<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Malware analysis</title>
	<atom:link href="http://blog.chackraview.net/category/malware-analysis/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction and so does the reverse engineer…</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:51:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Snort Detection Rules for APT Malware MSUpdater.exe</title>
		<link>http://blog.chackraview.net/2012/02/03/snort-detection-rules-for-apt-malware-msupdater-exe/</link>
		<comments>http://blog.chackraview.net/2012/02/03/snort-detection-rules-for-apt-malware-msupdater-exe/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 17:46:10 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[MSUpdater.exe]]></category>
		<category><![CDATA[Snort Rules]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=965</guid>
		<description><![CDATA[Background: On 31st January 2012, ZScalar and Seculert posted analysis on recently identified RAT malware which is believed to be used in government related targeted attacks. Both of these firms, identified command and control beacon patterns and independently published them on their respective websites. Similar to all the APT attacks, these C&#38;C patterns were built [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/02/03/snort-detection-rules-for-apt-malware-msupdater-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing Twitter short URLs</title>
		<link>http://blog.chackraview.net/2012/01/26/analyzing-twitter-short-urls/</link>
		<comments>http://blog.chackraview.net/2012/01/26/analyzing-twitter-short-urls/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 19:47:23 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[obama sex]]></category>
		<category><![CDATA[Short URLs]]></category>
		<category><![CDATA[TrojanDownloader:Win32/Small.AIN]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=903</guid>
		<description><![CDATA[Short URL is a concept of reducing long and non-human friendly URLs. This is especially useful when it comes to micro blogging sites like Twitter. Twitter has a word limit of only 140 characters for a tweet. Hence posting long URLs along with a descriptive message is somewhat difficult. A link shortening service from twitter [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/26/analyzing-twitter-short-urls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding CVE-2010-1885 exploit from Blackhole exploitkit.</title>
		<link>http://blog.chackraview.net/2012/01/04/understanding-cve-2010-1885-exploit-from-blackhole-exploitkit/</link>
		<comments>http://blog.chackraview.net/2012/01/04/understanding-cve-2010-1885-exploit-from-blackhole-exploitkit/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 09:36:19 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Blackhole]]></category>
		<category><![CDATA[CVE-2010-1885]]></category>
		<category><![CDATA[TrojanDownloader:VBS/Yerwen.A]]></category>
		<category><![CDATA[Worm:Win32/Cridex.B]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=813</guid>
		<description><![CDATA[A friend of mine reported receipt of suspicious email to me. It turned out to be a nice opportunity  to analyze one more client side attack from the bag of BlackHole exploit kit. Attacker was not at all funky this time, no fancy stuff in the email, just a plain email with an external link. Below is the email [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/04/understanding-cve-2010-1885-exploit-from-blackhole-exploitkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of the Encrypted PDF samples</title>
		<link>http://blog.chackraview.net/2011/12/30/analysis-of-the-encrypted-pdf-samples/</link>
		<comments>http://blog.chackraview.net/2011/12/30/analysis-of-the-encrypted-pdf-samples/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 10:02:03 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[CVE-2011-2462]]></category>
		<category><![CDATA[Encrypted PDF]]></category>
		<category><![CDATA[ZFKeyMonitor]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=793</guid>
		<description><![CDATA[ In this post, I have used one of the encrypted samples found for CVE-2011-2462 vulnerability. After coming back from my vacation, I decided to take a quick look at the new samples shared on contagio blog to understand the exploitation methods of CVE-2011-2462. As many nice articles/blog posts have already written on this vulnerability, I [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/12/30/analysis-of-the-encrypted-pdf-samples/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of .jar attack from blackhole exploit pack.</title>
		<link>http://blog.chackraview.net/2011/11/20/analysis-of-jar-attack-from-blackhole-exploit-pack/</link>
		<comments>http://blog.chackraview.net/2011/11/20/analysis-of-jar-attack-from-blackhole-exploit-pack/#comments</comments>
		<pubDate>Sun, 20 Nov 2011 11:56:39 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[.jar exploits]]></category>
		<category><![CDATA[Blachole]]></category>
		<category><![CDATA[CVE 2010-0840]]></category>
		<category><![CDATA[exploit pack]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=783</guid>
		<description><![CDATA[Yesterday, one of my friend received a legitimate looking email from Internal Revenue Service with subject: Your Federal Tax Payment with a link to tax report.pdf file. He reported it to me and I got a chance to analyze it. Below are some of my findings from the analysis. The link had below obfuscated javascript in [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/11/20/analysis-of-jar-attack-from-blackhole-exploit-pack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Layman&#8217;s guide to remove FakeAV malware</title>
		<link>http://blog.chackraview.net/2011/06/14/laymans-guide-to-remove-fakeav-malware/</link>
		<comments>http://blog.chackraview.net/2011/06/14/laymans-guide-to-remove-fakeav-malware/#comments</comments>
		<pubDate>Tue, 14 Jun 2011 16:50:47 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[BestAntivirus2011]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[MS Removal tool]]></category>
		<category><![CDATA[WinWebSec]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=727</guid>
		<description><![CDATA[In my previous blog post, I talked about FakeAV malware and its new techniques to spread by disguising legitimate software download. In this post I will talk about a very simple technique to clean the FakeAV infection. Before I talk about the infection removal, let me list out all the measures taken by malware to prevent [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/06/14/laymans-guide-to-remove-fakeav-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Live Memory Analysis of Astros IRC Bot</title>
		<link>http://blog.chackraview.net/2011/04/17/live-mermoy-analysis-of-astros-irc-bot/</link>
		<comments>http://blog.chackraview.net/2011/04/17/live-mermoy-analysis-of-astros-irc-bot/#comments</comments>
		<pubDate>Sun, 17 Apr 2011 19:43:43 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[astros bot]]></category>
		<category><![CDATA[IRC bot]]></category>
		<category><![CDATA[memory analysis]]></category>
		<category><![CDATA[msconfig.exe]]></category>
		<category><![CDATA[usbblock.exe]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=704</guid>
		<description><![CDATA[One might think IRC bots have gone but a recent incident made me believe that they have not. Here&#8217;s how the story goes&#8230; As a part of my job, I was looking for malicious traffic on the network and a binary name msconfig.exe caught my eye. I saw msconfig.exe was getting downloaded through one of [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/04/17/live-mermoy-analysis-of-astros-irc-bot/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analysis of The Best Antivirus 2011</title>
		<link>http://blog.chackraview.net/2011/03/29/analysis-of-the-best-antivirus-2011/</link>
		<comments>http://blog.chackraview.net/2011/03/29/analysis-of-the-best-antivirus-2011/#comments</comments>
		<pubDate>Tue, 29 Mar 2011 21:19:22 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[BestAntivirus2011]]></category>
		<category><![CDATA[FakeAV]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=674</guid>
		<description><![CDATA[At last the time has come to show some presence again on my blog. After my disappearance for almost half a year, today I got the chance to actually write something… and what motivated me in doing so was a new spyware infection.. &#160; Here is the prologue&#8230; I was spying on my MATRIX honeypot for new [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/03/29/analysis-of-the-best-antivirus-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Lawsuit notice: Social Engineering Attack</title>
		<link>http://blog.chackraview.net/2010/03/26/lawsuit-notice-social-engineering-attack/</link>
		<comments>http://blog.chackraview.net/2010/03/26/lawsuit-notice-social-engineering-attack/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 07:14:41 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Lawsuite notice]]></category>
		<category><![CDATA[Mal/RtfExe-A]]></category>
		<category><![CDATA[RTF.EmbedEXE.Gen]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Suspicious.Insight]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=620</guid>
		<description><![CDATA[Yesterday, I got an email saying some company has filed a lawsuit against me in court with the link to download a word file supposed to be containing copyright law violations. As expected it turned out to be a very sophisticated social engineering attack. When I downloaded the file and scan in virustotal, very few [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/03/26/lawsuit-notice-social-engineering-attack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBOTS: Part II</title>
		<link>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/</link>
		<comments>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 06:54:23 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=207</guid>
		<description><![CDATA[OK we know from previous post that malware is trying to connect testirc1.sh1xy2bg.NET. To learn more about its intentions, i added fake DNS entry in the XP host configuration file and pointed testirc1.sh1xy2bg.NET to my BackTrack 3 Machine. I then rebooted the live analysis machine and started Wireshark again on BT3 system. As malware has [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

