have placed out on the Internet From lateNovember through December 2008 we recorded more than 13,000 Confickerinfections within our honeynet, and surveyed more than 15 millioninfected IP addresses from 206 countries"read more</description><link>http://www.secuobs.com/revue/news/73028.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/73028.shtml</guid></item>
<item><title>Why anti mal* is doing it wrong</title><description>Secuobs.com : 2009-03-02 21:56:30 - Offensive Computing  Community Malicious code research and analysis -    I had a presentation the other day at UNM on some of the work that Ihad done two years ago It's fascinating that there is such a renewedinterestA Kozakiewicz, A Felkner, P Kijewski, and T Kruk published a paper4/2007 after my DefCon presentation entitled "Application ofbioinformatics methods to recognitio of network threats" Theconclusion of this paper was that these the bioinformatics techniquesseem to have less resistance to polymorphism, however I maintain thatwas because of the simplicity of the scoring function they consideredOne of the starting papers in the field of using nature as a way tofigure out how to do things correctly was a 1994 paper "Principles ofa Computer Immune System" by A Somayaji, S Hofmeyr, and S ForrestThis spends a lot of time considering the acquired immune systemSo, how does nature do things differently than anti mal* There's alot out there on this topic I'd like to advance two points I've notseen elsewhere:*  Natural systems don't "root" the individual hosts, but the hostsprovide enough information via MHC II molecules to an immutablestatus of what each host is doing Anti-mal* is the opposite,wanting hooks into everything and itself being readily disabled*  There is no hesitation to kill hosts that are suspected infectedAmong many destruct mechanism is the FAS ligand activationpathway Think of this as a lever on the outside thatautomatically shreds the cell and makes it easy for the acquiredimmune system to improve future defense Note again that the cellis shredded; there is no "root" required for post mortemforensicsThese are just some ideas I hope to be getting them together in aformal paper sometime soon I look forward to commentsread more</description><link>http://www.secuobs.com/revue/news/66631.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/66631.shtml</guid></item>
<item><title>binBLAST release</title><description>Secuobs.com : 2009-03-01 21:35:49 - Offensive Computing  Community Malicious code research and analysis -    This is something that I've ignored for entirely too long, so Ifinally just did it instead of trying to pretty up the releasebinBLAST is now available via google code not SourceForge:binBLAST source codeThis is everything that was presented at DefConread more</description><link>http://www.secuobs.com/revue/news/66366.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/66366.shtml</guid></item>
<item><title>Why Full Disclosure is an Important Tool</title><description>Secuobs.com : 2009-02-27 06:56:04 - Offensive Computing  Community Malicious code research and analysis -    This latest Adobe vulnerability has created a stir on some of theclosed mailing lists regarding full disclosure While I would haveliked to think that this debate was over a long time ago, I nowrealize that everyone has disagreed to disagree On one side we havethe people that are doing remarkable work by researching these flaws,disclosing them with appropriate warning to the vendors, and lettingthe public know about the problems On the other side of the argumentare the limited disclosure peopleThe advocators of limited disclosure are excellent researchers who Iknow and respect It floors me to think that it is acceptable forvulnerabilities to be left unpatched for a serious amount of time Iconsider 90 days to be entirely too long to patch a vulnerability Thefact that Adobe said that a patch would be issued 18 days after thepublic disclosure is highly irresponsibleYou can disagree with full disclosure, but it is a useful motivationaltool Microsoft responded well to their problems They created asecurity development process that is unparalleled in the world Adobe,it's time for you to step up as well Limited or closed disclosurecreates complacency, which amounts to willful neglectI wish there was some other way than full disclosure to motivatevendors Unfortunately it is the only method available that has aproven track record of workingread more</description><link>http://www.secuobs.com/revue/news/65837.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/65837.shtml</guid></item>
<item><title>Conficker Unpacking and Analysis</title><description>Secuobs.com : 2009-02-20 02:19:50 - Offensive Computing  Community Malicious code research and analysis -    Lurene Grenier from Sourcefire's Vulnerability Research Team has agood writeup on a technique to unpack the Conficker worm DLL Thanksfor going through the pain of malware analysis Lurene"The goal was to take the dll, and make it spit out some dns trafficso we could test our SO rule conficker dns detection engine which waswritten with a generation algorithm provided through the MAPP programin conjunction with Microsoft We'd paired it down a good bit, andsome information about randomness from other write-ups around the netconflicted with what was provided to us"read more</description><link>http://www.secuobs.com/revue/news/63397.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/63397.shtml</guid></item>
<item><title>YARA v12 released</title><description>Secuobs.com : 2009-02-17 06:34:22 - Offensive Computing  Community Malicious code research and analysis -    A new version of YARA have been released This version introduces somebug fixes and new features, such as:* Sub-string alternatives in hex strings* Global rules* Enhanced "of" operator and a new "forof" operator* Anonymous strings* uintXX and intXX functions to read integers from a given offset* yara-python improvementsI've also started to create some rules for packer identification basedon PEiD's signatures, there are just a few for now, but I expect toinclude more in the futureread more</description><link>http://www.secuobs.com/revue/news/62382.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/62382.shtml</guid></item>
<item><title>Tracking Waledac</title><description>Secuobs.com : 2009-01-28 03:21:33 - Offensive Computing  Community Malicious code research and analysis -    Jeremy from Sudosecure has built a really impressive tool for trackingthe Waledac worm The primary communication system is via thefast-flux method, and Jeremy has built in a system to track countries,origins, and other domains He also provided a large collection of theWaledac executablesSudosecure Blog Post About the TrackerSudosecure Waledac Trackerread more</description><link>http://www.secuobs.com/revue/news/55787.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/55787.shtml</guid></item>
<item><title>Asprox</title><description>Secuobs.com : 2009-01-25 06:10:56 - Offensive Computing  Community Malicious code research and analysis -    1311f650aa1209a3ec962b6a9a38fc98Asprox sample from Mike Johnson of Shadowserverorg See his write uphere -- Asprox - It's Baaaaaaack</description><link>http://www.secuobs.com/revue/news/54936.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/54936.shtml</guid></item>
<item><title>Barack Obama and TrojanScriptIframer</title><description>Secuobs.com : 2009-01-21 06:29:14 - Offensive Computing  Community Malicious code research and analysis -    People have been reporting spam e-mail linking them to:hxxp://storeworldnewsdotxxxIt turns out to be a anti-Obama website; they make fake claims such as"Barack Obama's inauguration that was planned on 20th January 2009 isunder the threat of failure On the Eve of Inauguration DayPresident-elect Barack Obama made statement He declared that he isdefinitely NOT ready for this position Analysts say that Barack Obamahas refused to be next president because he recognized inconsistencyof his plan of stimulating USA economy"read more</description><link>http://www.secuobs.com/revue/news/53472.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53472.shtml</guid></item>
<item><title>Zerowine: Dumping malware and detection of antivm and antidebug</title><description>Secuobs.com : 2009-01-20 20:53:50 - Offensive Computing  Community Malicious code research and analysis -    I released a new version of Zerowine, a QEmu+Wine based malwareauto-analysis tool In this version I added support to dump themalware from memory while running The dumps can also be downloadedfor later analysis with IDA ProThe other feature I added is the ability to detect both anti-debuggingand anti-vm techniques The detection of anti-debugging techniques isdone by analyzing the APIs called by the malware while the anti-vmdetection is done by looking for patterns in both the packed versionof the malware the original one and the unpacked memory dumpversion of the malwareYou can download the latest version of Zerowine as a Prebuilt QEmuvirtual machine you can convert it to one VMWare image if you preferusing the help found in this blog or in source code formCheersread more</description><link>http://www.secuobs.com/revue/news/53253.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53253.shtml</guid></item>
<item><title>New Classmatescom Malware Campaign</title><description>Secuobs.com : 2009-01-13 21:30:48 - Offensive Computing  Community Malicious code research and analysis -    While reading through my spam folder, I found a new sample There is anew malware sample being spread posing as a Classmatescom reunionmessage The sample I have is MD5 895377d01833dfd01dfccb523b2d3026 Ihaven't done anything to analyze this file yetHere's the original email from my spam folder:Received: from 78219242 by hoemail1alcatelcom; Tue, 13 Jan 2009 18:09:56 +0100From: "Committee members" To: read more</description><link>http://www.secuobs.com/revue/news/51060.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/51060.shtml</guid></item>
<item><title>YARA: a malware identification and classification tool</title><description>Secuobs.com : 2009-01-07 03:28:50 - Offensive Computing  Community Malicious code research and analysis -    YARA is open-source multi-platorm tool that allows you to create yourown signatures to identify malware families based on text or hexstrings presents on samples of those families The signatures arewritten in a special-purpose language looking like this:rule silent_banker : banker{strings: $a = {6A 40 68 00 30 00 00 6A 14 8D 91}  $b = {8D 4D B0 2B C1 83 C0 27 99 6A 4E 59 F7 F9}$c = "UVODFRYSIHLNWPEJXQZAKCBGMT"condition:$a or $b or $c}Complex signatures can be created by using boolean operators,wild-cards, regular expressions and much more You can find moreinformation on the project site:http://codegooglecom/p/yara-project/read more</description><link>http://www.secuobs.com/revue/news/49223.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/49223.shtml</guid></item>
<item><title>Zero Wine: QEMU based malware auto-analysis</title><description>Secuobs.com : 2009-01-03 11:05:23 - Offensive Computing  Community Malicious code research and analysis -    Zero wine is an open source GPL v2 research project to dynamicallyanalyze the behavior of malware Zero wine just runs the malware usingWINE in a safe virtual sandbox in an isolated environment collectinginformation about the APIs called by the programThe output generated by wine using the debug environment variableWINEDEBUG are the API calls used by the malware and the values usedby it, of course With this information, analyzing malware's behaviorturns out to be very easyread more</description><link>http://www.secuobs.com/revue/news/48341.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/48341.shtml</guid></item>
<item><title>Wepawet: analyzing web-based malware</title><description>Secuobs.com : 2008-12-24 22:27:44 - Offensive Computing  Community Malicious code research and analysis -    Hello guysWepawet is a new service for detecting and analyzing web-basedmalware It currently handles Flash and JavaScript fileshttp://wepawetiseclaborgThings you can do with Wepawet:- Determine if a page or file is malicious- wepawet runs various analyses on the URLs or files that you submitAt the end of the analysis phase, it tells you whether the resource ismalicious or benign and provides you with information that helps youunderstand why it was classified in a way or the other- wepawet displays various pieces of information that greatly simplifythe manual analysis and understanding of the behavior of malicioussamples For example, it gives access to the unobfuscated maliciouscode used in an attack It also collects the URLs accessed by asample- wepawet does not just tell you that a resource is malicious, it alsoshows you the exact vulnerability or, more likely, thevulnerabilities that are exploited during an attackread more</description><link>http://www.secuobs.com/revue/news/46366.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/46366.shtml</guid></item>
<item><title>DNSChanger 20</title><description>Secuobs.com : 2008-12-21 20:15:11 - Offensive Computing  Community Malicious code research and analysis -    DNS Changer 20 TrojanFlushM is the next –in the wild- variant ofthis famous malware Now the strategy has been changed, no need tomodify the DNS settings on ADSL routers Instead it will install anetwork driver NDISProtsys which allows the malware to send/receiveraw Ethernet packets Such approach will help it bypass WindowsTCP/IP, FW and HIPSread more</description><link>http://www.secuobs.com/revue/news/45667.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/45667.shtml</guid></item>
<item><title>Comments on NYT article: A sneaky security problem, ignored by the bad guys</title><description>Secuobs.com : 2008-11-22 18:22:27 - Offensive Computing  Community Malicious code research and analysis -    Today I read an article on the New York Times website called A sneakysecurity problem, ignored by the bad guysNY Times: A Sneaky Security ProblemI had a conversion by phone and mail with its author Robert McMillanfrom IDG News before and I've answered him some questions about myRustockC research as he planned to write the above story There aresome quotes by Al Huger from Symantec in this article I would like tocomment, as I disagree to most of his statements regarding rootkitsread more</description><link>http://www.secuobs.com/revue/news/38094.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/38094.shtml</guid></item>
<item><title>Great Virtual Memory Overview by Mark Russinovich</title><description>Secuobs.com : 2008-11-19 07:34:32 - Offensive Computing  Community Malicious code research and analysis -    Virtual memory continues to be one of the things that people have alot of problems understanding There are lots of misconceptions abouthow this fundamental part of the operating system works MarkRussinovich has done an excellent job, as usual, distilling thisinformation into a very readable form I suggest you read his blogpost titled Pushing the Limits of Windows: Virtual Memory on thetechnet site</description><link>http://www.secuobs.com/revue/news/37054.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/37054.shtml</guid></item>
<item><title>Exploiting human weakness with AntivirusPro 2009</title><description>Secuobs.com : 2008-11-04 17:37:59 - Offensive Computing  Community Malicious code research and analysis -    Almost everyday our viewers ask us about Rogue anti-malware softwareOut of all of the questions we receive, the most common is “When willthese attacks stop” The sad truth is that we cannot see an end tothis problem in near sight As long as the malicious individuals areable to trick or force users into downloading, installing, andeventually paying for their fake “Rogue” anti-malware products, theywill continue to develop and push the envelopeMore information here751f86d2e478387fe0a507a1e6fd7b2dread more</description><link>http://www.secuobs.com/revue/news/33427.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33427.shtml</guid></item>
<item><title>MS08-067 Gimmiv Worm</title><description>Secuobs.com : 2008-10-24 20:17:40 - Offensive Computing  Community Malicious code research and analysis -    Here is the Gimmiv worm that was created for the latest Microsoftpatch Kudos to Microsoft for patching the flaw out of band and notsitting on itd65df633dc2700d521ae4dff8c393bffEnjoy</description><link>http://www.secuobs.com/revue/news/31582.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/31582.shtml</guid></item>
<item><title>Antivirus 2009 - 2 files added - 5 domains added Low Detection 1/36</title><description>Secuobs.com : 2008-10-23 16:26:24 - Offensive Computing  Community Malicious code research and analysis -    Today I came across a new Antivirus 2009 binary with a 1 out of 36detection ratio on VirusTotal The session starts atantivirus-bestcom and that page is reduced to a pop-up message, asusual Then we are briefly taken to voodoorevenuecom where theaffilliate information for the malware creators is sent and thenredirected to the point of download, protection-overviewcommore info hereb0674e8e6c99de286a62b2fde5358110read more</description><link>http://www.secuobs.com/revue/news/31319.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/31319.shtml</guid></item>
<item><title>Hacklu talk on RustockC</title><description>Secuobs.com : 2008-10-21 21:25:37 - Offensive Computing  Community Malicious code research and analysis -    On Thursday morning i will give talk on RustockC analysis at theHacklu in Luxembourg After the conference is over, i will publishthe slides on my site I hope there will be some interesting speechesand good discussions on security and malware-analysiscu @ the conferencecheers,frank</description><link>http://www.secuobs.com/revue/news/30934.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/30934.shtml</guid></item>
<item><title>Malware Challenge</title><description>Secuobs.com : 2008-10-17 15:03:18 - Offensive Computing  Community Malicious code research and analysis -    Participants should download the malware sample and analyze it Theend result should be a document containing details on the analysisperformed The analysis document can be written in any form, but thequestions and statements beow should be answered within itParticipants should note what questions are being answeredAll the rules here:http://wwwmalwarechallengeinfo/challengehtmlPrizes:http://wwwmalwarechallengeinfo/sponsorshtmlread more</description><link>http://www.secuobs.com/revue/news/30227.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/30227.shtml</guid></item>
<item><title>A new member of the Offensive Computing team - Dante Allegro </title><description>Secuobs.com : 2008-10-15 22:05:34 - Offensive Computing  Community Malicious code research and analysis -    Hello everyoneMy name is Dante Allegro , and as the newest member of the team my jobis to work with members of the commercial community who wish topurchase products and services from Offensive ComputingIf you or your company would like to utilize the Offensive Computingmalware database in your commercial product, or if you have a specificjob that you feel the Offensive Computing team can assist you with ,please contact me and I will be quite happy to assist youAs I am on the road quite a bit please contact me directly atallegrodante  at  gmailcom</description><link>http://www.secuobs.com/revue/news/29850.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29850.shtml</guid></item>
<item><title>Total Secure 2009</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    We discovered a new Total Secure 2009 domain today The binary thesite distributes is only detected by 3 out of 36 AV engines accordingto VirusTotal206d7b4425c01d9b5e839e7604da5531more information hereread more</description><link>http://www.secuobs.com/revue/news/29393.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29393.shtml</guid></item>
<item><title>YouTube Video Page Creator</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    Last week PandaLabs discovered a new tool for creating fake YouTubevideo pages as a way of deceiving users into installing malware Thevector for infection is similar to many fake codec based malwareattacks seen in recent weeks CNN, MSNBC, etcThe flexibility of this tool allows anyone to direct the fake AdobeFlash update error to any malicious executable file hosted on anyserver - this means that essentially a hacker could register severaldomains in different countries as seen in the CNN alerts attack andutilize a bot-net to distribute a mass amount of spam pointing tothese fake YouTube pagesFull Details Hereread more</description><link>http://www.secuobs.com/revue/news/29392.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29392.shtml</guid></item>
<item><title>New Rogue - eAntivirusPro</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    Today we discovered a new rogue called eAntivirusPro Afterresearching the new rogue we found that the template for the site wassold on a Russian Freelance site, which is one of the first templateswe have seen contracted from a public freelance sitemore info here8c396fbdacce214de2e86354a77350d2read more</description><link>http://www.secuobs.com/revue/news/29391.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29391.shtml</guid></item>
<item><title>Another Antivirus 2009 installer 0/36 on VirusTotal</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    We came across a fully undetected Antivirus 2009 installer todaySite:*hxxp://8517166170/go/cmp=nm_ron2etuid=f8a0d9628fbb11dd95e4166350cfffffetrid=gl2vmclretguid=5b20e5c3232d4440b6234368749a6d3aetaffid=166350etlid=httpeturl=http:%2F%2Fwwwgooglecom%2Fetv=1145etm=an2go hxxp://freeonlinescanner9com/_downloadphpaid=77052204etdlth=19+ hxxp://vassariumbigcom/download/av_2009exec074384af50971632df88de847c89233More info hereread more</description><link>http://www.secuobs.com/revue/news/29390.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29390.shtml</guid></item>
<item><title>BITS used as covert channel</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    Eric Landuyt from DataRescue analyzed a malware that exploitsBackground Intelligent Transfer Service BITS as a covert channelFrom the site:"A strange executable, named MSMSGSEXE, was found on several machineson the network of a customer, apparently dropped by the exploitationof a vulnerability inside Word files As monitoring toolsregistry/file/socket provided insufficient information on themalware's behaviour, we proceeded with a complete analysis"wikipedia : BITSread more</description><link>http://www.secuobs.com/revue/news/29389.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29389.shtml</guid></item>
<item><title>stubstub14_newmodWinSrvvbp</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    I found a VB malware inside WinRar sfx This malware retrieve adropper from a websitethat drop on hard disk a trojan TR/Buzusztk for AVIRAThe WinRar sfx extract on user TEMP folder two files, startexe andthe original Sfx archive,executing startexe the malware and the sfxThe malware get dropper from an URL hxxp://671595783/setupexeusing wininetInternetOpenUrlAThe dropper create on folder an exe file Setup_ver115852exe withtrojanstartexe089e63cfe70aebc52fe5b087cc5dd2a4setupexe799b4296dd74a2adaaf30b903759db82Setup_ver115852f42e34cedc6e5ff0957ec60d58b5f8daread more</description><link>http://www.secuobs.com/revue/news/29388.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29388.shtml</guid></item>
<item><title>Prevalence of Exploited PDFs</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    While the threat landscape has changed dramatically over the pastyears, attackers are becoming increasingly aggressive in exploringways to get into users’ systemA spammed email with an EXE attachment no longer penetrates the widernetwork or users, now that most home users and enterprise networkshave a certain level of awareness on information securityBut, how about spamming an exploited file like a PDFThe incidents of exploited PDF files are not isolated Instead, therehas been a consistent prevalence and recurrence of this threatFurther Readingread more</description><link>http://www.secuobs.com/revue/news/29387.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29387.shtml</guid></item>
<item><title>iPhone Users Vulnerable to URL Spoofing Attack  </title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    As I was reading my RSS feeds, I just noticed that Aviv Raff disclosedtwo vulnerabilities found in iPhone on Jewish new year Oct 2 But,to my surprise the phishing vulnerability isn’t new really  FurtherReadread more</description><link>http://www.secuobs.com/revue/news/29386.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29386.shtml</guid></item>
<item><title>e-cardexe threat Braviax + XP AntiSpyware 2009</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    A new wave of e-card malspam is going out The e-mail arrives spoofedas 123greetingscom and installs XP Antivirus 2009 once on thecomputer906d95a9d5aa5db06ebb24f7168de0feFull details hereread more</description><link>http://www.secuobs.com/revue/news/29385.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29385.shtml</guid></item>
<item><title>The End of Storm</title><description>Secuobs.com : 2008-10-15 15:50:52 - Offensive Computing  Community Malicious code research and analysis -    Dark Reading has posted a scandalous article about the end of theStorm worm"It’s been nearly a month now since the Storm botnet sent its lastspam run -- significantly long enough that botnet researchers nowconclude this could be the end of most infamous botnet once and forall"Malware rockstars Joe Stewart and Paul Royal have weighed in on thisand seem to suggest this is the case I'm sad to hear about thisbecause I had a lot of fun reversing the storm worm It was one of thegreat worms, but it's a good thing that it's no longer spreadingread more</description><link>http://www.secuobs.com/revue/news/29384.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29384.shtml</guid></item>
<item><title>Apple Fixed Piggybacking Issue in Software Update</title><description>Secuobs.com : 2008-04-21 17:02:49 - Offensive Computing  Community Malicious code research and analysis -    If you are using Apple application in Windows, i'm pretty sure youencountered thisCouple weeks ago there has been a series of reaction specificallythose who understands information security, criticizing about Safari31 piggybacking or stealth installation through Software Update fullstory hereThe interesting news, Apple listened and fixed this issue in itslatest Software Update tool for Windows version 21Apple fixed the issue by creating two sections: 1 Updates 2 NewSoftware This shows that Safari 31 is no longer piggybacking insoftware updates since it has its own category as New Software, whichis goodBut, the tick boxes were still filled-in by default full story hereread more</description><link>http://www.secuobs.com/revue/news/19679.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/19679.shtml</guid></item>
<item><title>Autorun Manager OSAM - utility which helps to find malware/rootkits at startup</title><description>Secuobs.com : 2008-04-14 09:02:16 - Offensive Computing  Community Malicious code research and analysis -    HelloWe developed a free utility Online Solutions Autorun Manager - OSAMthat helps to find malware/rootkits at computer's startup It may bevery useful for malware analysts, helpers and other usersHere is an overview and download linkI hope to find here a beta-testers for our software and get somefeedback and suggestions to improve it If you have any questions feelfree to contact meread more</description><link>http://www.secuobs.com/revue/news/18236.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/18236.shtml</guid></item>
<item><title>SANS - What Works In Penetration Testing and Ethical Hacking Summit  2008</title><description>Secuobs.com : 2008-04-11 07:31:57 - Offensive Computing  Community Malicious code research and analysis -    Las Vegas, NV May 31 - June 9, 2008HD Moore and Valsmith will be teaming up to teach a course on TacticalExploitation at SANS in Las VegasHere is the link to the course:Course Descriptionread more</description><link>http://www.secuobs.com/revue/news/17913.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/17913.shtml</guid></item>
<item><title>Large Batch of Kraken Samples</title><description>Secuobs.com : 2008-04-11 02:17:07 - Offensive Computing  Community Malicious code research and analysis -    Paul Royal was gracious enough to send a large collection of Krakensamples You can download them from the list here Thanks Paulread more</description><link>http://www.secuobs.com/revue/news/17876.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/17876.shtml</guid></item>
<item><title>Storm Worm Config file parser</title><description>Secuobs.com : 2008-04-08 10:32:04 - Offensive Computing  Community Malicious code research and analysis -    I have written a small Perl script that will extract the IP addressesand Port numbers from the Storm Worm configuration file Right nowthis file can be found on an infected machine in the C:windowsdirectory and is currently named "aromisconfig" This is a fairlysimple script to run and it contains the ability to parse multiplefiles as it accepts wildcard characters "*" and/or multiple filenamesIf your interested here is a link to it: storm_config_decoder_pl Feelfree to contact me if you have any questions or commentsread more</description><link>http://www.secuobs.com/revue/news/17030.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/17030.shtml</guid></item>
<item><title>Looking for Kraken Botnet malware sample</title><description>Secuobs.com : 2008-04-08 00:01:53 - Offensive Computing  Community Malicious code research and analysis -    Hey, just looking for a sample of the Kraken Botnet malware Itdoesn't seem to be posted up here, and I've emailed a couple ofresearchers</description><link>http://www.secuobs.com/revue/news/16953.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/16953.shtml</guid></item>
<item><title>RSA 2008: Reverse-Engineering Malware and Commercial Software Armoring</title><description>Secuobs.com : 2008-04-07 10:31:55 - Offensive Computing  Community Malicious code research and analysis -    If you're going to be at the RSA 2008 conference, please join myselfand Colin Ames in our talk "Reverse-Engineering Malware and CommercialSoftware Armoring" on Thursday April 10 at 9:10am in the ResearchRevealed track We'll generally be around the conference so be sure tosay helloHere's the abstract:"Protecting software from reverse-engineering has been a common goalof both commercial software and malware authors Anti-reverseengineering techniques will be demonstrated and methods ofcircumventing them will be presented A forensically soundkernel-based monitoring system will be shown as an effective way tomonitor and instrument running applications"read more</description><link>http://www.secuobs.com/revue/news/16733.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/16733.shtml</guid></item>
<item><title>How To Download DNSChanger DMG In Windows</title><description>Secuobs.com : 2008-04-07 07:31:54 - Offensive Computing  Community Malicious code research and analysis -    There has been an increase prevalence of DNSChanger DMG threats Thesecapture more attention but unfortunately some analysts cannot downloadthe right installer DMG file for MacWhyRBN's Trojan DNSChanger, also known as fake codec for Mac, serves twoexecutables: an EXE for Windows, and a DMG for Mac When a Windowsuser visits a malicious site, the user's browser sends the User-Agentinfo This contains information such as your OS, version, web browser,and language preference The malicious website then decides whichexecutable to serveread more</description><link>http://www.secuobs.com/revue/news/16724.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/16724.shtml</guid></item>
<item><title>Storm Worm Study</title><description>Secuobs.com : 2008-04-05 04:32:16 - Offensive Computing  Community Malicious code research and analysis -    I have just completed a web page where I present my work on the StormWorm I built a Crawler on the Overnet P2P network and some of theoutcomes i am getting are presented in this websitehttp://planeteinrialpesfr/~perito/I hope you enjoy it</description><link>http://www.secuobs.com/revue/news/16571.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/16571.shtml</guid></item>
<item><title>Storm Worm Hoax</title><description>Secuobs.com : 2008-04-02 06:07:51 - Offensive Computing  Community Malicious code research and analysis -    This year's April Fool's day trick was to post a near exact copy ofthe Storm Worm propagation page on our website The big change that Imade was to swap out the executable with a custom compiled one Thecode wasn't all that complicated It was just a normal Visual StudioWin32 console project with a single printf that said, "Yes it's ajoke :" I then swapped out the debugger file link with a link toYouTube Most people that downloaded and analyzed the file seem to getthe joke at that point but others took concern and were nice enough tonotify us of the problem The file even found it's way onto VirusTotalfor scanningHere are the complete number of people who downloaded the executablesover the day:foolsdayexe - 266 accesseskickmeexe - 220 accessesfunnyexe - 1991 accessesread more</description><link>http://www.secuobs.com/revue/news/15767.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/15767.shtml</guid></item>
<item><title>Sophos: RAPIL</title><description>Secuobs.com : 2008-04-01 07:32:26 - Offensive Computing  Community Malicious code research and analysis -    When they aren't busy misclassifying benign research tools as malware,Sophos Labs is busy developing new and exciting malware protectionTheir latest tool, RAPIL, detects a hacker writing evil programs Whenthis hacker is detected the computer is locked and the malware isprevented"An exciting day in SophosLabs After long and arduous efforts, weannounce our new beta technology offering to defeat the hackers, whichwe are currently referring to as RAPIL Recognition and Analysis ofPotentially Intruding Lifeforms"read more</description><link>http://www.secuobs.com/revue/news/15464.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/15464.shtml</guid></item>
<item><title>Updated Saffron-DI Code 02a</title><description>Secuobs.com : 2008-03-29 01:31:52 - Offensive Computing  Community Malicious code research and analysis -    I've fixed a bug inside the Saffron-DI code that was released at lastyear's Blackhat USA It should result in better dumps of executablesI've tested it out with the latest version of Intel's PIN As of thiswriting 23-17236, IA32Saffron-DI 02aInstallation instructions are on the original Covert Debugging postIf you have any bug reports please feel free to contact me and I'lllook into itThe kernel release of Saffron will be ready Real Soon NowTMread more</description><link>http://www.secuobs.com/revue/news/14583.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/14583.shtml</guid></item>
<item><title>W32/StormWormgen1 Network Analysis</title><description>Secuobs.com : 2008-03-24 06:02:33 - Offensive Computing  Community Malicious code research and analysis -    This is actually my first analysis of malware so the paper I wrote upmay not be as in depth as some may wish I cover the two files thatthe variant creates on the windows system, and provide packet captureanalysis I plan on diving deeper into research with a few peers fromRochester Institute of Technology, including SPARSA SecurityPractices and Research Student AssociationAbstract:This paper briefly details the analysis of W32/StormWormgen1Analysis includes thetwo files created by the variant and a look into the contents of thosefiles A quickoverview of the network traffic generated by the worm is displayed andthe dataexchanged between the peers who are connected to the Overnet P2Pnetwork Towardsthe end of the paper, extended research discusses the disassembly ofthe variant andwhere the process injection is found within the assembly codeDownload the PDF of the research hereI will eventually post more analysis here once I can find the timeread more</description><link>http://www.secuobs.com/revue/news/13326.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/13326.shtml</guid></item>
<item><title>IcePack Exploit Toolkit</title><description>Secuobs.com : 2008-03-23 07:06:58 - Offensive Computing  Community Malicious code research and analysis -    aa292347b32a4bc4f33e51a76ccc9446Browser based exploit code is broken down into seperate modules Itsstatistics engine logs several important user variables such as IP,Browser and OS version By default, it performs a check of thevisiting IP to determine if it's already been seen and if so thenavoids further interaction with that sessionread more</description><link>http://www.secuobs.com/revue/news/13206.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/13206.shtml</guid></item>
<item><title>Good Assembly Book: PC Assembly Language</title><description>Secuobs.com : 2008-03-19 06:01:59 - Offensive Computing  Community Malicious code research and analysis -    One persistent question I've run across every time I teach malwareanalysis or exploit writing is "What's a good book on assembly" Thereare a couple of books on the topic, but they either suffer from toomuch detail or focus on outdated operating systems Typically myresponse to anyone wanting to learn assembly of any type has been tocompile code, and then look at the resulting assembly outputPaul Carter has written an assembly book called PC Assembly LanguageFrom the website:"I taught Computer Science at the University of Central Oklahoma for10 years During this time I taught an introductory course in PCAssembly Language programming I grew frustrated at teaching 16-bitreal mode programming and decided to change to 32-bit protected modeHowever, I soon ran into a problem I could not find a textbook thatcovered 32-bit protected mode assembly programming So, I decided towrite my own"It's even been translated into French, Italian, German, Spanish,Simplified and Traditional Chineseread more</description><link>http://www.secuobs.com/revue/news/12266.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/12266.shtml</guid></item>
<item><title>A safer way to monitor Javascript in a web page</title><description>Secuobs.com : 2008-03-18 04:52:44 - Offensive Computing  Community Malicious code research and analysis -    Recently Val asked me to look over a html file that contained encodeddata that was decoded by javascriptIt sent me on a mission to find a way to redirect javascript output toa console rather than to a browser windowAs always, firefox is your friend I found this snippet onborngeekcom , tested it , and it works like a charm Once you makethe required changes to firefox, just edit the hostile javascriptreplacing " documentwrite " with " dump " and the output is sentto a console windowLogging to the Standard Console An alternative method of logging debuginformation is available through the standard console mechanismBefore this method can be used, several modifications to the browsermust be made First, we need to add a new browser preference In theURL bar in Firefox, type about:config and press enter Right click inthe list control and select the New » Boolean menu item to create anew boolean preference Give the preference a name ofbrowserdomwindowdumpenabled and set the value to trueThe next step is to add the "-console" command line parameter to yourFirefox startup shortcut Using this parameter will cause the standardoutput console window to appear each time you run Firefox Once thishas been done, and Firefox has been started, any output produced bythe dump function will appear in this console window The dumpfunction works just like the standard JavaScript alert function, sothe syntax is similarread more</description><link>http://www.secuobs.com/revue/news/11952.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/11952.shtml</guid></item>
<item><title>More Blog Spam / updateonlinecc</title><description>Secuobs.com : 2008-03-15 23:51:59 - Offensive Computing  Community Malicious code research and analysis -    UPDATE: Starting to tear apart the updateonlinecc guys Found severalinteresting urlshttp://updateonlinecc/winupdate/ice/exephp has an exe, will analyzesoonhttp://updateonlinecc/winupdate/stats/http://updateonlinecc/winupdate/ice/indexphphttp://updateonlinecc/winupdate/mpack9/indexphpSo assorted badness, mpack, redirects, iframes, etcSo we suffered some more blog comment spam on Offensive Computing inthe last couple of days This is basically the same stuff that we’veseen over and over So far I haven’t been able to find an EXE comingfrom this stuff but that doesn’t mean its not thereI started off by looking at the e-mail address the spammer subscribedfrom and then looking up all IP’s and domains involved I thenanalyzed some of the source code on one of the pages and looked atpacket captures and did some HTTP tamperingI’m finding myself wondering why they persist in doing this Is thissimply a vehicle for malware spreading Do they get money somehow forgetting people to hit the various websites Are they increasing theirgoogle rankings by having lots of blogs link to themread more</description><link>http://www.secuobs.com/revue/news/11518.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/11518.shtml</guid></item>
<item><title>more blog spam</title><description>Secuobs.com : 2008-03-15 04:21:43 - Offensive Computing  Community Malicious code research and analysis -    So we suffered some more blog comment spam on Offensive Computing inthe last couple of days This is basically the same stuff that we’veseen over and over So far I haven’t been able to find an EXE comingfrom this stuff but that doesn’t mean its not thereI started off by looking at the e-mail address the spammer subscribedfrom and then looking up all IP’s and domains involved I thenanalyzed some of the source code on one of the pages and looked atpacket captures and did some HTTP tamperingread more</description><link>http://www.secuobs.com/revue/news/11441.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/11441.shtml</guid></item>
<item><title>pBot - PHP Remote File Include Bug - Web based / PHP bot</title><description>Secuobs.com : 2008-03-14 10:47:00 - Offensive Computing  Community Malicious code research and analysis -    Speaking about PHP RFI vulns, this is a classic exampleThis is a web-based bot that uses PHP as it's base, and is similar toBlackEnergy DDoS bot in terms of operating out of the webOC Download pBot Source code rename extension to rarHere's the Rapidshare MirrorCheers :Kishread more</description><link>http://www.secuobs.com/revue/news/11176.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/11176.shtml</guid></item>
<item><title>Microsoft Security Advisory 947563 Vulnerability in Microsoft Excel Could Allow Remote Code Execution</title><description>Secuobs.com : 2008-03-13 20:44:52 - Offensive Computing  Community Malicious code research and analysis -    Just addedMD5: 2511f821af2d5bea80899bf2ce716b34</description><link>http://www.secuobs.com/revue/news/10684.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/10684.shtml</guid></item>
<item><title>VirusUnixbud analysis</title><description>Secuobs.com : 2008-03-13 20:44:52 - Offensive Computing  Community Malicious code research and analysis -    Today we'll analyze a simple Python virus that doesn't have a payloadie it only replicates: VirusUnixbud KAV name, md5:a92d1688f10401a5e3fd9102ef3a91c4This is a very simple virus It replicates only in the current folder,and it replicates in every python script at the first executionread more</description><link>http://www.secuobs.com/revue/news/10683.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/10683.shtml</guid></item>
<item><title>Storm Worm Process Injection from the Windows Kernel</title><description>Secuobs.com : 2008-03-13 20:44:52 - Offensive Computing  Community Malicious code research and analysis -    I spent a few hours looking at the storm worm and wrote up a quickinformal paper on how to extract the actual malicious payload Ifyou're interested in how to use asynchronous procedure call to injectcode into a userspace process this paper might be interesting to youStorm Worm Process Injection from the Windows KernelAbstract:This paper will detail the analysis methods of W32/StormWormgen1 andshow a process injection method it uses to run malicious code inuser-space This variant loads a driver into the kernel which theninjects itself into the running servicesexe process The worm thenconnects to a P2P network sending spam, initiating DDoS from theinfected computer This technique does not use a packer in thetraditional sense but a two-stage loader to inject itself into arunning process from kernel space I will show the decoding processand methods for extracting the true malicious code from the driverexecutableread more</description><link>http://www.secuobs.com/revue/news/10682.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/10682.shtml</guid></item>
<item><title>29A has left the building</title><description>Secuobs.com : 2008-03-01 21:02:21 - Offensive Computing  Community Malicious code research and analysis -    29A Group retired foreverhttp://vxorgua/29a/mainhtml+I tried to contact ValleZ for some time in order to take a decissiontogether about the future of 29A with no luck therefore I decided totake the decission alone And my decission is that 29A goes officiallyretired I feel this is fair because I am kinda the alpha and theomega of the group 29A was born in Dark Node, my BBS, and I am thelast active member of the group My last words as 29A member are forall the people that worked hard to make of this group the best one:Thank you very much Regards, VirusBuster/29Aread more</description><link>http://www.secuobs.com/revue/news/10050.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/10050.shtml</guid></item>
<item><title>Blog Spammer</title><description>Secuobs.com : 2008-02-26 22:43:42 - Offensive Computing  Community Malicious code research and analysis -    You might notice that from time to time we suffer from Blog CommentSPAM Generally we just delete it, block the user and move on HoweverI'm getting kind of tired of it so I decided to analyze the latestround that hit us a bit Heres the results so far:The Spam looks something like this, but with hyperlinks here andthere:The Spam:e9f195616015330be85dfe00e93c4fc3read more</description><link>http://www.secuobs.com/revue/news/9444.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/9444.shtml</guid></item>
<item><title>Tactical Exploitation Course</title><description>Secuobs.com : 2008-02-25 22:49:44 - Offensive Computing  Community Malicious code research and analysis -    HD Moore and I are partnering with the SANS Institute to offer anintensive two-day training class on Tactical ExploitationRegistration for this class starts NOW and only a limited number ofseats are available Please see the course description to sign uptodayV</description><link>http://www.secuobs.com/revue/news/9223.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/9223.shtml</guid></item>
<item><title>Analyze Malware-infections on your own - part two</title><description>Secuobs.com : 2008-02-25 11:06:28 - Offensive Computing  Community Malicious code research and analysis -    Today we will continue our talk about malware Let's go one stepforward to see how exciting it is once you get infected with malwareon your machine, then clean it I always call this process "CSI -Malware Analysis" Not yet broadcast folks Why Your antivirus isclueless, because either it's not up-to-date, or there are nosignatures yet You have to come to the rescue, or format the systemand loss your data, configurations, forgotten filesetc So, yourjob start when the antivirus stopsread more</description><link>http://www.secuobs.com/revue/news/8855.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/8855.shtml</guid></item>
<item><title>McAfee Site Advisor Gives us the Bad Rating</title><description>Secuobs.com : 2008-02-25 11:06:28 - Offensive Computing  Community Malicious code research and analysis -    McAfee SiteAdvisor is a service that is available to everyday users todetermine the "safety" of websites The idea behind it is that you canuse their software prior to visiting to determine whether or not youwant to visit a site It is very similar to the Google warnings, andStop Badware It was recently pointed out to me that OffensiveComputing is now officially listed as a bad siteI'm not upset by this, in fact, I think it's a really good idea tohave us listed here The big reason for this is that we do in factcollect and spread malware albeit for research purposes The type ofpeople that would use the SiteAdvisor service really have no businesscoming here It's a good thingIf SiteAdvisor actually rated us down because we distribute malwarethat would be a completely valid reason Instead the reason listed ontheir site at the time of this writing was the following:"When we tested this site we found links to reconstructerorg, whichwe found to be a distributor of downloads some people consider adware,spyware or other potentially unwanted programs"Frank Boldewin runs reconstructerorg and he makes valid contributionsto the field of research This entire conviction reeks of automatedscanning Since Frank analyzes real malware he probably had a sampleincluded in his files Since we link to his site happily I might addwe are therefore guilty This seems like an extremely naive way toperform a test of maliciousness What's more a quick glance of othermalicious sites reveals that we are in good company Examples of othermalicious sites include projects such as MetasploitUPDATE 2/21/2008 We are now officially listed as "good" Thanks McAfeeread more</description><link>http://www.secuobs.com/revue/news/8854.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/8854.shtml</guid></item>
<item><title>Not detected yet</title><description>Secuobs.com : 2008-02-25 11:06:28 - Offensive Computing  Community Malicious code research and analysis -    While checking my email yesterday at Hotmail I got an email from anicole smith The email was an attachment of what appeared to be avalid jpg file: "nicole256jpg" When I put my mouse on the image Inoticed the link on the status bar was not to the "nicole256jpg" filebut instead to another site"hxxp://20124111130/pics/nicole256php" needless to say, it was aspoofed link to an "exe" file I downloaded the file and scanned itwith avp kav 70 with the very latest definitions and it foundnothing Nope, not even as suspicious I have included 3 screenshots:what appeared as a suspicious string of the source code of the hotmailpage and 2 screen captures of the scan from virus total, severalscanners did register it as malware and a couple as suspicious Isthis a new technique/method of infecting For a long time now, hotmailhad always restricted almost all attachments but this one seemed toget by with no problemread more</description><link>http://www.secuobs.com/revue/news/8853.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/8853.shtml</guid></item>
<item><title>Analysis of an Obfuscated PHP Virus</title><description>Secuobs.com : 2008-02-25 11:06:28 - Offensive Computing  Community Malicious code research and analysis -    Recently, I received a copy of an obfuscated php "virus" OC hash:6891e6df8e053d3438af8a5404284361 It is not very complex, but thedeobfuscation process is very interesting I have the process andfunctionality analysis on my blog at isisblogspolyedu By the way,this iCTF 2007 challenge is something else you can check out if youlike deobfuscating phpThe PHP code was collected from a working server after unusual trafficpatterns were noticed After the machine was compromised not in scopeof this description, the code was injected It listened to andexecuted commands passed through a POST request with ‘www’ userprivileges Some of the commands that were run include id, pwd as wellas directory searches and wgets of various files The compromisedmachine also served as a hop in a pharmacy ad delivery scheme Itredirected HTTP requests for medications to a possible ‘mothership’server There is evidence that links to our server were posted as adson websites like MySpaceI have found descriptions of similarly obfuscated filed on blogs suchas arbornetworks, cyberlot and waraxe So there must be an obfuscatorthat does this If anyone knows what it is please let me know, I'dlike to check it out Anyway, the obfuscation on the file I providedseems to be slightly more complex then the links I gave So there mustbe good options on that obfuscator that allow specification of howmany iterations to do etcThe mothership adware server is still alive at the time of thiswriting link in my blogread more</description><link>http://www.secuobs.com/revue/news/8852.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/8852.shtml</guid></item>
<item><title>VMware Vulnerability: Time to Upgrade</title><description>Secuobs.com : 2008-02-25 11:06:28 - Offensive Computing  Community Malicious code research and analysis -    Core Security found a pretty spectacular vulnerability in Vmware Ifyou have shared folders with the guest OS a program running inside theVM can modify any file on the host Given how dependent we are on VMsfor malware analysis it would be a good idea to upgrade Hats off toCore for finding this bug"A vulnerability was found in VMware's shared folders mechanism thatgrants users of a Guest system read and write access to any portion ofthe Host's file system including the system folder and othersecurity-sensitive files Exploitation of this vulnerability allowsattackers to break out of an isolated Guest system to compromise theunderlying Host system that controls it"read more</description><link>http://www.secuobs.com/revue/news/8851.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/8851.shtml</guid></item>
<item><title>Shmoocon 2008: Malware Software Armoring Circumvention Content</title><description>Secuobs.com : 2008-02-17 17:47:00 - Offensive Computing  Community Malicious code research and analysis -    We just finished giving our talk at Shmoocon 2008, which is a slightupdate of our Blackhat 2007 talk Under great peer pressure we decidedto give a live demonstration of Saffron-kernel It crashed the firsttime but the second attempt worked well We unpacked two sets ofpackers live on stage: TeLock and Vmprotect Afterwards we were evenable to unpack a random binary from the audience Thanks to theShmoocon organizers and everyone who got up early to see our talkPresentation PDFOriginal Saffron DI code This is our material from Blackhat 2007 Thisis a proof of concept, and not production codeShmoocon is a really nice conference If you get a chance to attend Ihighly recommend itAbstractSoftware armoring techniques have increasingly created problems forreverse engineers and software security analysts As protections suchas packers, run-time obfuscators, virtual machine and debuggerdetectors become common, newer methods must be developed to cope withthem In this talk we will present our forensically sound debuggingplatform named Saffron Saffron is based upon dynamic instrumentationtechniques as well as a page fault assisted debugger We show that thecombination of these two techniques is effective in removing armoringfrom most software armoring systemsread more</description><link>http://www.secuobs.com/revue/news/8239.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/8239.shtml</guid></item>
<item><title>More advanced unpacking - Part II</title><description>Secuobs.com : 2008-02-15 17:06:40 - Offensive Computing  Community Malicious code research and analysis -    With "More advanced unpacking - Part II" I show you how to decrypt aninfamous real-life malware called WSNPOEM, aka InfostealerBankerCThe binaries are usually created with a tool called ZEUS Builder, andthere exist lots of different versions in the wild I found sampleswith and without rootkit functionality They are also "ontop" packedbinaries, meaning they are additionally protected/packed with toolslike Aspack, ACProtect, Polycrypt and so forth We will discuss all 3types and how to deal with them in 3 different ways1 Manual unpacking + import fixing2 Manual unpacking + Auto import fixing3 Auto unpacking/import fixingStage 2 introduces a nice tool called "Universal Import Fixer" andStage 3 shows how to automate unpacking/import fixing withOllyDbgScriptFind the information on Reconstructerorgread more</description><link>http://www.secuobs.com/revue/news/7864.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/7864.shtml</guid></item>
<item><title>Shmoocon 2008: Malware Software Armoring Circumvention</title><description>Secuobs.com : 2008-02-12 13:38:51 - Offensive Computing  Community Malicious code research and analysis -    Val and I will be speaking at Shmoocon 2008 showing off our malwareunpacking techniques The talk is Sunday at 10am during the "BreakIt" session If you can't make it but are in the area let us know,we'll be around for the entire weekend This talk will be similar tothe one we gave at Blackhat USA 2007 however we'll also be talkingabout building an effective hardware based analysis systemAbstractSoftware armoring techniques have increasingly created problems forreverse engineers and software security analysts As protections suchas packers, run-time obfuscators, virtual machine and debuggerdetectors become common, newer methods must be developed to cope withthem In this talk we will present our forensically sound debuggingplatform named Saffron Saffron is based upon dynamic instrumentationtechniques as well as a page fault assisted debugger We show that thecombination of these two techniques is effective in removing armoringfrom most software armoring systemsread more</description><link>http://www.secuobs.com/revue/news/6627.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/6627.shtml</guid></item>
<item><title>Sophos Contact</title><description>Secuobs.com : 2008-02-12 13:38:51 - Offensive Computing  Community Malicious code research and analysis -    Could someone from Sophos please contact usinfo @ offensivecomputing  netThanksV</description><link>http://www.secuobs.com/revue/news/6626.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/6626.shtml</guid></item>
<item><title>Analyze Malware-infections on your own - part one</title><description>Secuobs.com : 2008-02-12 13:38:51 - Offensive Computing  Community Malicious code research and analysis -    To start working on malware analysis there are two ways: the hard wayand the easy way The hard way depends on advanced level of knowledgeabout assembly language, operating systems, programming languages c,c++, vbscript, javascript, perl, pythonEtc, andreverse-engineering This part has been covered by the antivirusvendors and independent security researchersThe easy way depends on a high-level of skills about operatingsystems, networking, batch scripting, and security If you have therequired skills you can choose which way to follow Today I’ll showyou how to use free and easy to get tools, with some skills to recoveryour infected machineread more</description><link>http://www.secuobs.com/revue/news/6625.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/6625.shtml</guid></item>
<item><title>Basic mIRC socket bot</title><description>Secuobs.com : 2008-02-12 13:38:51 - Offensive Computing  Community Malicious code research and analysis -    Many people use mIRC bots in their IRC channels, some even use themfor botnets, as I made the R2C bot This bot is a socket bot which isvery easy to use Though, it will require a bit of mIRC scriptknowledge The script is commented, and to make it easier tounderstand, I have putted it on Pastebin to make it readable withcolorsI don't know what more to say, I just hope people will find this'script' useful, and if there's anything you don't understand, orfound a bug which MIGHT be somewhere in the script, don't rememberlet me know- Link to the scriptread more</description><link>http://www.secuobs.com/revue/news/6624.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/6624.shtml</guid></item>
<item><title>Random News</title><description>Secuobs.com : 2008-02-08 15:27:01 - Offensive Computing  Community Malicious code research and analysis -    Alot of things you should know about going on right nowMetasploit released a new version / update of the metasploit frameworktoday This update includes a GUI for windows, check it outAlso there is a new issue of Uninformed out today that you shoulddefinitely check outDon't forget that Danny and I are speaking at Shmoocon and RSA 2008More important news coming soonV</description><link>http://www.secuobs.com/revue/news/6047.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/6047.shtml</guid></item>
<item><title>New Storm Strand Encryption key</title><description>Secuobs.com : 2008-02-08 11:04:59 - Offensive Computing  Community Malicious code research and analysis -    I've downloaded and analyzed the last strand of the storm worm and asmany of you know, the p2p payload it's encrypted nowI'm mostly interested in its network behavior, so has anyone of youfound what the encryption key is I would really appreciate thisinformation or a link to some article that talks about itIn case nobody knows: how would you proceed to find the key in thedisassembled code Any ideas on the techniques/tools to be usedThx</description><link>http://www.secuobs.com/revue/news/5741.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/5741.shtml</guid></item>
<item><title>Backdoor: PHP/ObfuA readable code</title><description>Secuobs.com : 2008-02-03 05:13:20 - Offensive Computing  Community Malicious code research and analysis -    I was boredhttp://pastebincom/fbccb9f2</description><link>http://www.secuobs.com/revue/news/4742.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/4742.shtml</guid></item>
<item><title>An idea that never materialized</title><description>Secuobs.com : 2008-02-03 05:13:20 - Offensive Computing  Community Malicious code research and analysis -    Warning: This happens to be an OFF Topic Post, sort of a rantIt's too bad that we didn't see the potential to develop somethingsimilar here in Offensive computing, even upon a bare idea and somesmall support from one guy who said it's a nice idea to have astandard for testing AVsToday this is here on http://wwwsecurityfocuscom/news/11502Just felt like, aww, that's something I thought, and it nevermaterialzed ;Cheers :Kish</description><link>http://www.secuobs.com/revue/news/4741.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/4741.shtml</guid></item>
<item><title>Pay-per-Install A Malware Retail Business</title><description>Secuobs.com : 2008-02-03 05:13:20 - Offensive Computing  Community Malicious code research and analysis -    Organize cyber-criminals introduces a new retail businessPay-Per-Install This business primarily entice webmaster to join thegang and promises to pay 350$ for every 1000 installThe deal behind this is you have to register or sign up for anaccount Then, they will reply with your login credentials and link toyour installerDetailed info found at iantivirusread more</description><link>http://www.secuobs.com/revue/news/4740.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/4740.shtml</guid></item>
<item><title>The basics of Remote File Inclusion</title><description>Secuobs.com : 2008-02-02 13:22:51 - Offensive Computing  Community Malicious code research and analysis -    Many people have heard of it, seen it, and may have tried it But dothey really know what it does Because there are still a lot of peoplewho do not know what RFI Remote File Inclusion actually is, or does,I have decided to write a little tutorial about it It willbasically just explain and 'show' how RFI actually works, and help youunderstand the basicsAfter reading this, you should be able to recognize RFI's, and youwill be able to find and use it At least, that's what I thinkSince this is my first 'tutorial', I would like to have your opinionon it, so leave me a comment- KnickLighter's Tutorialread more</description><link>http://www.secuobs.com/revue/news/4708.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/4708.shtml</guid></item>
<item><title>News you should know</title><description>Secuobs.com : 2008-01-29 00:10:31 - Offensive Computing  Community Malicious code research and analysis -    Alot of things you should know about going on right nowMetasploit released a new version / update of the metasploit frameworktodayThis update includes a GUI for windows, check it outAlso there is a new issue of Uninformed out today that you shoulddefinitely check outDon't forget that Danny and I are speaking at ShmooconMore important news coming soonV</description><link>http://www.secuobs.com/revue/news/3851.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/3851.shtml</guid></item>
<item><title>More advanced unpacking - Part I</title><description>Secuobs.com : 2008-01-23 10:54:57 - Offensive Computing  Community Malicious code research and analysis -    Unbelievable but true After 4 months of getting owned by other thingsmaking my life mad, i finally managed to release a new unpackingtutorial This one goes far more into depth as the beginners tutoriali have released last year It aims to show some generic tricks andtools, that can be used on many other protectors EnjoyFind the files hereread more</description><link>http://www.secuobs.com/revue/news/2328.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/2328.shtml</guid></item>
<item><title>Cisco bot - Source code</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    This is a bot used to scan for Cisco devicesDownload the source hereCheers :Kish</description><link>http://www.secuobs.com/revue/news/883.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/883.shtml</guid></item>
<item><title>Analyzing VM-detecting malware</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    About a year ago, I read something about VM-detecting malwareAfter studying this subject, there were a few thoughts which came tomindFirst thought was "How to analyze the behaviour/payload ofVM-detecting malware without the use of a Virtual Computer, withoutsacrificing your computer, without the need to re-install your OSafter the analysis =infectionAccording to a SANS-Article this can be addressed either by patchingthe malware so it doesn't look for signs of VM environments, or bymaking changes to the VM environment that will trick the malwareread more</description><link>http://www.secuobs.com/revue/news/882.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/882.shtml</guid></item>
<item><title>XKCD Is Great</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    IMAGE</description><link>http://www.secuobs.com/revue/news/881.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/881.shtml</guid></item>
<item><title> Russian Business Network study</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    For Reading - Russian Business Network studyThere are some places in the world where life is dangerous Internethas some dark zones too and RBN is one of them RBN stands for RussianBusiness Network and its a nebulous organisation which aims to fulfilcyber crimeThis study aims to provide some enlightenment on RBN activities andtries to detail how they work Indeed RBN has many constituents andits hard to have an exact idea on the goal of some of them and theway theyre linked with other constituentsThere are some countermeasures available but they don't make sense forhome users or even companies Only ISPs, IXPs and internet regulatorscan help mitigating risks originating from RBN and other maliciousgroupsYou may download, the pdf in these links:+ http://research-labsnet/news/13-Russian+Business+Network+studyhtml+ wwwbizeulorg/files/RBN_studypdfjust fyiRegards,~ Zenoread more</description><link>http://www.secuobs.com/revue/news/880.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/880.shtml</guid></item>
<item><title>Mpack Toolkit - Source code</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    The Mpack toolkit has been uploaded to rapidshare I searched thedatabase and found only the dreamhack tool the compiled form and Ithought it would make sense to upload the source for our members ;Click here to download the source code from RapidshareOC Download c0ff6e3db8afa6bf598e54afe351d795 rename extension torarPassword: "infected"Just tried it on a machine, the contents of the archive are,read more</description><link>http://www.secuobs.com/revue/news/879.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/879.shtml</guid></item>
<item><title>Tiger Team Premier</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    Recently our friends from Colorado hello 303 had a TV show aboutpenetration testing made about them called Tiger Team It wasfeatured on Court TV, now Tru TV, and features them trying to breakinto various businesses The two episode pilot showed them breakinginto a luxury car dealership as well as a Beverly Hills jewelry storeIn each of the episodes the team relies on social engineering,physical security, and computer security techniques to gain completeand total access to the businesses in question and breach theirsecurity almost entirely Delchi, a main contributor at OffensiveComputing, designed and built the HID cloner that was used in thejewelry store episodeI really hope that this TV series takes off for a couple of reasonsFirst, it is very representative of real-world vulnerabilities which Ihope will inspire people to take a deeper look at their securitySecond, the show is very entertaining and I know weve added a fewmore tricks to our penetration tests We at Offensive Computing engagein similar activities, albeit more towards the software side of thehouse, and its good to see this taking a more mainstream appeal Ifyou have the opportunity to watch the episodes I highly recommendthemread more</description><link>http://www.secuobs.com/revue/news/878.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/878.shtml</guid></item>
<item><title>Another Analysis of the Storm Worm</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    When you search the internet for analysis of the Storm Worm, you'llfind a lot of them I don't want to re-invent the wheel, but I justlike doing dynamic analysisA few days ago I was collecting some variants of the Storm-worm akaPeed, Nuwar, Zhelatin, Peacom and did a Virus-Identification with mycurrent AV F-Secure One of the samples was detected asEmail-WormWin32Zhelatinpt and I was curious about a description ontheir website; but it wasn't there Google, and other search enginescouldn't help me, and also a search for the checksum didn't give memore information So I decided to do an analysis by myself And it wasvery interesting to see the activity of this wormAfter executing the sample, internet traffic increased heavily Myfirewall Sygate alerted every second  with a new warningHere a summary of the analysis, if you're interested in the wholeanalysis contact me:ChatoFlores AT mysecuritynlread more</description><link>http://www.secuobs.com/revue/news/877.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/877.shtml</guid></item>
<item><title>Storm: System Modifications and How to Remove</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    A few days ago I wrote about the huge internet-traffic, caused by theStorm-WormThe last days I spent some time for the analysis of thesystem-modifications and for making a removal-procedure and of courseI want to share my results with all of youread more</description><link>http://www.secuobs.com/revue/news/876.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/876.shtml</guid></item>
<item><title>BackdoorW32SmallPF</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    A long time has passed since my first analysis paper, but here isanother one This time its short and small The package contain allthe necessary files to get you started on understanding the malware Ihope its better than my last paper You can check my blog for moredetails and to download the analysis package</description><link>http://www.secuobs.com/revue/news/875.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/875.shtml</guid></item>
<item><title>MBR Rootkit</title><description>Secuobs.com : 2008-01-12 08:09:42 - Offensive Computing  Community Malicious code research and analysis -    Here is a copy of the MBR rootkit that has been getting press latelyMD5: 88ffe413ce04294cc0ed8c4d163f1c31</description><link>http://www.secuobs.com/revue/news/874.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/874.shtml</guid></item>
</channel>
</rss>
 
<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>State of Offensive Computing</title><description>2012-07-07 21:45:34 - Offensive Computing   Community Malicious code research and analysis :    I would like to take this time to thank everyone that expressed their support while Offensive Computing was offline It was a trying time and I really appreciate everyone's support Without getting into any of the specifics of why the site was offline for two months, we are back and here to stay There are a couple of people who were instrumental in helping to keep everything up and running Paul Royal, from the Georgia Tech Information Security Center helped out significantly with hardware and the new home of the site Kelcey Tietjen also stepped in and helped out tremendously If you see either of them at some upcoming conferences  hint  Paul is giving a talk at Blackhat  buy them a drink There are a couple of changes that are going to happen that more accurately reflect the intentions of the site First, the name will be changing to Open Malware The new name more accurately reflects the purpose and intention of the site Way back in 2005 the intention was to make this a place where you could find information related to malware and other types of hacking As things  and life  have progressed it has changed into a malware research site, specifically with the ability to download malware samples The domain will be OpenMalwareorg in the very near future The second big item of news is that we will be transitioning to a download-only malware repository in the coming weeks The blog site will be officially shutting down There are much better forums maintained by commercial services that have taken up the role of a discussion area Specifically the  r ReverseEngineering and  r Malware sub-Reddits, and OpenRCE are better avenues of communication I will maintain a static version of the site to archive the old content To accommodate the new download site, there will be a couple of changes First, a lot of the back end software has changed Searches will be faster, more malware will be available, and the overall maintenance will be a lot easier Second, you will need to have a valid, verified Google Account Having a Google account allows us to use industry standard authentication, and most importantly not to have to maintain a user database Get one here if you haven't already In the meantime new account creation is disabled while we make the transition Old accounts should work as normal Finally, we are discontinuing our commercial services I would like to thank all of our customers for their business You all helped to support this site and maintain an open service We will be looking at transitioning to a non-profit status in the coming years Thanks again, Danny Quist read more </description><link>http://www.secuobs.com/revue/news/385961.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/385961.shtml</guid></item>
<item><title>VizSec 2012 Call for Papers Out</title><description>Secuobs.com : 2012-04-11 20:30:05 - Offensive Computing   Community Malicious code research and analysis -    VizSec 2012 will be held in mid-October as part of VisWeek in Seattle Papers are due July 1 The International Symposium on Visualization for Cyber Security  VizSec  is a forum that brings together researchers and practitioners from academia, government, and industry to address the needs of the cyber security community through new and insightful visualization techniques Co-located this year with VisWeek, the 9th VizSec will provide new opportunities for the usability and visualization communities to collaborate and share insights on a broad range of security-related topics Accepted papers will appear in the ACM Digital Library as part of the ACM International Conference Proceedings Series Important research problems often lie at the intersection of disparate domains Our focus is to explore effective, scalable visual interfaces for security domains, where visualization may provide a distinct benefit, including computer forensics, reverse engineering, insider threat detection, cryptography, privacy, preventing 'user assisted' attacks, compliance management, wireless security, secure coding, and penetration testing in addition to traditional network security Human time and attention are precious resources We are particularly interested in visualization and interaction techniques that effectively capture human analyst insights so that further processing may be handled by machines, freeing the analyst for other tasks For example, a malware analyst might use a visualization system to analyze a new piece of malicious software and then facilitate generating a signature for future machine processing When appropriate, research that incorporates multiple data sources, such as network packet captures, firewall rule sets and logs, DNS logs, web server logs, and or intrusion detection system logs, is particularly desirable More information is on the web site  http wwwornlgov sci vizsec read more </description><link>http://www.secuobs.com/revue/news/369429.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/369429.shtml</guid></item>
<item><title>Scalable, Automated Baremetal Malware Analysis</title><description>Secuobs.com : 2012-03-14 15:00:27 - Offensive Computing   Community Malicious code research and analysis -    This week I will be presenting on scalable, automated baremetal malware analysis at Black Hat Europe My presentation will coincide with the release of NVMTrace, a tool that facilitates automated baremetal sample processing using inexpensive hardware and freely available technologies More information is available at the following link  Entrapment  Tricking Malware with Transparent, Scalable Malware Analysis If you are attending Black Hat Europe and malware analysis is a topic of interest to you, please attend my talk If you are interested but will not be in attendance, please let me know and I will make my whitepaper and slide set available to you read more </description><link>http://www.secuobs.com/revue/news/363475.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/363475.shtml</guid></item>
<item><title>BHO Reversing</title><description>Secuobs.com : 2012-03-04 16:31:32 - Offensive Computing   Community Malicious code research and analysis -    From a long time for those days  BHO is supported since IE 40  malware writers exploit BHO functionality to bully on IE users Mostly evil BHO has two functionality   for sure if we talk about bankers  - monitoring logging requests sending by browser POST dump - password stealing - HTML page code dynamic modification HTML code injection - used for eg - adding additional form fields intended to obtain, more amount of TAN codes or generally some    Read entire post here  BHO Reversing </description><link>http://www.secuobs.com/revue/news/361335.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/361335.shtml</guid></item>
<item><title>Practical Malware Analysis - A Book Review and Curmudgeonly Rant on the State of Reverse Engineering</title><description>Secuobs.com : 2012-02-27 21:51:23 - Offensive Computing   Community Malicious code research and analysis -    Recently I was asked to review a pre-publication copy of Mike Sikorski and Andrew Honig s book  Practical Malware Analysis  by Nostarch Press I gave it an enthusiastic review, and I strongly believe this will become the defacto text for learning malware analysis in the future This is a review of that book, and a short rant on reverse engineering Before getting into Practical Malware Analysis, I hope you will indulge me in a rant about other books on the reverse engineering topic  They are not pretty If you ve taken one of my classes I recommend a few books for learning reversing, but climbing the steep mountain of pre-requisite material before you can attempt to be somewhat proficient is daunting Specifically the books I recommended were based off of each individual author s own personal style of reverse engineering with the tools that were available at the time The field has gotten much more accessible thanks to the awesome tools that are out there from companies like Hex-Rays and Zynamics Practical Malware Analysis does a good job of tying together the methods of modern malware analysis While most of the previous texts have done a good job of presenting the state of the art at their time, PMA overviews many of the tools that are in use in the modern day Part 1 starts off with the basic static techniques, how to set up a virtual environment, and dynamic analysis These initial steps are the basis for any good reversing environment What is nice is that these topics aren t dwelled on for an entire book Part 2 goes over the relationships of the Intel architecture, IDA Pro, modern compilers, and the Windows operating system to reverse engineering Having an understanding of this as it applies to the reversing process is extremely important Outside implementing a compiler, learning the fundamentals of the architecture is the most important skill a reverser can have for understanding the field The difference between an adequate reverser and a great reverser lies in the understanding of how the system interactions work The rest of the book is focused on the advanced topics of dynamic analysis Part 5 deals with all the ways that malware authors can make your life miserable, from anti-disassembly to packers Part 6,  Special Topics,  talks about shellcode analysis, C  specifics, and the ever-looming threat of 64-bit malware I suspect that there will be a second edition once 64-bit malware comes in vogue Overall the book is excellent for those that are new to this field Experts love to curmudgeonly talk about how nothing is new anymore, everything sucks, and pine for the good old days of reverse engineering with some wire-wrap, a lead pencil, a 9-volt Duracell, and a single LED If you consider yourself one of these people, reading this book is going to feel a lot like wearing someone else s underwear If, on the other hand, you read it and put aside your natural skepticism of all things new, you might learn something I really do like this book read more </description><link>http://www.secuobs.com/revue/news/360205.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/360205.shtml</guid></item>
<item><title>CAST Slides  Hunting malware with Volatility v20</title><description>Secuobs.com : 2011-12-26 07:41:15 - Offensive Computing   Community Malicious code research and analysis -    Last week i had a speech at the CAST forum about hunting malware with volatility 20 On 40 slides i will introduce the main features of this powerful forensic framework All memory dumps being discussed are snapshots from infected machines with modern malwares and rootkits http reconstructerorg papers Huntingpourcents20malwarepourcents20withpourcents20Volatilitypourcents20v20pdf </description><link>http://www.secuobs.com/revue/news/349006.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/349006.shtml</guid></item>
<item><title>The WOW-Effect  Imho something the IT-Security community should be aware of </title><description>Secuobs.com : 2011-12-05 17:18:03 - Offensive Computing   Community Malicious code research and analysis -    Dear like-mindeds, we  CERTat, the Austrian National Computer Emergency Response Team  just released our latest paper which addresses an issue with Microsoft Windows 64-bit that has high potential to affect the IT-Security community Especially those dealing with malware analysis and accordingly investigations It's even possible that some of us already are or were affected but just didn't notice The goal of my paper is to raise the IT-Security community's awareness regarding this issue In short  this issue - I call it the  WOW-Effect  - is a so to say unintentionally implication of Microsoft's WOW64 technology and the according redirection functionality You can find the paper on our website If you have any questions regarding the  WOW-Effect  or would like to give me some feedback feel free to contact me via wojner_at_certat Here's the link to the paper  http certat downloads papers wow_effect_enhtml Enjoy reading  Cheers, Christian Wojner CERTat read more </description><link>http://www.secuobs.com/revue/news/345376.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345376.shtml</guid></item>
<item><title>Introduction to IDA Python</title><description>Secuobs.com : 2011-11-22 21:33:24 - Offensive Computing   Community Malicious code research and analysis -    The Introduction to IDA Python document by Ero Carrera is one of the better documents on scripting the IDA Pro platform available After talking with Ero directly, I have received permission to host the PDF directly on Offensive Computing to make it available long-term Enjoy Introduction to IDA Python by Ero Carrera Danny </description><link>http://www.secuobs.com/revue/news/342080.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342080.shtml</guid></item>
<item><title>CSI Internet series - Spyeye detection with Volatility v2 and kernel debugging the TDL4  rootkit</title><description>Secuobs.com : 2011-10-05 00:33:09 - Offensive Computing   Community Malicious code research and analysis -    Just in case you missed my forensic analysis contributions for the CSI Internet series on h-onlinecom CSI Internet - A trip into RAM http wwwh-onlinecom security features CSI-Internet-A-trip-into-RAM-1339479html CSI Internet - Open heart surgery http wwwh-onlinecom security features CSI-Internet-Open-heart-surgery-1350313html Enjoy  read more </description><link>http://www.secuobs.com/revue/news/332712.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/332712.shtml</guid></item>
<item><title>Three Million Samples</title><description>Secuobs.com : 2011-08-27 04:21:44 - Offensive Computing   Community Malicious code research and analysis -    Today we added our three millionth sample to the Offensive Computing malware corpus While three million pales in comparison to the total malware out there, we still have the largest openly available collection available on the open Internet The story of this site has had its ups and downs, and on multiple occasions it was on the brink of shutting down Every time I heard from someone at a conference, or saw mention of the site in presentations in papers, this helped to keep us up and running The resources needed to keep things moving have been interesting to deal with Our commercial services have supported the ongoing maintenance of running a free malware archive Some changes are coming to the site Real Soon Now  TM  and I think now is a good time to share them with you First, the storage and catalog software we have been running on has been sluggish for a long time I'm about 80pourcents through a rewrite of the underlying malware processing system that should get us to the next order of magnitude without problems We have made some key partnerships with other open malware resources and we are beginning to put those into service soon Second, our Reverse Engineering training is getting a massive rewrite Currently we only do on-site offerings, but we are investigating the possibility of hosting at a more public general venue Finally, the blog that you see here will be undergoing some changes Thank you to all of our customers, users, and supporters Without you Offensive Computing would not be up and running today Watch for more news coming soon Danny Quist Founder, Offensive Computing, LLC read more </description><link>http://www.secuobs.com/revue/news/325519.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/325519.shtml</guid></item>
<item><title>Releasing PDF X-RAY</title><description>Secuobs.com : 2011-08-26 23:49:27 - Offensive Computing   Community Malicious code research and analysis -    For the past few months I have been doing research on PDF analysis and how it could be better improved While doing the research I found myself writing tools and scripts to help me get the job done and decided it was time to put something more useful together PDF X-RAY is a static analysis tool that allows you to analyze PDF files through a web interface or API The tool uses multiple open source tools and custom code to take a PDF and turn it into a sharable format The goal with this tool is to centralize PDF analysis and begin sharing comments on files that are seen PDF X-RAY differs from all other tools because it doesn't focus on the single file Instead it compares the file you upload against thousands of malicious PDF files in our repository These checks look for similar data structures within the PDF you upload and ones that have been reviewed by analysts Using this feature we can begin to see shared coded samples among malicious files or trends due to malicious author coding styles The tool is still in beta, but I wanted to release it to the public to see what users thought In my opinion the API is the most useful as you can begin to integrate rich PDF analysis into other tools and services with little or no cost read more </description><link>http://www.secuobs.com/revue/news/325501.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/325501.shtml</guid></item>
<item><title>MeMMon - A Light Weight Process Memory Scanner</title><description>Secuobs.com : 2011-08-26 23:49:27 - Offensive Computing   Community Malicious code research and analysis -    Vejovis is a project that was started to develop an user mode memory scanning tool  MeMMoN - A Process Memory Scanning Tool  It scans the memory of all the processes in the system It can be downloaded from the below link Download </description><link>http://www.secuobs.com/revue/news/325500.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/325500.shtml</guid></item>
<item><title>PoC XMPP Bot C C using Google Talk  video </title><description>Secuobs.com : 2011-08-02 03:59:49 - Offensive Computing   Community Malicious code research and analysis -    Earlier this year I put together an outline for a talk to cover how XMPP could be used as a botnet command and control I just got around to playing around with the stuff and wanted to share some of the information I had and get opinions on what people thought about it all I see XMPP as a more modern and flexible IRC when it comes to botnets Features like federation, transports, p2p and client server communication all make it seem to fit well in this area Rather then waiting until it actually gets implemented, maybe we should think about what we could do to stop it or detect it now http blog9bpluscom new-age-cc-xmpp-bots-preview http blog9bpluscom poc-xmpp-bot-cc-using-google-talk read more </description><link>http://www.secuobs.com/revue/news/320471.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/320471.shtml</guid></item>
<item><title>Reversing TDSS  The x64 Dollar Question</title><description>Secuobs.com : 2011-05-11 04:54:04 - Offensive Computing   Community Malicious code research and analysis -    In the two years since the Win32 Olmarik family of malware programs  also known as TDSS, TDL and Alureon  started to evolve, its authors have implemented a notably sophisticated mechanism for bypassing various protective measures and security mechanisms embedded into the operating system Read more here Reverse Engineering Malware The fourth version of the TDL rootkit family  TDL4  is the first reliable and widely spread bootkit to target x64 operating systems  Windows Vista and Windows 7  Since TDL4 started to spread actively in August 2010, several versions of the malware have been released By comparison with its predecessors, TDL4 is not just characterized by modification of existing code, but to all intents and purposes can be regarded as new malware Among the many changes that have been applied as it developed, the most radical were those made to its mechanisms for self-embedding into the system and surviving reboot One of the most striking features of TDL4 is its ability to load its kernel-mode driver on systems with an enforced kernel-mode code signing policy  64-bit versions of Microsoft Windows Vista and Windows 7  and perform kernel-mode hooks with kernel-mode patch protection policy enabled This makes TDL4 a powerful weapon in the hands of cybercriminals In this article, we consider the PPI  Pay Per Install  distribution model used by both TDL3 and TDL4, and the initial installation read more </description><link>http://www.secuobs.com/revue/news/303986.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/303986.shtml</guid></item>
<item><title>YARA 15 released</title><description>Secuobs.com : 2011-03-24 05:23:11 - Offensive Computing   Community Malicious code research and analysis -    A new version of YARA has been released This version provides some new features, including    Process memory scanning   Support for ELF files   Faster regular expressions by using RE2 instead of PCRE For more information visit  http codegooglecom p yara-project read more </description><link>http://www.secuobs.com/revue/news/293810.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/293810.shtml</guid></item>
<item><title>ShmooCon 2011  Visual Malware Reversing</title><description>Secuobs.com : 2011-02-04 23:48:47 - Offensive Computing   Community Malicious code research and analysis -    This past weekend I had the pleasure of presenting at ShmooCon 2011 This conference continues to be one of my favorites Shmoocon is a small conference that is trying very hard to stay that way This year I talked about my improvements to VERA over the past 6 months Much of the talk was centered around live demos, which unfortunately did not make it to the slides The new tracing module and updated versions of the VERA code will be posted here soon PDF of the Powerpoint Slides A new version of VERA with the updates will be posted here soon Abstract  Reverse engineering is a complicated process that has a lot of room for improvement This talk will showcase some improvements to our visualization framework, VERA New features that decrease the overall time to reverse a program will be shown New items are a debugger based interface which allows for faster analysis without the need for a hypervisor, integrated trace processing tools, IDA Pro integration, and an API to interface with the display During the talk I will reverse engineer malware samples, and show how to integrate it into your reversing process Danny read more </description><link>http://www.secuobs.com/revue/news/283128.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/283128.shtml</guid></item>
<item><title>Paper  Hunting rootkits with Windbg</title><description>Secuobs.com : 2011-02-01 17:07:23 - Offensive Computing   Community Malicious code research and analysis -    Here are the slides to my talk  Hunting rootkits with Windbg  at the Ruhr University of Bochum yesterday I'll introduce several ways to find well known rootkits like Rustock or TDL Versions 3 4 with Windbg and scripts Enjoy  http wwwreconstructerorg papers Hunting rootkits with Windbgpdf The Windbg script shown in the slides to grab Kernelcallbacks can be found here  http wwwreconstructerorg code WindbgScript-KernelCBFindx86rar </description><link>http://www.secuobs.com/revue/news/282154.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/282154.shtml</guid></item>
<item><title>Releasing malpdfobj  malicious PDF described in a JSON object </title><description>Secuobs.com : 2011-01-04 07:09:01 - Offensive Computing   Community Malicious code research and analysis -    About a month ago I posted a blog describing research I was doing on malicious PDF files As part of this research I needed a way to represent a malicious PDF file in a queryable form I ultimately decided on MongoDB as my backend and therefore wanted to get the malicious file in a JSON form so I could store it The tool I just released today is a composite of tools from myself and Didier Stevens Didier's PDF tools have done a lot of the heavy lifting, but my glue code brings multiple pieces of data into a single object As of right now the object contains the following details  read more </description><link>http://www.secuobs.com/revue/news/275630.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/275630.shtml</guid></item>
<item><title>VERA 03 Released</title><description>Secuobs.com : 2010-12-23 01:05:40 - Offensive Computing   Community Malicious code research and analysis -    VERA 03 has been released This new version contains a bunch of new features and API improvements The two biggest updates are the addition of the trace file parsing and analysis inside of the GUI This alleviates the need for the gengraphexe program The next big feature is the integration with IDA Pro Currently it only supports version 56 and 60 versions of IDA Finally, VERA now includes documentation Download VERA 03 MSI File Download VERA Documentation  PDF  Please feel free to email me  dquist at this domain  if you have any comments Those of you that have responded thank you very much Changelog    Added processing of trace files without having to use gengraph via new wizard   Better handling of low memory situations   Major code cleanup, refactoring, and new buzzwordy sounding tasks   Added a toolbar, because everyone loves those   Added IDA integration and IDA Pro module   Fixed a bug involving parsing of non-traditional Ether trace files   Now should support larger and more complicated graphs   I'm getting paid to write and support VERA   At Shmoocon 2011 I'll be rolling out the next version of VERA, complete with new features read more </description><link>http://www.secuobs.com/revue/news/273708.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/273708.shtml</guid></item>
<item><title>Detecting Malicious PDF Files</title><description>Secuobs.com : 2010-12-08 08:40:33 - Offensive Computing   Community Malicious code research and analysis -    For the past few days I have been completely immersing myself in PDF research in hopes to find better ways to detect malicious PDF files I have collected a pretty good random sample set  15K  of PDF data and have a bunch of malicious files with the same statistics I have wrote some basic tools to aid in my research and it would be nice to get some input on the results I have found so far The outline of the project can be found here  http pdfxray9bpluscom  The blog with all the research, data and tools that have been released can be found here  http blog9bpluscom </description><link>http://www.secuobs.com/revue/news/270176.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/270176.shtml</guid></item>
<item><title>Reversing the source of the ZeroAccess crimeware rootkit</title><description>Secuobs.com : 2010-11-16 01:22:01 - Offensive Computing   Community Malicious code research and analysis -    We recently undertook a project to update the hands-on labs in our Reverse Engineering Malware course, and one of our InfoSec Resources Authors, Giuseppe  Evilcry  Bonfa, defeated all of the anti-debugging and anti-forensics features of ZeroAccess and traced the source of this crimeware rootkit  Part 1 InfoSec Institute would classify ZeroAccess as a sophisticated, advanced rootkit It has 4 main components that we will reverse in great detail in this series of articles ZeroAccess is a compartmentalized crimeware rootkit that serves as a platform for installing various malicious programs onto victim computers It also supports features to make itself and the installed malicious programs impossible for power-users to remove and very difficult security experts to forensically analyze read more </description><link>http://www.secuobs.com/revue/news/265023.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/265023.shtml</guid></item>
<item><title>LinkedIn  Meeting Docs </title><description>Secuobs.com : 2010-09-29 02:23:57 - Offensive Computing   Community Malicious code research and analysis -    MD5  7227d2c555262145700be91ae991d91e I just received this malware via LinkedIn Upon quick inspection at CWSandbox  Sunbelt Software  this looks connected to padreimru, the file  appears to exploit C Program Files Adobe Reader 90 Reader Reader_slexe hides itself in C Documents and Settings All Users Application Data Microsoft OFFICE TEMP  as well as  tmp doc dat runs as C WINDOWS system32 svrwscexe and numerous other service names Just starting my analysis but wanted to get this out Sunbelt Software CWSandbox report http wwwsunbeltsecuritycom cwsandboxreportaspx id 73306018 cs 7EB44195CE93B70BDD431D51DA773EDB Virus Total Report http wwwvirustotalcom file-scan reporthtml id 3eaf012380777e3b0944bb571ab676b6a79789a81236ccc6f70b2a00ea954af0-1285706380 read more </description><link>http://www.secuobs.com/revue/news/252621.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/252621.shtml</guid></item>
<item><title>Vera 020 - Now Available</title><description>Secuobs.com : 2010-09-17 01:42:50 - Offensive Computing   Community Malicious code research and analysis -    After a lot of work, I'm happy to announce that Vera 020 is available for download This release is a rewrite of the entire code base into wxWidgets Based on some excellent feedback from my talk at REcon  an excellent con by the way  I've made some substantial changes to the backend code If you're not familiar with VERA, it's a visualization tool to help understand the dynamic execution of a program It's made to take the instruction traces from Ether and generate directed graphs showing the overall flow and composition of a program Identifying the OEP is easy, as well as looking for main loops and initialization sections of the program You can read about VERA in my Vizsec 2009 paper for more information Here's the complete changelog  Rewrite of entire codebase to wxWidgets  should allow for future ports to other platforms  Added configuration file  wxVera wxveraini  Read save previous window position and size from to config file Fixed a graph centering problem Added update checking code Reloading of graphs more efficient Added welcome message Introduced notebook style for GUI Please feel free to contact me  dquist at this domain  if you have any problems or suggestions for VERA Thanks  read more </description><link>http://www.secuobs.com/revue/news/247601.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/247601.shtml</guid></item>
<item><title>AV Testing Standards  Don't Like the Results of the Tests  Change the Rules</title><description>Secuobs.com : 2010-07-19 09:46:37 - Offensive Computing   Community Malicious code research and analysis -    There were good responses, mostly from people in the AV industry, to my blog post about the malware testing standards Overlooking my error linking to their original paper  sorry  there were some points I would like to address At the heart of this whole process, is exactly how dangerous a collection of malware is For the consumers, I would argue, it's not dangerous at all The malware industry is the only one who has to fear from it Notice I didn't say just the AV vendors, but also the producers of the malicious software In large part the authors depend on a closed, inside group of people unwilling to collaborate openly on the problem If you look at the major sources of malware in academic research prior to the creation of large open collections, you'll see that there were some big problems First, the samples were old and not representative of current threats Second, those samples either did not work or were not malicious in nature Finally, the samples are traded as something of value I'm no different, of course I derive value both from the collection and from consulting I do, however, go out of my way to support those doing open research as much as I can If someone in academia needs access to samples, just contact me and I'll work something out Likewise we have helped innumerable small businesses get their start in the malware world before they could enter the  circle of trust  mentioned by David Harley The  circle of trust  is often cited when discussing who can and cannot gain access to these samples Over the course of the years I've joined four of these groups While the vetting is done as best as possible, there's very little outside of an email address, and a recommendation keeping someone from joining Antivirus vendors exchange malware with themselves at a much higher volume, but there is still a perceived difficulty of entering this area Malware exists on the Internet in a freely available manner as a function of its being Limiting sample access to a certain set of privileged people fundamentally hurts innovation and response by everyone There was also some allusion that I did not support malware testing at all That is not the case Malware defense systems should be heavily tested against a range of threats The basis for my problems with the AMTSO is that it should  not  be composed of anyone in the AV industry Consumer Reports did an excellent job exposing the ineffectiveness of AV vendors by producing new samples Due to the very nature of the threat, there are going to be new samples that are discovered for the first time If an AV software can't respond to this threat, it should not be given a favorable review The current set of players in the malware testing arena are profit driven In and of itself that's ok, I'm all for capitalism, but in fairness there needs to be an independent authority AV testing companies that publish open information on the effectiveness of scanning results are not independent Without naming names, there is a prominent one claiming to provide results for the public, but instead is backed by every AV vendor in the industry This testing company takes in new samples, scans them with all the products, then tells the vendors how their performance rates What is not acceptable, in my view, are the shoddily written reports intended for consumers that report unethically high detection rates Finally I would like to address the ethics of the malware tester One thing I agree with David Harley on is the need to represent the full scope of the testing process to the consumer One of the things that the academic world does well is to produce research which can be recreated by other researchers That's the intent, at least AV testing standards advocated by the vendors cannot and will not provide the latest samples to malware authors What this ends up doing is providing all the methods of testing, but not the actual data to test on For those of us able to use new samples, it's not a problem Others who have older data and are unable to acquire new malware  due to cost, time involved, etc  are left with only one viable option  Synthesize new samples using the exact same methods available to the authors read more </description><link>http://www.secuobs.com/revue/news/241594.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/241594.shtml</guid></item>
<item><title>Using RDMA during malware research</title><description>Secuobs.com : 2010-07-05 06:14:00 - Offensive Computing   Community Malicious code research and analysis -    During my malware research i have encountered thousands of samples most research labs uses same methods during their sample analysis, they all uses emulators or any other kind of virtualization implementation the problem start when trying to analyze well defended malwares, ie malwares which uses good packers, antivm and anti debugging technique  and no im not talking about IsDebuggerPresent  read more </description><link>http://www.secuobs.com/revue/news/237611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/237611.shtml</guid></item>
<item><title>Vera 011 - Bug Fix Release</title><description>Secuobs.com : 2010-06-13 18:18:24 - Offensive Computing   Community Malicious code research and analysis -    First of all, thanks for all the great feedback from everyone about Vera Keep the feedback coming  Vera 011 is out on the main Vera page This release fixes a major memory leak for those of you who aren't running video cards with a gig of ram This should also alleviate problems that were related to running under Windows XP A future port to a wxWidgets version is underway This will eventually allow for cross-platform versions, hopefully timed with the IDA QT release As always, please report bugs to dquist at this domain </description><link>http://www.secuobs.com/revue/news/231136.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/231136.shtml</guid></item>
<item><title>URLVOID  Suspicious url scanner</title><description>Secuobs.com : 2010-06-08 18:28:59 - Offensive Computing   Community Malicious code research and analysis -    Urlvoid  beta version at the moment  is a free service that scan suspicious websites with multi engines to check if the site is safe to browse Its a virustotal like but for websites   http wwwurlvoidcom  Scanner list used by urlvoid  McAfee SiteAdvisor, McAfee Trusted Source, PcTools Browser Defender, Norton SafeWeb, MyWOT, Threat Log, MalwareDomainList, hpHosts, ZeuS Tracker, Google Diagnostic, PhishTank, Project Honey Pot, ParetoLogic, Spamhaus, URIBL, Malware Patrol, SURBL, SpamCop, TrendMicro Web Reputation, Web Security Guard read more </description><link>http://www.secuobs.com/revue/news/229611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/229611.shtml</guid></item>
<item><title>Released Buster Sandbox Analyzer 122</title><description>Secuobs.com : 2010-06-03 21:43:51 - Offensive Computing   Community Malicious code research and analysis -    Buster Sandbox Analyzer 122 has been released Actually the tool is being hosted here  http h1ripwaycom BusterBSA Version 122 introduces the automatic malware analysis mode This mode allows the analysis of multiple files without any user intervention New version also adds other features like the digital signature verification The tool can be downloaded directly from  http h1ripwaycom BusterBSA bsarar Buster Sandbox Analyzer makes the malware analysis accesible to everybody in a simple and safe manner </description><link>http://www.secuobs.com/revue/news/228363.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/228363.shtml</guid></item>
<item><title>Finding the TDSS authors and affiliates ---- An Analysis </title><description>Secuobs.com : 2010-06-01 17:26:32 - Offensive Computing   Community Malicious code research and analysis -    Although it is a mystery who created TDSS, there are some interesting strings in some of TDSS'es files Lets start with this one If we open the file in notepad, we see this somewhere  Comments Thanks to Edin Kadribasic, Marcus Boerger, Johannes Schlueter FileVersion 521111 0 InternalName phpexe   LegalCopyright Copyright 1997 - 2007 The PHP Group 0 LegalTrademarks PHP 8 OriginalFilename phpexe PrivateBuild 8 ProductName PHP phpexe 2 ProductVersion 5211 SpecialBuild URL http wwwphpnet D VarFileInfo   Translation Z y D   M u          read more </description><link>http://www.secuobs.com/revue/news/227529.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/227529.shtml</guid></item>
<item><title>Ether 01 Debian Package - BETA</title><description>Secuobs.com : 2010-05-29 02:10:38 - Offensive Computing   Community Malicious code research and analysis -    To make Ether a bit easier to install, we've put together a Debian package with precompiled Ether binaries This is considered a highly beta install package, so you will want to take care about where you install it Everything should install into  opt  and work very closely to how Ether does when you compile via source Please note that this package contains the Ether patched Xen package Other than satisfying the package's dependencies, you shouldn't install anything beyond that This has been tested with a fresh installation of Debian Lenny Please note that uninstall is currently not implemented Thanks to Chris Collord and Daniel Cox for their work on this Download the Ether 01 Debian Package here read more </description><link>http://www.secuobs.com/revue/news/226833.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/226833.shtml</guid></item>
<item><title>Generating Ether-like Trace Files for VERA</title><description>Secuobs.com : 2010-05-25 02:06:03 - Offensive Computing   Community Malicious code research and analysis -    I've had a few people email me about how to use non-Ether generated trace files in VERA To help with this, I ran a trace with Ether of the Notepadexe included with Windows XP Notepadexe Trace file If you want to generate instruction traces external from Ether, you just need to make sure it follows the same format First, you should start with the standard instruction trace boilerplate It looks like this  After init  shared_page_ptr  0xffff830000fd9000 shared_page_mfn  0xfd9 domid_source  0 event_channel_port  34 Shared Page va  0x7fde19b77000 Shared Page test  Page-Sharing is A-OK  Trying to bind to local port Success, bound to local port  35 Trying to get first pending notification Taking off suprious pending notification Setting filter by name to  notepadexe Execution of Target detected  Image Base   0x1000000 Image Size   0x14000 Entry Point  0x100739d After this, all you need to do is have a listing of instructions Right now the only thing I'm parsing is the instruction address, so there's no need to include the actual instruction Later versions of VERA will use the disassembly 100739d  push   0x70 100739d  push   0x70 100739f  push   0x01001898 10073a4  call   0x01007568 1007568  push   0x010075BA 100756d  mov    eax, fs 0x00000000  1007573  push   eax At the end of the file, after all the instructions make sure you include two  Handling sigint  messages  1007519  jnz    0x01007522 100751b  push   esi 100751c  call    0x1001318  Handling sigint Handling sigint That should be all you need to use VERA for your own uses As always, let me know if there are any bugs you observe read more </description><link>http://www.secuobs.com/revue/news/225201.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/225201.shtml</guid></item>
<item><title>VERA 01 Released</title><description>Secuobs.com : 2010-05-24 02:41:20 - Offensive Computing   Community Malicious code research and analysis -    I would like to announce the latest version of VERA, the reverse engineering visualization program Lots of bugs have been fixed, which I have detailed below Be sure to read the original VERA release documentation for instructions on how to use it Here is the change log    View panning has now been fixed so that it follows the mouse   Cleaned up display code and made it more portable   Fixed right-click selection code Currently a stub function but more will come later   Center graph on first load Now the graph isn't out in the middle of nowhere when you first load it   The start of execution is highlighted with a big blue box   Added arrows to show directionality of execution   Implemented frustum culling for rendering font text This makes things  much  faster If you have any problems, please let me know via dquist SHIFT-2 offensivecomputingDOTnet read more </description><link>http://www.secuobs.com/revue/news/224894.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/224894.shtml</guid></item>
<item><title>State of the art in CRiMEPACK Exploit Pack</title><description>Secuobs.com : 2010-05-23 19:23:41 - Offensive Computing   Community Malicious code research and analysis -    CRiMEPACK exploit pack is a widespread and accepted in the crime scene in this area came under the slogan  Highest Lowest rates for the price  He is currently In-the-Wild 30 version is being developed as alpha  the first of this version  That's, is in the middle stage of evaluation, perhaps in the next few days will go on sale in underground forums, at which time it will know your actual cost Like any pack exploit, it also consists of a set of pre-compiled exploits to take advantage of a number of vulnerabilities in systems with weaknesses in some of its applications, then download and run  Drive-by-Download   Execute  codes malicious and convert that system into a zombie, and therefore part of the apparatus crime And I mean   criminal  because those behind the development of this type of crimeware do for this purpose And judging by the pictures  a washcloth, a handgun, a wallet, money and what appears to be cocaine, own scenario of all mafia  observed in the authentication interface your control panel, this definition is very evident The first time I found this package was in 2009, when version In-the-Wild was version 21 and later expressed his  great leap  to one of the most popular  version 28  still active  which in early 2010 had incorporated into its portfolio of exploits CVE-2010-0188 y CVE-2010-0806  in addition to adding an iframe generator and function  Kaspersky Anti-emulation , at a cost of USD 400 read more </description><link>http://www.secuobs.com/revue/news/224864.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/224864.shtml</guid></item>
<item><title>YARA 14 released</title><description>Secuobs.com : 2010-05-23 06:29:18 - Offensive Computing   Community Malicious code research and analysis -    A new version of YARA have been released This version improves the scanning speed and fix an annoying bug which causes crashes on 64-bits Windows It also introduces external variables, a feature that allows you to create rules dependent on variables provided from the outside world Get the latest documentation here </description><link>http://www.secuobs.com/revue/news/224810.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/224810.shtml</guid></item>
<item><title>The Irrelevancy of Industry Accepted Malware Testing Standards</title><description>Secuobs.com : 2010-05-18 03:00:11 - Offensive Computing   Community Malicious code research and analysis -    Writing or presenting about AV testing and performance is a great way to draw the collective ire of the AV industry This is a hot button subject that I, personally, have received a lot of grief on The primary reason that the AV industry is so sensitive about their software is because it is not as effective as they would like you to believe Case in point is the recent Anti-Malware Testing Standards Organization s document titled Issues involved in the  creation  of samples for testing If you want to find a document listing all the hot-button issues that particularly perturb the AV community, here it is Without taking a particular side, the document seeks to  frame the debate  of the issue of  creating  malware samples What follows is a 19 page exploration of all the ways new malware can be created Here is a short list of modifications that they address  1 Archiving samples using ZIP or tar 2 Packing   repacking with a new packer  think UPX or ASPack  3 Using a malware generation kit 4 Server-side polymorphic samples - the sample is slightly modified every time it is downloaded from a public website 5 Patched versions of an existing file, including PE modifications and actual code changes 6 Writing a custom packer 7 Writing a new sample using existing techniques 8 Writing new samples using unknown techniques Specifically prohibited is public dissemination of malware samples These might actually encourage people to test AV software before buying it The pros and cons of each are presented, followed by a way to frame your debate afterwards What all of these miss is the central point that malware authors are using every single one of these techniques with spectacular success The other terrible secret is that these techniques are extremely easy Continued debate on whether or not these tests are ethical is moot because malware authors are already using them In order to protect against real threats, you must use the techniques that are being used to evade your protection software Consider the NHTSA talking about testing crash performance, but not actually ever smashing any of the cars into a wall There s no substitute for the real thing unless you re trying to hide something In the case of the AV industry, that thing is their technological irrelevance to the modern malware threat read more </description><link>http://www.secuobs.com/revue/news/222990.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/222990.shtml</guid></item>
<item><title>PDF Exploit detection system  Joedoc</title><description>Secuobs.com : 2010-04-26 23:17:14 - Offensive Computing   Community Malicious code research and analysis -    We are happy to release Joedoc a novel runtime analysis system for detecting exploit in documents like pdf and doc In its current beta stage it detects pdf exploits in Acrobat Reader 705, 812, 90 and 92 Check out the submission instructions on wwwjoedocorg to check malicious pdfs </description><link>http://www.secuobs.com/revue/news/216160.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/216160.shtml</guid></item>
<item><title>WIn32TDSS</title><description>Secuobs.com : 2010-04-25 06:39:36 - Offensive Computing   Community Malicious code research and analysis -    As a malware researcher I just got my hand on one of the latest TDSS Malware The malware uses protection against an execution on a virtual machine by using the SIDT query technique, in case a VMware environment is detected, the malware simply terminates and removes itself from the machine For this analysis I used solely real machine to perform the analysis The malware prevent itself from being executed several times using name event, it is pretty convenient as a signaling synchronization as well push esi push offset aGfdjhfd    gfdjhfd  push 1   bInitialState push 1   bManualReset push 0   lpEventAttributes call ds CreateEventA push fs 0  RCPT TO  DATA Received  201004210823012417qmail  Date  Wed, 21 Apr 2010 06 23 01 -0120 Message-ID  To  nicolad hammondresourcescouk Subject  April Discount  88724 From  USA VIAGRA Reply-To  nicolad hammondresourcescouk MIME-Version  10 Content-Type  text plain Content-Transfer-Encoding  8bit http tuxoxynurilivejournalcom Command   Coordination Communication  Data is being encoded  HTTP 11 200 OK magic-number   1281176 78 92 79 102 102 50 246 184 71 97 63 185 238 83 142 67  150 205 76 183 198 210 215 181 120 211 118 191 153 157 112 231 250 191 77 96 242 68 24 58  165 88 243 148 171 129 215 66 79 36 249 22 246 208 203 110 163 65 46 60 223 158 36 217 93 113 57 80  181 82 138 91 170 125 240 86 255 200 152 79 236 145 101 226 97 49 81 5 114 127 66 82 29 102 43 123 215  100 203 141 183 85 233 98 211 217 184 211 162 80 34 142 226 136 112 68 185 194 73 44 65 139 126 95 241 169 218  content-length   40448 entity-info   1271783310 40448 2  x-powered-by   PHP 526-1 lenny8 vary   Accept-Encoding server   nginx 0632 connection   close version   1 date   Wed, 21 Apr 2010 07 30 58 GMT rnd   11988440 content-type   text html  charset utf-8 http hjwbxhqrcn win-xp controllerphp action report guid 0 rnd 11987634 uid 7 entity 1271783310 read more </description><link>http://www.secuobs.com/revue/news/215791.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/215791.shtml</guid></item>
<item><title>Basical Trojan-BankerWin32Banza Anatomy - Reverse Engineering</title><description>Secuobs.com : 2010-04-09 17:34:55 - Offensive Computing   Community Malicious code research and analysis -    Hi, Today we are going to inspect a Rootkit Technology based Banker, called Win32Banza or RKIT Banker9088 This rootkit presents some interesting aspects from a reverse engineering point of view because has two layers of protection   b    UPX   DalKrypt b  Before starting the direct analysis let's study the general structure, with a PE inspection MD5  58A567A59A6B713B3B2638BC76C100DC SHA-1  0C18FF28DF6941541CDA89FF8006025E0E07E83D  b Section Headers    UPX0   UPX1   rsrc   DalKiT b  read more </description><link>http://www.secuobs.com/revue/news/210555.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/210555.shtml</guid></item>
<item><title>Best Buy iPad Censorship</title><description>Secuobs.com : 2010-04-08 04:23:12 - Offensive Computing   Community Malicious code research and analysis -    Today I was at Best Buy playing with the iPad, when I tried loading Offensive Computing on the web browser It seems that Best Buy thinks that this site has something to do with hacking I wonder if some customers were stress testing the demo machines' antivirus products  IMAGE  The picture is blurry so here is the text  This Page Cannot Be Displayed Based on your corporate access policies, access to this web site   http offensivecomputingnet     has been blocked because the web category  Hacking  is not allowed Store Network If you have questions, please contact a Best Buy Employee and provide the codes shown below Notification codes       1, WEBCAT, BLOCK-WEBCAT, 0x0021ed3a, 1270677200557,  AAAdUAAAAAAAAAAAyf8AEP8AAAA , http offensivecomputingnet  read more </description><link>http://www.secuobs.com/revue/news/209978.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/209978.shtml</guid></item>
<item><title>Analysis of new malware  YolrotX - BackdoorWin32Poisonapec </title><description>Secuobs.com : 2010-04-03 00:43:00 - Offensive Computing   Community Malicious code research and analysis -    This is the latest malware I got from the malware repositories, here I present how this malware infect the system and which third-party actions is doing by this specimen  YolrotX written in Visual Basic 60 MD5 Checksum   cb702c3319a27e792b84846d3d6c61ad Size   61493 Bytes Extract itself to pourcentswindirpourcents System32 with 3 different names   updateexe, securityexe, avgexe it's also open the internet explorer and tends to surf golocom website Seems it also uses the following library   Microsoft Base Cryptographic Provider v10 usename of the author is Basic, so we can name the author Basic  Also trying to download the following files to system32  hxxp wwwoviedolocal3476com mail bin msmexe  system32 updatesexe hxxp wwwoviedolocal3476com mail bin plugoffexe  system32 securitysexe hxxp wwwoviedolocal3476com mail bin regdllhelperexe  system32 drivessexe when start to executing, it's also drop a driver named  drivesys  and  drivesysoff  to system32 Drivers, had some rootkit behavior, while scanning with RKU it reports try to hide process updateexe  Open a Handle to Cmdexe  seems, there's no hooking behavior available in this sample  set itself as startup to the following key with 3 different entries  HKLM SOFTWARE MICROSOFT WINDOWS CurrentVersion Run  System32 avgexe  System32 updateexe  System32 securityexe easy to kill, just terminate updateexe , securityexe and globoexe, so the malware become inactive  vt result   Result  6 42  1429pourcents  vt perma link   http wwwvirustotalcom analisis ec89254ddb24b1c7f750d8c32d6e33d8f20959be410092401bbc28ee0bf19d07-1270075998 download sample from here   http wwwmultiuploadcom I5OPJU5DIN pass   Infected PS   I've been added it OC dataBase, try to search this one   cb702c3319a27e792b84846d3d6c61ad read more </description><link>http://www.secuobs.com/revue/news/208563.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/208563.shtml</guid></item>
<item><title>BackdoorIRCZapchast - mIRC used as Zombie - Reversing Malicious Network-IRC Activity</title><description>Secuobs.com : 2010-03-16 04:15:56 - Offensive Computing   Community Malicious code research and analysis -    In this blog post we are going to Investigate the malicious network activity of a still-alive Backdoor-Zombie called BackdoorIRCZapchast, here a little summary of its functionalities    Changes security settings of Internet Explorer   Survives to System Restart   Creates various copies of itself into Windows directory   Produces other Processess   Join to IRC Network, This is the most interesting functionality read more </description><link>http://www.secuobs.com/revue/news/202027.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/202027.shtml</guid></item>
<item><title>Win32PariteB Unpacking and Anatomy Reversing and Network Analysis</title><description>Secuobs.com : 2010-03-12 10:53:40 - Offensive Computing   Community Malicious code research and analysis -    Hi, Long time not blogging due to real life issues Today we are going to inspect Win32PariteB a trojan that modifies System Files and Enstablishes a Network Activity with an Irc Server and Downloads other potential threats We can consider PariteB an IrcBot Client Let's perform a first basilar inspection of the malicious binary The executable is delivered under the name of Protesto_Serasaexe MD5  475D456FA0062BB5323F1F002AC143DA Application presents an interesting Section Directory   UPX0   UPX1   rsrc   wtq Apparently appears to be a classical UPX packed application, but if we go to inspect deeply the wtq section we can suddenly see that the EntryPoint is located at 00096000 that belogs exactly to wtq This means that at loading time, UPX presence is quite useless because the first code that will be execute comes out from wtq that as we will see contains layer of decryption for the rest of the code Pay attention that exists also a TLS Directory, so in debugging phase we have to set TLS Awareness  Break on TLS  to be sure that we are able to follow the potentially hidden to debugger code read more </description><link>http://www.secuobs.com/revue/news/201038.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/201038.shtml</guid></item>
<item><title>Vizsec 2010 CFP Now Open</title><description>Secuobs.com : 2010-02-11 19:30:49 - Offensive Computing   Community Malicious code research and analysis -    Vizsec 2010, or the Visualization Security conference, is one of those conferences that I feel strongly could change the nature of security field If you have any ideas for visualization, especially reverse engineering related visualization, I strongly recommend you submit a paper there Here are the relevant dates  April 30, 2010 Full papers May 21, 2010 Short papers The Vizsec CFP is open now It's colocated with RAID this year Based on the 2008 RAID papers it should be a productive week read more </description><link>http://www.secuobs.com/revue/news/191019.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/191019.shtml</guid></item>
<item><title>Spam and Abuse</title><description>Secuobs.com : 2010-01-31 00:22:22 - Offensive Computing   Community Malicious code research and analysis -    One of the day-to-day tasks of running this site involves monitoring for spam Usually it's no problem  I just delete the junk posts, comments, and disable the accounts I've made some tools to make this pretty easy The problem is that the spammers and malcontents seem to have ratcheted up their spamming and it's getting to be too much work I've made a drastic change requiring people to send me an email asking to register their account There is a general pattern to the spam All of the accounts are new and created within 1-10 hours of the spam They all tend to have Gmail accounts Others such as Yahoo, Hotmail, etc have really dropped off It would be nice if Google could do something to prevent people from taking advantage of their server If I just banned any accounts from Gmail I could probably get rid of about 90pourcents of the spam That would affect other people using Gmail legitimately though, so I didn't want to take that step I realize there are people out there doing legitimate work  1  that can't answer the questions truthfully That's ok, just make something up I will accept  I work for the Post Office  as an answer  2 , or pretty much anything else So far it seems to be working too, there haven't been nearly as many spam messages as before There also have been some efforts to download our entire collection of malware While I can understand why someone would want to do this, it does end up using a lot of our resources, bandwidth being one of them As always I'm happy to work with people but please contact me about it I'm happy to make trades with people for new samples I can add If you have nothing to trade drop me a note and we can work something out  1  For some definition of legitimate    2  Stolen without shame from Halvar's class read more </description><link>http://www.secuobs.com/revue/news/187006.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/187006.shtml</guid></item>
<item><title>Trouble Unpacking</title><description>Secuobs.com : 2010-01-25 20:15:25 - Offensive Computing   Community Malicious code research and analysis -    I recently ran across some malware on a site and am trying to figure out how it works I've been trying to unpack the original file I downloaded, but haven't been having much success The original executable deletes itself and creates another executable in C WINDOWS system32 Attempts to disassemble it with IDA, ollydbg, and PE Browse all don't work I've put what dumpbin has to say at the bottom of the post I figure it's packed somehow Any tips  I've uploaded the file, you can find it here  http wwwoffensivecomputingnet q ocsearch ocq 2d7a7bceac89a0ae7c6edcbf62252bc5 read more </description><link>http://www.secuobs.com/revue/news/185154.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/185154.shtml</guid></item>
<item><title>One Million Samples</title><description>Secuobs.com : 2010-01-18 09:09:02 - Offensive Computing   Community Malicious code research and analysis -    Watching the sample counter, I noticed that we have ticked over the 1 million mark Ordinarily I'm not one for making a big deal about big round numbers, but I think this one has some special merit There has been a lot of work to make this happen from a lot of people Offensive Computing has been running for a little over 4 years now It started out as a small website with big dreams That turned into one with more of a focus on large numbers of samples I can remember conversations with friends about how amazing it was when we had a thousand, ten thousand, and forty thousand samples Each increment of size added more complexity to the system There is no better way to learn about scaling issues than to run a public site like this It has always been our hope that this site has been a resource to the reverse engineering and malware analysis community As always we enjoy interacting with everyone whether it be at conferences, training we've taught, twitter, or just email Thank you for all your support in creating this resource Happy 1 million samples  Danny Quist read more </description><link>http://www.secuobs.com/revue/news/182655.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/182655.shtml</guid></item>
<item><title>Siberia Exploit Pack Another package of explois In-the-Wild</title><description>Secuobs.com : 2009-12-28 18:22:55 - Offensive Computing   Community Malicious code research and analysis -    Siberia Exploit Pack is a new package designed to exploit vulnerabilities and recruit zombies original, as is easy to deduce from its name and as is customary in this area crimeware clandestine business in Russia read more </description><link>http://www.secuobs.com/revue/news/176168.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/176168.shtml</guid></item>
<item><title>Rule2Alert</title><description>Secuobs.com : 2009-12-24 08:15:21 - Offensive Computing   Community Malicious code research and analysis -    Rule2Alert's goal, is to read in snort rules and generate packets that would make snort produce an alert It is written entirely in python and utilizes Scapy to craft the packets It is still under heavy development with myself, Pablo Rincon, and Will Metcalf Currently, it is able to generate pcaps based off simple content snort compatible rules I loaded in the emerging-allrules file and was able to create a pcap that alerted snort 514 times The project is not ready to be released yet, but the results look promising so far This project is currently under the Open Information Security Foundation, as all of the project members are currently working on the new IDS IPS system Suricata Example  testrule ---------- alert tcp  HOME_NET any -  EXTERNAL_NET 80  msg Snort alert  flow to_server,established  content 56 24 5a 63  content hey  distance 5  within 12  sid 2000000  rev 1  famousjs youbantoo rule2alert  sudo python r2apy -vt -c  etc snort snortconf -f rules testrule -w testpcap Ether   IP   TCP 19216801 9001  1111 www S Ether   IP   TCP 1111 www  19216801 9001 SA Ether   IP   TCP 19216801 9001  1111 www A Ether   IP   TCP 19216801 9001  1111 www PA   Raw -------- Hex Payload Start ---------- 56 24 5a 63 20 20 20 20 20 68 65 79 --------- Hex Payload End ----------- Loaded 1 rules successfully  Writing packets to pcap Successfully alerted on all loaded rules read more </description><link>http://www.secuobs.com/revue/news/175511.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/175511.shtml</guid></item>
<item><title>Ether Mailing List</title><description>Secuobs.com : 2009-11-25 00:59:22 - Offensive Computing   Community Malicious code research and analysis -    Artem has created a mailing list for all Ether development related activities You can find it here in the Google Groups </description><link>http://www.secuobs.com/revue/news/164927.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/164927.shtml</guid></item>
<item><title>Buster Sandbox Analyzer 10 release version</title><description>Secuobs.com : 2009-11-24 01:20:54 - Offensive Computing   Community Malicious code research and analysis -    I released Buster Sandbox Analyzer 10 Buster Sandbox Analyzer is a malware analyzer using Sandboxie as environment to run programs You can follow the development of the tool here  http sandboxiecom phpbb viewtopicphp t 6557 And you can download the tool from here  http bsaqneade bsarar Reading the manual before using the tool is necessary </description><link>http://www.secuobs.com/revue/news/164339.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/164339.shtml</guid></item>
<item><title>Wandering Through TrojanNtRootKit47 Driver</title><description>Secuobs.com : 2009-11-22 22:34:13 - Offensive Computing   Community Malicious code research and analysis -    Wandering Through TrojanNtRootKit47 Driver Author  Davide  ocean  Quarta Introduction I didn t have the dropper at the moment of writing this, only the driver Without the dropper we can only get a generic idea of what the driver is used for The driver has been reverse engineered by deadlist, a really irritating thing to do actually, but it can be useful to see the generic structure of a typical driver It s a driver with dll functionality Erssd shows us that the driver is produced by ErrorSafe, a fake-av  scareware  company Seems like there are no rootkit functionality in this driver, while only a few zw  functions are exposed to the dropper, through the use of IOCTLS, though we can t know how this is used without access to the dropper Driver entry point  driver entry point graph Simple start structure, a Device is created with name  erssdd  and linked with a Dosdevice with the same name, next every PDRIVER_DISPATCH MajorFunction IRP_MJ_MAXIMUM_FUNCTION 1  will be written to point to a general IRP_dispatch procedure Also a driver unload routine is set text 000113EA push 1Ch   IRP_MJ_MAXIMUM_FUNCTION 1 text 000113EC lea edi,  ebx 38h  text 000113EF pop ecx text 000113F0 mov eax, offset irp_dispatch text 000113F5 rep stosd text 000113F7 mov dword ptr  ebx 34h , offset unload unload procedure is pretty simple too text 0001133A unload  text 0001133A cmp Handle, 0 text 00011341 jz short loc_1134A text 00011343 push 0 text 00011345 call close_handle text 0001134A text 0001134A loc_1134A  text 0001134A push offset DestinationString text 0001134F call ds IoDeleteSymbolicLink text 00011355 push DeviceObject text 0001135B call ds IoDeleteDevice text 00011361 retn 4 it will just check if there s and object handle open and close it  inside function close_handle there s a call to ZwClose  now the irp dispatcher procedure   read more </description><link>http://www.secuobs.com/revue/news/163964.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163964.shtml</guid></item>
<item><title>Huytebesy4ko Hijacker analysis</title><description>Secuobs.com : 2009-11-20 16:42:44 - Offensive Computing   Community Malicious code research and analysis -    Continuing on the road of scammail-spread malwares, today I am going to analyze an interesting little toy i accidentally get in touch just yesterday when receiving this funny email at my Universitary address from a fake crafted address notifications cremaunimiit  We are contacting you in regards to an unusual activity that was identified in your mailbox  As a result, your mailbox has been deactivated To restore your mailbox, you are required to  extract and run the attached mailbox utility Best regards, cremaunimiit technical support As you may guess there was an attachment called utilityzip containing an utilityexe which VirusTotal rates with a 73pourcents read more </description><link>http://www.secuobs.com/revue/news/163441.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163441.shtml</guid></item>
<item><title>T-IFRAMER Kit for the injection of malware In-the-Wild</title><description>Secuobs.com : 2009-11-17 00:50:13 - Offensive Computing   Community Malicious code research and analysis -    T-IFRAMER is a package that allows you to automate, centralize and manage via http the spread of malicious code via code injection sites violated viral techniques using iframe, and feed a botnet We then see a screen capture of authentication While there is a complex kit allows computer criminals manage the spread of malware via the http protocol type attacks using Drive-by-Download and Drive-by-Injection by inserting iframe tags in web pages violated The four key modules  Stats, Manager, Iframes and Injector, and each has the main function to optimize the spread of malware The first one  Stats  to manage FTP accounts violated having control over them with the ability to upload files Thus begins one of the cycles of propagation of malicious code The management module has several categories, among which are    Iframe accounts These are pages that have been injected malicious scripts through the iframe tag   Not Iframe FTP accounts are basically violated In this case, stored until several ftp accounts  read more </description><link>http://www.secuobs.com/revue/news/161406.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/161406.shtml</guid></item>
<item><title>Ether Automation Utility  Ether Bunny</title><description>Secuobs.com : 2009-11-14 00:44:02 - Offensive Computing   Community Malicious code research and analysis -    Ether Bunny is a script that I use to automatically startup and run Xen domains, copy files, and then execute them with Ether It is a quick hack I put together Most of the variables at the top of the file will need to be changed to match your configuration This script is made available as-is If it doesn't work you'll need to debug it on your own That being said if you find it useful and modify it let me know and I'll be happy to update the public version You'll need to get a copy of Winexe as well to remotely run the files There are some setup instructions at the Winexe page that will help you to configure your host machine Here's how I use it  snoosnoo xen   ebpy 19216802 malwareexe Ether Bunny v01 by Danny Quist Analyzing malwareexe to on VM 192168050 Destroying old vm image  xen winxp-sp2-malware-instance  Restoring vm image Starting vm from  etc xen ramdisk-winxp-sp2cfg Copying malwareexe to VM 1166 at 192168050 Attempt  1 Running malwareexe on VM winxp-sp2-ramdisk  1166  192168050 Letting program run dos charset 'CP850' unavailable - using ASCII EPOLL_CTL_ADD failed  Operation not permitted  - falling back to select  Killing ether Destroying VM ID  1166 Aborting Download Ether Bunny here Danny read more </description><link>http://www.secuobs.com/revue/news/160765.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/160765.shtml</guid></item>
<item><title>PHP pBot Dissection</title><description>Secuobs.com : 2009-11-02 18:44:51 - Offensive Computing   Community Malicious code research and analysis -    Today I'll dissect a website infected with PHP Pbot-A according to Avast naming convenction Be careful link reported is still alive  From a malicious domains DB emerged this infected URL http jamera2justfreecom cmdupload2txt As you can see it seems a classical txt file, but this is a classical evidence of RFI Infection MD5   da67134fc6953201d3556f5fedbcd50d        crew corp since 2003   edited by  devil__ and MEIAFASE   Friend  LP   COMMANDS      user  login to the bot   logout  logout of the bot   die  kill the bot   restart  restart the bot read more </description><link>http://www.secuobs.com/revue/news/156270.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/156270.shtml</guid></item>
<item><title>YARA 13 released</title><description>Secuobs.com : 2009-10-26 19:12:27 - Offensive Computing   Community Malicious code research and analysis -    I'm glad to announce a new version of YARA which includes three new major features, some of them inspired by requests and suggestions of some users out there They are    C-style includes Now you can include a YARA source file into another just like you do in your C programs with the  include pre-processor directive   Metadata in rules Rules now can contain associated metadata in identifier value pairs Metadata information can be string, integer or boolean values This metadata can be accessed later from the yara-python extension   Multi-source compilation in yara-python A group of YARA source files can be compiled together in yara-python In this way rules from different sources can be matched at the same time against your data, which is more efficient than compiling and matching each source independently Here is an example of the  include  and  metadata  features  include   includes some_other_rulesyar  rule silent_banker   banker   meta                                           description    This is just an example  thread_level   3 in_the_wild   true strings    a    6A 40 68 00 30 00 00 6A 14 8D 91     b    8D 4D B0 2B C1 83 C0 27 99 6A 4E 59 F7 F9   c    UVODFRYSIHLNWPEJXQZAKCBGMT  condition   a or  b or  c   For more info  http codegooglecom p yara-project  read more </description><link>http://www.secuobs.com/revue/news/154138.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/154138.shtml</guid></item>
<item><title>Turbodiff v101 Beta Released</title><description>Secuobs.com : 2009-10-22 06:07:46 - Offensive Computing   Community Malicious code research and analysis -    Turbodiff is a high-performance IDA plugin designed to detect differences between executable binaries It works on architectures supported by IDA 49 FREE, IDA 50 through 55 Turbodiff was developed by Nicolas A Economou, from the Exploit Writers Team of Core Security Technologies The tool's page is here  Coresecurity's Turbodiff You can also read the presentation of Turbodiff at Ekoparty '09 Buenos Aires, Argentina read more </description><link>http://www.secuobs.com/revue/news/152863.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152863.shtml</guid></item>
<item><title>Swimming into Trojan and Rootkit GameThief Win32 Magania Hostile Code </title><description>Secuobs.com : 2009-10-03 08:07:09 - Offensive Computing   Community Malicious code research and analysis -    Hi, Here my last paper Abstract Trojan-GameThiefWin32Magania, according to Kaspersky naming convention, monitors the user activities trying to obtain valuable information from the affected user, especially about gaming login accounts This long tutorial analyze this malware but is also a general document which explains how to analyze a modern nested-dolls malware http wwwaccessrootcom arteam site downloadphp view313 Regards, Giuseppe 'Evilcry' Bonfa' </description><link>http://www.secuobs.com/revue/news/147125.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/147125.shtml</guid></item>
<item><title>W32 RustockF, a quite unknown RustockC dropper</title><description>Secuobs.com : 2009-09-29 19:49:39 - Offensive Computing   Community Malicious code research and analysis -    Some days ago a friend of mine posted me a suspicious malware, unfortunately I couldn t look at it before yesterday night because I was out for work By submitting the file to virustotalcom I could see that only the 39,02pourcents of the av recognizes it as a malware  some popular antivirus like Kaspersky or Symantec, for example, don t recognize it , Microsoft calls it  TrojanDropper Win32 RustockF  while for Panda it is  Trj RustockL  As resulting from the analysis this is really a dropper for the famous malware RustockC A lot of papers has been written on RustockC so I will analyze only this dropper in order to make you know that this is a malware even if your antivirus does not signal it as a bad application The file I m talking about is called  is7771exe  In the article I will explain the behaviour of the dropper in details, take a look at it here  http revengstuffwordpresscom files 2009 09 rustock_f1pdf read more </description><link>http://www.secuobs.com/revue/news/145658.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/145658.shtml</guid></item>
<item><title>Tool for visualizing encrypted and or packed data with special focus on PE-files </title><description>Secuobs.com : 2009-09-29 19:49:39 - Offensive Computing   Community Malicious code research and analysis -    Hi folks, I developed a tool which might be of interest for you us reversers It's capable of creating histograms for the spreading of byte-codes for a whole file as well as section-wise regarding PE-files This will make the detection of crypted and or packed data much easier The tool  a windows and a linux version  and a decent description is available under our CERT-homepage  http certat downloads software bytehist_enhtml Plz let me know if you encounter any problems or have any questions Cheers, Christian Wojner CERTat </description><link>http://www.secuobs.com/revue/news/145657.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/145657.shtml</guid></item>
<item><title>My Ether Installation Method</title><description>Secuobs.com : 2009-09-21 07:32:40 - Offensive Computing   Community Malicious code research and analysis -    I've gotten a few emails from people asking questions about how to install Ether I thought I would put some very rough notes together for my general method to install it Artem Dinaburg and crew have some good notes at the official Ether website but there are a few more things I do to get things rolling Here goes  1 Download the Debian AMD64 5x net installation ISO and install it Get your network card and configuration working 2 Install ONLY the linux-image-2626- -xen-amd6 package You just want the kernel for this one This is where I've gotten myself into trouble by installing the kernel source that comes with the patched Xen system 3 Download the Xen and the ether_ctl source and patch as described on the Ether installation instructions page 4 Install the Debian packages necessary to get the system up and running I recently installed a system and this is the output of dpkg --get-selections command  ether_install_packageslog 5 Start compilation of Ether in the following directories not the main xen-310-src directory 1 cd xen   make   make install 2 cd  tools   make   make install 3 cd firmware   make   make install 6 Edit the  boot grub menulst to have an entry that looks something like this  be sure to substitute your information  title Debian GNU Linux, kernel 2626-1-xen-amd64 root  hd0,0  kernel  boot xen-310gz dom0_mem 1G module  boot vmlinuz-2626-1-xen-amd64 root dev sda1 ro quiet module  boot initrdimg-2626-1-xen-amd64 7 Download and install  configure   make   make install  libdisasm  I know libdasm is better but Ether works with libdisasm  8 Reboot You should see a Xen logo then your system will start up and look like normal 9 Make a Windows VM and follow the modification instructions on the Ether website That should be all it takes to get a working system up and running While you're playing with Ether be sure to check out Vera as well read more </description><link>http://www.secuobs.com/revue/news/142744.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/142744.shtml</guid></item>
<item><title>Google Groups Used To Control Botnets </title><description>Secuobs.com : 2009-09-14 06:14:03 - Offensive Computing   Community Malicious code research and analysis -    It's seems good that symantec guys discovered C C   command   control   on the private google pages, from the symantec blog the following quotes are available   Maintaining a reliable command and control  C C  structure is a priority for back door Trojan writers Recent developments have included the utilization of Web 20 social networking websites to deliver commands By integrating C C messages into valid communications, it becomes increasingly difficult to identify and shut down such sources It's a concept very similar to that of chaffing and winnowing Symantec has observed an interesting variation on this concept in the wild A back door Trojan that we are calling TrojanGrups has been using the Google Groups newsgroups to distribute commands Trojan distribution via newsgroups is relatively common, but this is the first instance of newsgroup C C usage that Symantec has detected It s worth noting that Google Groups is not at fault here  rather, it is a neutral party The authors of this threat have chosen Google Groups simply for its bevy of features and versatility The Trojan itself is quite simple It is distributed as a DLL, and when executed will log onto a specific account  Escape REMOVED gmailcom h0 REMOVED t The Web-based newsgroup can store both static  pages  and postings When successfully logged in, the Trojan requests a page from a private newsgroup, escape2sun The page contains commands for the Trojan to carry out The command consists of an index number, a command line to execute, and optionally, a file to download Responses are uploaded as posts to the newsgroup using the index number as a subject The post and page contents are encrypted using the RC4 stream cipher and then base64 encoded The attacker can thus issue confidential commands and read responses If no command is received from the static page, the infected host uploads the current time read more </description><link>http://www.secuobs.com/revue/news/140569.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/140569.shtml</guid></item>
<item><title>Vizsec 2009  Visualizing Compiled Executables for Malware Analysis</title><description>Secuobs.com : 2009-09-01 05:06:45 - Offensive Computing   Community Malicious code research and analysis -    The Vizsec 2009 program looks to be a pretty exciting this year Please join us in Atlantic City New Jersey  I will be presenting more visualization techniques for malware I'm presenting a paper titled  Visualizing Compiled Executables for Malware Analysis  I hope to see you there Abstract Reverse engineering compiled executables is a task with a steep learning curve It is complicated by the task of translating assembly into a series of abstractions that represent the overall flow of a program Most of the steps involve finding interesting areas of an executable and determining their overall functionality This paper presents a method using dynamic analysis of program execution to visually represent the overall flow of a program We use the Ether hypervisor framework to covertly monitor a program The data is processed and presented for the reverse engineer Using this method the amount of time needed to extract key features of an executable is greatly reduced, improving productivity A preliminary user study indicates that the tool is useful for both new and experienced users read more </description><link>http://www.secuobs.com/revue/news/136403.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/136403.shtml</guid></item>
<item><title>OSSS  Security Suite Fourth public beta  Vista support </title><description>Secuobs.com : 2009-08-21 14:39:56 - Offensive Computing   Community Malicious code research and analysis -    For the recent six weeks we have implemented a number of new functions The first one to mention is automatic customization of rules via Security Master already at the program installation stage Starting with version v11, search for software in use is performed during the OSSS installation, whereupon the accumulated data are analyzed on our server and the set of rules for the detected applications is generated automatically read more </description><link>http://www.secuobs.com/revue/news/133132.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/133132.shtml</guid></item>
<item><title>W32 Skintrim Reversing of a Badly Coded Mw</title><description>Secuobs.com : 2009-08-10 22:19:25 - Offensive Computing   Community Malicious code research and analysis -    Hi, Here I've linked the first two parts of W32 Skintrim Reverse Engieering of a Badly Coded Malware a Malware that is not working and appears really little, I've repaired it and I'm reversing it completely, Skintrim appeared to be really articulate Here the first three blog posts   1  2  3 Soon I will publish the  4 part Regards, Giuseppe 'Evilcry' Bonfa' read more </description><link>http://www.secuobs.com/revue/news/129611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/129611.shtml</guid></item>
<item><title>Offensive Computing Twitter OComputing</title><description>Secuobs.com : 2009-08-08 06:22:10 - Offensive Computing   Community Malicious code research and analysis -    Offensive Computing is now on Twitter  Follow OComputing for all the malware and reverse engineering 160 characters can handle </description><link>http://www.secuobs.com/revue/news/129171.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/129171.shtml</guid></item>
<item><title>Analyzing MSOffice malware with OfficeMalScanner - Whitepaper</title><description>Secuobs.com : 2009-07-31 05:28:09 - Offensive Computing   Community Malicious code research and analysis -    Finally i'm happy to release my paper Analyzing MSOffice malware with OfficeMalScanner This paper describes all features of the OfficeMalScanner suite in detail Further i've updated some features since my PH-Neutral talk, fixed bugs and replaced bin2code with MalHost-Setup A much smarter way to analyze the inner workings of shellcode in a real life session Both malicious samples described in the paper are included in the package For sure additionally compressed and with extra password safety Get the Paper Here Enjoy  read more </description><link>http://www.secuobs.com/revue/news/126821.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/126821.shtml</guid></item>
<item><title>Blackhat USA 2009  Reverse Engineering by Crayon</title><description>Secuobs.com : 2009-07-31 05:28:09 - Offensive Computing   Community Malicious code research and analysis -    My Blackhat talk is over and I think things went really well As promised here is the latest information on the slides To be able to use VERA you will need to follow the installation instructions from the Ether project Thanks again to everyone who attended and thank you for all the great questions Vera Executables - Binaries to run VERA and generate graphs Reverse Engineering by Crayon Slides from the Blackhat talk VERA Source Code  coming soon  If you're going to try and use Ether  which you definitely should  make sure you run Debian Sarge with a 64-bit installation From there the installation instructions from the Ether site should be all you need Read more for usage instructions read more </description><link>http://www.secuobs.com/revue/news/126820.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/126820.shtml</guid></item>
<item><title>What are the BOT elements here</title><description>Secuobs.com : 2009-07-25 22:37:56 - Offensive Computing   Community Malicious code research and analysis -    A lot of press is going around the discovery of the SymbOS Yxe threat, I have just uploaded a sample of the threat to Offensive Computing, in hopes that fellow researchers here will help me identify the BOT elements of the threat If your looking for a challenge this is it The File is the EPOC based execulatebe, not the SISX package, thus you should be able to get this decompiled in IDA right away without having to do any extractions MD5 of the sample 24D40DD68DCC17F9DAB29C9CFE3529A0 Note  Just uploaded it so maybe a little bit before it gets uploaded </description><link>http://www.secuobs.com/revue/news/124761.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/124761.shtml</guid></item>
<item><title>Malware Patent Application</title><description>Secuobs.com : 2009-07-16 17:37:25 - Offensive Computing   Community Malicious code research and analysis -    I recently came across this patent from Network Associates by Igor Muttik Here's the abstract   One embodiment of the present invention provides a system for determining whether software is likely to exhibit malicious behavior by analyzing patterns of system calls made during emulation of the software The system operates by emulating the software within an insulated environment in a computer system so that the computer system is insulated from malicious actions of the software During the emulation process, the system records a pattern of system calls directed to an operating system of the computer system The system compares the pattern of system calls against a database containing suspect patterns of system calls Based upon this comparison, the system determines whether the software is likely to exhibit malicious behavior In one embodiment of the present invention, if the software is determined to be likely to exhibit malicious behavior, the system reports this fact to a user of the computer system In one embodiment of the present invention, the process of comparing the pattern of system calls is performed on-the-fly as the emulation generates system calls  Reading through the claims it appears that they have patented much of what was the state of the art of academic research in the early 2000's I'm shocked with how loosely the patent is written Comparing system calls might have been novel at the time, but the real magic is finding a matching algorithm for them That algorithm, I would think, would be the real patentable material Then again that's why I'm not a patent lawyer read more </description><link>http://www.secuobs.com/revue/news/121484.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/121484.shtml</guid></item>
<item><title>Facebook Phisher</title><description>Secuobs.com : 2009-07-16 02:28:10 - Offensive Computing   Community Malicious code research and analysis -    Facebook phisher - Check it out while it's hot   Download here  Rapidshare  Local mirror RAR Archive Password   infected   without quotes  Cheers   Kish read more </description><link>http://www.secuobs.com/revue/news/121238.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/121238.shtml</guid></item>
</channel>
</rss>
 
