Author Topic: A basic analysis on malware  (Read 5782 times)

0 Members and 1 Guest are viewing this topic.

Offline XssRoot

  • NULL
  • Posts: 4
  • Cookies: 2
    • View Profile
A basic analysis on malware
« on: March 30, 2011, 12:33:35 am »
A very good article on malware analysis using basic tools though its kinda basic but may help few :)

Code: [Select]
http://www.blackhat.com/presentations/bh-dc-07/Kendall_McMillan/Paper/bh-dc-07-Kendall_McMillan-WP.pdf

Offline FuyuKitsune

  • Knight
  • **
  • Posts: 292
  • Cookies: 21
    • View Profile
Re: A basic analysis on malware
« Reply #1 on: March 30, 2011, 04:55:01 am »
Simple, but it's a starting point for people who don't know about RE.

Offline Crimson

  • NULL
  • Posts: 4
  • Cookies: 0
    • View Profile
Re: A basic analysis on malware
« Reply #2 on: March 30, 2011, 12:52:26 pm »
Links i found helpful

http://www.emre.de/wiki/index.php/MWC2008
http://zeltser.com/reverse-malware-paper/

Top one is the winner of malware challenge 2008 and the procedure he used to reverse the malware, good read and shows fundamentals

Also try this linux distro
http://zeltser.com/remnux/

Has guides how to use it as well

Offline XssRoot

  • NULL
  • Posts: 4
  • Cookies: 2
    • View Profile
Re: A basic analysis on malware
« Reply #3 on: March 30, 2011, 10:21:33 pm »
Yeah its for the starters :)

Offline FuyuKitsune

  • Knight
  • **
  • Posts: 292
  • Cookies: 21
    • View Profile
Re: A basic analysis on malware
« Reply #4 on: March 30, 2011, 11:31:22 pm »
Links i found helpful

http://www.emre.de/wiki/index.php/MWC2008
http://zeltser.com/reverse-malware-paper/

Top one is the winner of malware challenge 2008 and the procedure he used to reverse the malware, good read and shows fundamentals
Now these are friggin thorough. The first one is a nice read.
I don't get all the VMs though. I'm used to anti-everything included in bots, using a VM is not considered proper analysis since they're so easy to detect. A good analysis should be done on real computers, not in VMs or Sandboxes.

Offline Rafy

  • Peasant
  • *
  • Posts: 111
  • Cookies: 5
    • View Profile
Re: A basic analysis on malware
« Reply #5 on: April 25, 2011, 10:34:30 am »
http://computer-forensics.sans.org/community/downloads/
This should be nice for anyone that's doing PC forensics studies and work.I have not tried it myself.It seems like it's an ubuntu-based distro.
If it moves shoot it,if it runs... hack it!