pen-test
[Top] [All Lists]

Re[2]: Analize Virus

To: pen-test@securityfocus.com
Subject: Re[2]: Analize Virus
From: Rafa Richart <Rafa@ontinet.com>
Date: Fri, 3 Aug 2007 13:59:52 +0200
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <53b7021b0708020839u2ba9b58ds35c65b99bd54324@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Organization: Ontinet.com (Dpto. Tecnico)
References: <1862113696.20070731192813@ontinet.com> <53b7021b0708020839u2ba9b58ds35c65b99bd54324@mail.gmail.com>
Reply-to: Rafa Richart <rafa@ontinet.com>
Resent-date: Fri, 3 Aug 2007 09:50:00 -0600 (MDT)
Resent-from: pen-test-return-1078484753@securityfocus.com
Resent-message-id: <20070803155000.AA76E144F8E@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thanks very much to all the people has aswered my question, now I've many 
information 


Best regards

jueves, 02 de agosto de 2007
a las 17:39, escribió:

AS> My $.02

AS> For static or code analysis, I use IDAPro or Ollydbg as well as good
AS> old 'strings' and 'objdump', I've also been starting to play with PE
AS> Explorer lately.

AS> For dynamic studies, I'll run wireshark on my host system and use a
AS> combo of Winalysis, Process Explorer, filemon, and fport. Lately, I've
AS> been kicking SysAnalyzer around a bit.

AS> Keep in mind, more and more malware is becoming VMWare aware, so a
AS> hardware solution such as a CoreRestore card might be a good
AS> investment.

AS> In general:

AS> Behavioral Analysis:
AS> Wireshark
AS> Process Monitor
AS> Process Explorer
AS> FileMon
AS> RegMon
AS> TCPView
AS> Winalysis
AS> SysAnalyzer
AS> Snort
AS> tcpdump

AS> Static Analysis:
AS> AV Scanners
AS> IDA Pro
AS> Ollydbg
AS> strings
AS> Various unpackers
AS> PE Explorer
AS> LordPE
AS> Google

AS> HTH



AS> On 7/31/07, Rafa Richart <Rafa@ontinet.com> wrote:

>> Hi Pals,

>> we're looking for some tools to analize the Malware behaivor, we've a Lab 
>> under contrucción, but we need some advices of what tools we've to use. 
>> tools to see what have benn changin the registry, stat conexions etc...

>> Any help is wellcome.

>> Thanks in advance

>> Rafa



>> ------------------------------------------------------------------------
>> This list is sponsored by: Cenzic

>> Need to secure your web apps NOW?
>> Cenzic finds more, "real" vulnerabilities fast.
>> Click to try it, buy it or download a solution FREE today!

>> http://www.cenzic.com/downloads
>> ------------------------------------------------------------------------








-- 
Saludos,
Departamento técnico
Ontinet.com, S.L.
http://www.protegerse.com
----------------------------------------------------------------------------
Noticias de seguridad, Datos sobre virus, Alertas, Bulos
Visite nuestra Enciclopedia: http://www.enciclopediavirus.com
----------------------------------------------------------------------------

***
Mensaje escrito con The Bat! versión 3.95.8
Con fecha viernes, 03 de agosto de 2007 a las 13:55


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>