pen-test
[Top] [All Lists]

Re: Analize Virus

To: "Rafa Richart" <rafa@ontinet.com>
Subject: Re: Analize Virus
From: "Jason Ross" <algorythm@gmail.com>
Date: Wed, 1 Aug 2007 00:03:42 -0400
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=Uz0gMFGtQW+btAZ/dh276Y5uY3m45CulRGPtXoQEle+WW3pdh8ju+c0HCvN91/7Om6W7LWM4Mi0Jb88RHEBle+6fx2hmj8CzY2yS8DCdJnH7ek6d/GkZTYt0vTuIcBthJIJ5qDVvTImrDT2jswXAxEspPHcKqBwGhISvOhlsjGs=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=nj1Ze5Jr1ZDvwAWvNynmDtYDIMxEfpAr28VgpcenuSEHCq2yBxuAQInRUxVidv7PGcObuj4ILWH0raiY5+2CjD5YpDPj1pN5lH2QgZQ3hrJ+3hf9NHz2InVCPp/jQ81Sz5rDke4qUX0+f4fqFig0uly+bP/jY5WSlQVvM+fr0a0=
In-reply-to: <1862113696.20070731192813@ontinet.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <1862113696.20070731192813@ontinet.com>
Resent-date: Wed, 1 Aug 2007 20:38:19 -0600 (MDT)
Resent-from: pen-test-return-1078484743@securityfocus.com
Resent-message-id: <20070802023819.29626237A5B@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
On 7/31/07, Rafa Richart <Rafa@ontinet.com> wrote:
>
> we're looking for some tools to analize the Malware behaivor, we've
> a Lab under contruccion but we need some advices of what tools we've
> to use. tools to see what have benn changin the registry, stat
> conexions etc...

I've found VmWare Server (the free version) to be especially useful
for this purpose.

I use "What Changed" (which is available from [among other places]
http://majorgeeks.com/What_Changed_d5018.html to compare files and
registry hives which have changed, and have had decent results with it.

I have heard good things about the "Reg Shot" app
( http://majorgeeks.com/RegShot_d965.html ) but haven't used it myself.

Of course, wirehark is essential (in my opinion), as are the various
utilities previously offered from sysinternals (now microsoft) ...
in particular i find pstools and tcpview to be very handy.
The collection of these is at the technet site:
http://www.microsoft.com/technet/sysinternals/default.mspx

You also may find it useful to have some form of disassembler/debugger.
I am fond of ollydbg for this purpose, which is available at
http://www.ollydbg.de

It's probably worth noting that the craftier malware authors are
beginning to check to see if they are running in a vmware environment.
Accordingly it may  be useful to take some countermeasures to that if
possible. See http://isc.sans.org/diary.html?storyid=1871 for some
information on this.

Regards,
--
Jason Ross

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>