<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Code patching</title>
	<atom:link href="http://blog.chackraview.net/tag/code-patching/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction, and so does the reverse engineer…</description>
	<lastBuildDate>Sun, 25 Jul 2010 17:43:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Analyzing IRCBOTS: Part II</title>
		<link>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/</link>
		<comments>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 06:54:23 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=207</guid>
		<description><![CDATA[OK we know from previous post that malware is trying to connect testirc1.sh1xy2bg.NET. To learn more about its intentions, i added fake DNS entry in the XP host configuration file and pointed testirc1.sh1xy2bg.NET to my BackTrack 3 Machine. I then rebooted the live analysis machine and started Wireshark again on BT3 system. As malware has [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/29/analyzing-ircbots-part-ii/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBOTS: Part I</title>
		<link>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/</link>
		<comments>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 07:43:11 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=187</guid>
		<description><![CDATA[IRC based malware bots caught enormous attention in 2005-06. Though existence of IRC based Malwares are slowing down, Nailing them down is really interesting task. The sole purpose of Malware is to serve his master and follow his order. There are many ways adopted by Malware authors to achieve this, however controlling Malware from Intener [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/24/analyzing-ircbots-part-i/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Analyzing IRCBots III</title>
		<link>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/</link>
		<comments>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:44:54 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[59a95f668e1bd00f30fe8c99af675691]]></category>
		<category><![CDATA[Anti Virus Signature]]></category>
		<category><![CDATA[ClamAV Signature Generation]]></category>
		<category><![CDATA[Code patching]]></category>
		<category><![CDATA[IRC bots]]></category>
		<category><![CDATA[Malware Removal Tool]]></category>
		<category><![CDATA[processes C#]]></category>
		<category><![CDATA[Registry C#]]></category>
		<category><![CDATA[sigtool]]></category>
		<category><![CDATA[testirc1.sh1xy2bg.NET]]></category>
		<category><![CDATA[W32.Spybot]]></category>
		<category><![CDATA[W32/Spybot-Fam]]></category>
		<category><![CDATA[W32/Spybot.worm.gen]]></category>
		<category><![CDATA[Win32.Spybot.gen]]></category>
		<category><![CDATA[Winsec32.exe]]></category>
		<category><![CDATA[Worm.P2P.SpyBot.gen]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=218</guid>
		<description><![CDATA[Here I am for the third and final installment of our 3 installment post: Analyzing IRCBots. In the first post I showed you a static and behavioural analysis while in then second post we saw Code patching and analysis. We also conclude the behavior of the malware and categorized it under IRC bot. Those who [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2009/09/24/analyzing-ircbots-iii/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
