 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Irregular Expressions &#187; malware analyzing</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/Irregular-Expressions/tag/malware-analyzing/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions</link>
	<description>Insight into current security related events and exploits, including virtualization security and tips.</description>
	<lastBuildDate>Sun, 28 Apr 2013 08:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>What Is The Gauss Payload?</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/what-is-the-gauss-payload/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/what-is-the-gauss-payload/#comments</comments>
		<pubDate>Mon, 27 Aug 2012 03:49:58 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[exploits as munitions]]></category>
		<category><![CDATA[Gauss]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware analyzing]]></category>
		<category><![CDATA[malware engineering]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[stuxnet source code]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=883</guid>
		<description><![CDATA[If you have not seen this yet, Gauss is something that appears to have come out of the same labs or workshop as Flame and Stuxnet. This specifically seems to be targeted against the financial industry in the middle east. Here is a Guardian article with some excellent information; http://www.guardian.co.uk/technology/2012/aug/09/stuxnet-gauss-virus-kaspersky Kaspersky is still actively working [...]]]></description>
				<content:encoded><![CDATA[<p>If you have not seen this yet, Gauss is something that appears to have come out of the same labs or workshop as Flame and Stuxnet.  This specifically seems to be targeted against the financial industry in the middle east.</p>
<p>Here is a Guardian article with some excellent information;<br />
<a href="http://www.guardian.co.uk/technology/2012/aug/09/stuxnet-gauss-virus-kaspersky" title="http://www.guardian.co.uk/technology/2012/aug/09/stuxnet-gauss-virus-kaspersky" target="_blank">http://www.guardian.co.uk/technology/2012/aug/09/stuxnet-gauss-virus-kaspersky</a></p>
<p>Kaspersky is still actively working on figuring out the payload, and strangly they are asking for assistance.</p>
<p><a href="https://www.securelist.com/en/blog/208193781/The_Mystery_of_the_Encrypted_Gauss_Payload" title="https://www.securelist.com/en/blog/208193781/The_Mystery_of_the_Encrypted_Gauss_Payload" target="_blank">https://www.securelist.com/en/blog/208193781/The_Mystery_of_the_Encrypted_Gauss_Payload</a></p>
<p>If you have the interest and capabilities you can contact them at the above site and get involved.  Very very interesting just to get caught up on the current suspicions of what they think is going on.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/what-is-the-gauss-payload/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paypai.com</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/paypai-com/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/paypai-com/#comments</comments>
		<pubDate>Tue, 21 Aug 2012 05:35:29 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[backdoor]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware analyzing]]></category>
		<category><![CDATA[malware engineering]]></category>
		<category><![CDATA[remnux]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=876</guid>
		<description><![CDATA[I picked up another similar listener to the Groupon one the other day. This again is an attached ZIP file with an exe inside. It says its from paypai.com depending on your font the i will look like a L. The exe looks like it has been reused but I don&#8217;t see any mention of [...]]]></description>
				<content:encoded><![CDATA[<p>I picked up another similar listener to the Groupon one the other day.  This again is an attached ZIP file with an exe inside.  </p>
<p>It says its from paypai.com depending on your font the i will look like a L.</p>
<p>The exe looks like it has been reused but I don&#8217;t see any mention of it&#8217;s original file name.  The original name appears to have been stickiestfilm.exe md5 42bbb627d3bcc12745e8a6fbd4b2c825.</p>
<p>It also appears to have been used in several other campaigns according to it&#8217;s technical data.</p>
<p>https://www.virustotal.com/file/a9cbb0ac7ce189f4340fd23f295b118b28d74709c47205fed58c464e0ffcd942/analysis/</p>
<p>So far the only behavior I have seen is that it opens a command shell on local port 8000 TCP and awaits incoming connections.  I did not see it send any out bound packets of yet.</p>
<p>Next is some source analysis.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/paypai-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Malware Analyzing</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/simple-malware-analyzing/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/simple-malware-analyzing/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 02:08:55 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[malware analyzing]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=417</guid>
		<description><![CDATA[http://securitytube.net/Simple-Malware-Analyzing-video.aspx Excellent video, short and to the point with a good list of tools to get you started if you are interested in this kind of thing. If you do this, it&#8217;s better to do this with a physical machine and not a virtual machine.  Many malware will detect if it&#8217;s in a VM or [...]]]></description>
				<content:encoded><![CDATA[<p>http://securitytube.net/Simple-Malware-Analyzing-video.aspx</p>
<p>Excellent video, short and to the point with a good list of tools to get you started if you are interested in this kind of thing.</p>
<p>If you do this, it&#8217;s better to do this with a physical machine and not a virtual machine.  Many malware will detect if it&#8217;s in a VM or not and change what it&#8217;s doing.  In the past I have used BartPE and ImageXML to take and restore my images, ImageXML can take a image of a running machin using VSS so that can save you one reboot.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/simple-malware-analyzing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
