<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Reverse Engineering</title>
	<atom:link href="http://blog.chackraview.net/category/reverse-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction and so does the reverse engineer…</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:51:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Analysis of CVE-2007-0024 Exploit and its Payload</title>
		<link>http://blog.chackraview.net/2011/07/14/analysis-of-cve-2007-0024-exploit-and-its-payload/</link>
		<comments>http://blog.chackraview.net/2011/07/14/analysis-of-cve-2007-0024-exploit-and-its-payload/#comments</comments>
		<pubDate>Thu, 14 Jul 2011 17:13:31 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[CVE-2007-024]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[MS10-004]]></category>
		<category><![CDATA[PWS:Win32/OnLineGames.KN]]></category>
		<category><![CDATA[Trojan:Win32/Sistyserav.A]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=741</guid>
		<description><![CDATA[CVE-2007-0024 is quite old and you might think, there would be no more active exploitation of this vulnerability as it was patched long back. I will say, think again. Today, I analyzed live attack while exploiting above vulnerability. Here is the gist of my analysis. Overview of CVE-2007-0024: An Integer overflow in the Vector Markup [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/07/14/analysis-of-cve-2007-0024-exploit-and-its-payload/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Live Memory Analysis of Astros IRC Bot</title>
		<link>http://blog.chackraview.net/2011/04/17/live-mermoy-analysis-of-astros-irc-bot/</link>
		<comments>http://blog.chackraview.net/2011/04/17/live-mermoy-analysis-of-astros-irc-bot/#comments</comments>
		<pubDate>Sun, 17 Apr 2011 19:43:43 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[astros bot]]></category>
		<category><![CDATA[IRC bot]]></category>
		<category><![CDATA[memory analysis]]></category>
		<category><![CDATA[msconfig.exe]]></category>
		<category><![CDATA[usbblock.exe]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=704</guid>
		<description><![CDATA[One might think IRC bots have gone but a recent incident made me believe that they have not. Here&#8217;s how the story goes&#8230; As a part of my job, I was looking for malicious traffic on the network and a binary name msconfig.exe caught my eye. I saw msconfig.exe was getting downloaded through one of [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/04/17/live-mermoy-analysis-of-astros-irc-bot/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analysis of The Best Antivirus 2011</title>
		<link>http://blog.chackraview.net/2011/03/29/analysis-of-the-best-antivirus-2011/</link>
		<comments>http://blog.chackraview.net/2011/03/29/analysis-of-the-best-antivirus-2011/#comments</comments>
		<pubDate>Tue, 29 Mar 2011 21:19:22 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[BestAntivirus2011]]></category>
		<category><![CDATA[FakeAV]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=674</guid>
		<description><![CDATA[At last the time has come to show some presence again on my blog. After my disappearance for almost half a year, today I got the chance to actually write something… and what motivated me in doing so was a new spyware infection.. &#160; Here is the prologue&#8230; I was spying on my MATRIX honeypot for new [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/03/29/analysis-of-the-best-antivirus-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBOTS: Part II</title>
		<link>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/</link>
		<comments>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 06:54:23 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=207</guid>
		<description><![CDATA[OK we know from previous post that malware is trying to connect testirc1.sh1xy2bg.NET. To learn more about its intentions, i added fake DNS entry in the XP host configuration file and pointed testirc1.sh1xy2bg.NET to my BackTrack 3 Machine. I then rebooted the live analysis machine and started Wireshark again on BT3 system. As malware has [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBOTS: Part I</title>
		<link>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/</link>
		<comments>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 07:43:11 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=187</guid>
		<description><![CDATA[IRC based malware bots caught enormous attention in 2005-06. Though existence of IRC based Malwares are slowing down, Nailing them down is really interesting task. The sole purpose of Malware is to serve his master and follow his order. There are many ways adopted by Malware authors to achieve this, however controlling Malware from Intener [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Analyzing W32.Imait.As and W32.Virut Malware</title>
		<link>http://blog.chackraview.net/2009/11/28/analyzing-w32-imait-as-and-w32-virut-malware/</link>
		<comments>http://blog.chackraview.net/2009/11/28/analyzing-w32-imait-as-and-w32-virut-malware/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 22:02:11 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[W32.Imait.As]]></category>
		<category><![CDATA[W32.Virut]]></category>
		<category><![CDATA[win32 virut nbk]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=402</guid>
		<description><![CDATA[Today, I was sitting in a dark room  self-evaluating about some things I did in past couple of months. And I realized my JOB is making me a lazy ass. It’s been a long time since I analyzed any malicious binary. So  I decided to  pick up a random old malware sample from my 320 [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/11/28/analyzing-w32-imait-as-and-w32-virut-malware/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBots III</title>
		<link>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/</link>
		<comments>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:54 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[ClamAV Signature Generation]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[Malware Removal Tool]]></category>
		<category><![CDATA[processes C#]]></category>
		<category><![CDATA[Registry C#]]></category>
		<category><![CDATA[sigtool]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=218</guid>
		<description><![CDATA[Here I am for the third and final installment of our 3 installment post: Analyzing IRCBots. In the first post I showed you a static and behavioural analysis while in then second post we saw Code patching and analysis. We also conclude the behavior of the malware and categorized it under IRC bot. Those who [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>W32.WaleDac Analysis</title>
		<link>http://blog.chackraview.net/2009/09/24/w32waledac-analysis/</link>
		<comments>http://blog.chackraview.net/2009/09/24/w32waledac-analysis/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:36 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[barackblog.exe]]></category>
		<category><![CDATA[Email Spam]]></category>
		<category><![CDATA[Email Virus]]></category>
		<category><![CDATA[fake Obama Website]]></category>
		<category><![CDATA[FileMon]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[obamanes.exe]]></category>
		<category><![CDATA[onlyYou.exe]]></category>
		<category><![CDATA[Process Explorer]]></category>
		<category><![CDATA[RegMon]]></category>
		<category><![CDATA[TDIMon]]></category>
		<category><![CDATA[W32.waledac]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=168</guid>
		<description><![CDATA[Since Jan20th 2009, a worm named W32.Waledac is a culprit for sending spam emails.  People found reporting spam emails linking to http://store.worldnewsdot.com or http://topwale.com I also went on the site to check what is all this fuss about by pointing my Firefox on the URL.  I was presented with nice picture filled with tempting hearts [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/w32waledac-analysis/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

