| To: | "Rafa Richart" <rafa@ontinet.com> |
|---|---|
| Subject: | Re: Analize Virus |
| From: | "Jason Ross" <algorythm@gmail.com> |
| Date: | Wed, 1 Aug 2007 00:03:42 -0400 |
| Cc: | pen-test@securityfocus.com |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | pentest-list2@consult.net |
| Delivered-to: | mailing list pen-test@securityfocus.com |
| Delivered-to: | moderator for pen-test@securityfocus.com |
| Dkim-signature: | a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=Uz0gMFGtQW+btAZ/dh276Y5uY3m45CulRGPtXoQEle+WW3pdh8ju+c0HCvN91/7Om6W7LWM4Mi0Jb88RHEBle+6fx2hmj8CzY2yS8DCdJnH7ek6d/GkZTYt0vTuIcBthJIJ5qDVvTImrDT2jswXAxEspPHcKqBwGhISvOhlsjGs= |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=nj1Ze5Jr1ZDvwAWvNynmDtYDIMxEfpAr28VgpcenuSEHCq2yBxuAQInRUxVidv7PGcObuj4ILWH0raiY5+2CjD5YpDPj1pN5lH2QgZQ3hrJ+3hf9NHz2InVCPp/jQ81Sz5rDke4qUX0+f4fqFig0uly+bP/jY5WSlQVvM+fr0a0= |
| In-reply-to: | <1862113696.20070731192813@ontinet.com> |
| List-help: | <mailto:pen-test-help@securityfocus.com> |
| List-id: | <pen-test.list-id.securityfocus.com> |
| List-post: | <mailto:pen-test@securityfocus.com> |
| List-subscribe: | <mailto:pen-test-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:pen-test-unsubscribe@securityfocus.com> |
| Mailing-list: | contact pen-test-help@securityfocus.com; run by ezmlm |
| References: | <1862113696.20070731192813@ontinet.com> |
| Resent-date: | Wed, 1 Aug 2007 20:38:19 -0600 (MDT) |
| Resent-from: | pen-test-return-1078484743@securityfocus.com |
| Resent-message-id: | <20070802023819.29626237A5B@outgoing3.securityfocus.com> |
| Resent-sender: | listbounce@securityfocus.com |
| Sender: | listbounce@securityfocus.com |
On 7/31/07, Rafa Richart <Rafa@ontinet.com> wrote: > > we're looking for some tools to analize the Malware behaivor, we've > a Lab under contruccion but we need some advices of what tools we've > to use. tools to see what have benn changin the registry, stat > conexions etc... I've found VmWare Server (the free version) to be especially useful for this purpose. I use "What Changed" (which is available from [among other places] http://majorgeeks.com/What_Changed_d5018.html to compare files and registry hives which have changed, and have had decent results with it. I have heard good things about the "Reg Shot" app ( http://majorgeeks.com/RegShot_d965.html ) but haven't used it myself. Of course, wirehark is essential (in my opinion), as are the various utilities previously offered from sysinternals (now microsoft) ... in particular i find pstools and tcpview to be very handy. The collection of these is at the technet site: http://www.microsoft.com/technet/sysinternals/default.mspx You also may find it useful to have some form of disassembler/debugger. I am fond of ollydbg for this purpose, which is available at http://www.ollydbg.de It's probably worth noting that the craftier malware authors are beginning to check to see if they are running in a vmware environment. Accordingly it may be useful to take some countermeasures to that if possible. See http://isc.sans.org/diary.html?storyid=1871 for some information on this. Regards, -- Jason Ross ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Analize Virus, 杨峰 |
|---|---|
| Next by Date: | AW: Analize Virus, Jörg Weber |
| Previous by Thread: | Re: Analize Virus, Paul Halliday |
| Next by Thread: | Re: Analize Virus, Robert McArdle |
| Indexes: | [Date] [Thread] [Top] [All Lists] |