<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Malware Techniques</title>
	<atom:link href="http://blog.chackraview.net/category/information-security/malware-techniques/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction, and so does the reverse engineer…</description>
	<lastBuildDate>Sun, 25 Jul 2010 17:43:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Beware of Embedded PDF Malwares</title>
		<link>http://blog.chackraview.net/2010/05/16/beware-of-embedded-pdf-malwares/</link>
		<comments>http://blog.chackraview.net/2010/05/16/beware-of-embedded-pdf-malwares/#comments</comments>
		<pubDate>Mon, 17 May 2010 01:43:25 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Adobe hack]]></category>
		<category><![CDATA[pdf hack]]></category>
		<category><![CDATA[Zeus bot]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=644</guid>
		<description><![CDATA[Last month a security researcher Didier Stevens published a PoC PDF file which had executable embedded inside it. Though Metasploit framework already has this attack module to embed any executable inside a PDF file, the approached used by Didier Stevens is different and does not involve use of Javascript. As JavaScript is not used, disabling [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/05/16/beware-of-embedded-pdf-malwares/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBOTS: Part II</title>
		<link>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/</link>
		<comments>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 06:54:23 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=207</guid>
		<description><![CDATA[OK we know from previous post that malware is trying to connect testirc1.sh1xy2bg.NET. To learn more about its intentions, i added fake DNS entry in the XP host configuration file and pointed testirc1.sh1xy2bg.NET to my BackTrack 3 Machine. I then rebooted the live analysis machine and started Wireshark again on BT3 system. As malware has [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Execute programs at windows startup</title>
		<link>http://blog.chackraview.net/2010/01/24/execute-program-at-windows-startup/</link>
		<comments>http://blog.chackraview.net/2010/01/24/execute-program-at-windows-startup/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 07:43:16 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[ADS]]></category>
		<category><![CDATA[Alternate Data Streams]]></category>
		<category><![CDATA[Filetype association]]></category>
		<category><![CDATA[Win.ini]]></category>
		<category><![CDATA[winstart.bat]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=54</guid>
		<description><![CDATA[My Last post was related to the ADS technology adopted by viruses and rootkits. These viruses can implement Alternate Data Streams and easily hide themselves behind legitimate files. I also did a small mention of how to get suspicious whenever you see some new entry in Registrys keys used to start program with operating system. [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/24/execute-program-at-windows-startup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBOTS: Part I</title>
		<link>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/</link>
		<comments>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 07:43:11 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=187</guid>
		<description><![CDATA[IRC based malware bots caught enormous attention in 2005-06. Though existence of IRC based Malwares are slowing down, Nailing them down is really interesting task. The sole purpose of Malware is to serve his master and follow his order. There are many ways adopted by Malware authors to achieve this, however controlling Malware from Intener [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>My Encounter with Live Web Attack</title>
		<link>http://blog.chackraview.net/2010/01/19/my-encounter-with-live-web-attack/</link>
		<comments>http://blog.chackraview.net/2010/01/19/my-encounter-with-live-web-attack/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 07:16:55 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[De-obfuscation]]></category>
		<category><![CDATA[Decode malicious JavaScript]]></category>
		<category><![CDATA[iFrame injections]]></category>
		<category><![CDATA[Rhino]]></category>
		<category><![CDATA[Web attacks]]></category>
		<category><![CDATA[web based malware]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=234</guid>
		<description><![CDATA[It will not be an average day, I knew from the dawn, as EOD I will be on my way to Pune. You might think whats so special about visiting pune? Let me tell you, people who have spent at least a year or two in city like Pune or Bangalore will hate to stay [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/19/my-encounter-with-live-web-attack/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Alternate Data Streams (ADS)</title>
		<link>http://blog.chackraview.net/2010/01/14/alternate-data-streams-ads-2/</link>
		<comments>http://blog.chackraview.net/2010/01/14/alternate-data-streams-ads-2/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 22:45:25 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[ADS]]></category>
		<category><![CDATA[Alternate Data Streams]]></category>
		<category><![CDATA[Hidden Files]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[NTFS]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=535</guid>
		<description><![CDATA[With the introduction of NTFS file system in Windows NT, Microsoft introduced new concept of having multiple streams into single file known as Alternate Data Streams (ADS). In this blog i will discuss some advantages and disadvantages of ADS. Whenever we perform any operations on any file like &#8211; reading, writing, editing etc, we did [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/14/alternate-data-streams-ads-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBots III</title>
		<link>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/</link>
		<comments>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:54 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[ClamAV Signature Generation]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[Malware Removal Tool]]></category>
		<category><![CDATA[processes C#]]></category>
		<category><![CDATA[Registry C#]]></category>
		<category><![CDATA[sigtool]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=218</guid>
		<description><![CDATA[Here I am for the third and final installment of our 3 installment post: Analyzing IRCBots. In the first post I showed you a static and behavioural analysis while in then second post we saw Code patching and analysis. We also conclude the behavior of the malware and categorized it under IRC bot. Those who [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Unlock Registry Editor, Task Manager and Folder Options</title>
		<link>http://blog.chackraview.net/2009/09/24/unlock-registry-editor-task-manager-and-folder-options/</link>
		<comments>http://blog.chackraview.net/2009/09/24/unlock-registry-editor-task-manager-and-folder-options/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:46 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[folder options]]></category>
		<category><![CDATA[task manager]]></category>
		<category><![CDATA[unlock registry]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=369</guid>
		<description><![CDATA[Many of the computer users have the habit to download and use online games or check out latest screen savers. Most of them use torrents to download such softwares or movies. This habit could lead to locking yourself out of using tools like registry editor or process viewer. Let me ask you some questions. Have [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/unlock-registry-editor-task-manager-and-folder-options/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Karmetasploit: Another feather in Metasploit Hat</title>
		<link>http://blog.chackraview.net/2009/09/24/karmetasploit/</link>
		<comments>http://blog.chackraview.net/2009/09/24/karmetasploit/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:45 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[KARMA]]></category>
		<category><![CDATA[Karmetasploit]]></category>
		<category><![CDATA[Metasploit]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=75</guid>
		<description><![CDATA[Metasploit is rocking again and this time with Wireless hacking. After getting Best of open source software in security field, Metasploit has come up with a wireless masterpiece &#8211; Karmetasploit. Metasploit developers in collaboration with Aircrack-Ng developer hirte developed a super Access Point Impersonator (Rouge Access Point) based on KARMA Wireless Client Security Assessment Tool [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/karmetasploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Silently install malware using IExpress.</title>
		<link>http://blog.chackraview.net/2009/09/24/silently-install-malware-using-iexpress/</link>
		<comments>http://blog.chackraview.net/2009/09/24/silently-install-malware-using-iexpress/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:37 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Create Installer]]></category>
		<category><![CDATA[IExpress]]></category>
		<category><![CDATA[Install Malware]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=131</guid>
		<description><![CDATA[Now you have your Malware  ready and want it to get executed on victim machines. While doing so you obviously don&#8217;t want to ring any kinda bells so that victim get an alert . There are many tricks to do it, heres mine. Lot of people are crazy about installing latest softwares, games, screensavers on [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/silently-install-malware-using-iexpress/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
