Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download - Clean, repair and optimize your system



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

From the mailbag, December 3rd edition, (Mon, Dec 3rd)

Security News




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 12-04-2007
Steve's Avatar
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 57,942
Steve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to behold
Thanks: 11
Thanked 92 Times in 21 Posts
From the mailbag, December 3rd edition, (Mon, Dec 3rd)
Several months ago, I wrote about Mandiant releasing Mandiant Red Curtain (MRC), a tool to attempt to characterize files to point an investigator at files that might require more careful investigation. Earlier this week, Russ McRee sent us info on a nice little presentation he gave on malcode analysis techniques for incident handling. In it, he shows use of MRC and a couple of other tools that I'm quite fond of for malware analysis. His presentation can be found here.
Speaking of incident response data gathering, I'm finally starting to read a book that has been on my list since before it was published. That book is Harlan Carvey's execellent, Windows Forensic Analysis Including DVD Toolkit. Lots of excellent tools.


One of the things that MRC does is look at entropy in the files. Ero Carrerra's pefile (which I've mentioned previously I use in my own little script for packer identification) also calculates the entropy for each section of a PE file. One of the other things that I've been looking at is hashing sections (or even individual functions) in an executable to see if that was useful in establishing relationships between malware variants. Since Ero was already calculating entropy of each section, I asked if he'd be willing to hash the sections as well. He graciously agreed and put the feature in version 1.2.8 of pefile which he released the following day. Thanx, Ero.
I also discovered another new tool that hashes the sections of an executable. Chris Rohlf has released a useful little tool called binhash.
Finally, this morning Thorsten Holz, pointed out that the Chinese Honeynet Project has released 2 new technical reports. The first entitled Characterizing the IRC-based Botnet Phenomenon, and the second, Studying Malicious Websites and the Underground Ecomony on the Chinese Web.

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Estonian Defense Minister Comments, (Mon, Dec 3rd) Steve Security News 0 12-03-2007 19:40
Immanentize the Eschaton, (Mon, Sep 3rd) Steve Security News 0 09-04-2007 03:40
Deobfuscating VBScript, (Mon, Sep 3rd) Steve Security News 0 09-03-2007 01:41
Mailbag, (Mon, Jul 23rd) Steve Security News 0 07-23-2007 13:39
3rd party software Gurpreet microsoft.public.windows.vista.music pictures video 2 05-02-2007 17:13




All times are GMT +1. The time now is 14:55.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119