<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Virus Signature</title>
	<atom:link href="http://blog.chackraview.net/category/virus-signature/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction and so does the reverse engineer…</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:51:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Understanding CVE-2010-1885 exploit from Blackhole exploitkit.</title>
		<link>http://blog.chackraview.net/2012/01/04/understanding-cve-2010-1885-exploit-from-blackhole-exploitkit/</link>
		<comments>http://blog.chackraview.net/2012/01/04/understanding-cve-2010-1885-exploit-from-blackhole-exploitkit/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 09:36:19 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Blackhole]]></category>
		<category><![CDATA[CVE-2010-1885]]></category>
		<category><![CDATA[TrojanDownloader:VBS/Yerwen.A]]></category>
		<category><![CDATA[Worm:Win32/Cridex.B]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=813</guid>
		<description><![CDATA[A friend of mine reported receipt of suspicious email to me. It turned out to be a nice opportunity  to analyze one more client side attack from the bag of BlackHole exploit kit. Attacker was not at all funky this time, no fancy stuff in the email, just a plain email with an external link. Below is the email [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/04/understanding-cve-2010-1885-exploit-from-blackhole-exploitkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lawsuit notice: Social Engineering Attack</title>
		<link>http://blog.chackraview.net/2010/03/26/lawsuit-notice-social-engineering-attack/</link>
		<comments>http://blog.chackraview.net/2010/03/26/lawsuit-notice-social-engineering-attack/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 07:14:41 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Lawsuite notice]]></category>
		<category><![CDATA[Mal/RtfExe-A]]></category>
		<category><![CDATA[RTF.EmbedEXE.Gen]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Suspicious.Insight]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=620</guid>
		<description><![CDATA[Yesterday, I got an email saying some company has filed a lawsuit against me in court with the link to download a word file supposed to be containing copyright law violations. As expected it turned out to be a very sophisticated social engineering attack. When I downloaded the file and scan in virustotal, very few [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/03/26/lawsuit-notice-social-engineering-attack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBots III</title>
		<link>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/</link>
		<comments>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:54 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[ClamAV Signature Generation]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[Malware Removal Tool]]></category>
		<category><![CDATA[processes C#]]></category>
		<category><![CDATA[Registry C#]]></category>
		<category><![CDATA[sigtool]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=218</guid>
		<description><![CDATA[Here I am for the third and final installment of our 3 installment post: Analyzing IRCBots. In the first post I showed you a static and behavioural analysis while in then second post we saw Code patching and analysis. We also conclude the behavior of the malware and categorized it under IRC bot. Those who [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

