Razorback 0.5.0 released
The Razorback team has released version 0.5.0. You can find the new version of Razorback here: http://sfi.re/JlWZ0U. We have also updated the virtual machine, which you can get here: http://sfi.re/IAW1oa. This release adds support for running inspection nuggets on Windows. At t
ClamAV vs. Content IQ Test, part 3
This is the third post in a series of blog posts about the Content IQ Test. Please see ClamAV vs. Content IQ Test, part 1 and ClamAV vs. Content IQ Test, part 2. Today we look at how ClamAV would handle detecting the target string when embedded in polymorphic files. If you were
Prototyping Mitigations with DBI Frameworks
A couple weeks ago I had the privilege of both attending my first Austin Hackers Association meeting and speaking at the first Infosec Southwest conference in Austin, Texas. I had been wanting to visit Austin for several years now and was excited to see the dynamics of the local
Snort Performance and IP-Only Rules
One of the most frequent topics that comes up when I'm out speaking to customers, or when anyone from the VRT is discussing Snort on a mailing list, IRC channel, etc., is performance. Everyone wants to know how to make their rules faster - and many people are willing to go to
Special Delivery -- Phoenix Exploit Kit
You would think that spam masquerading as a delivery company would be getting a little long in the tooth, but that isn't the case.Last week the winner was "DHL Attention 846698", which looks something like this: Good day! Dear Consumer , Recipient's address
Adventures in Domain Takedowns
I gave a presentation entitled "Adventures in Domain Takedowns" recently at the APCERT 2012 conference in Bali, Indonesia. The conference itself was excellent - plenty of good technical material and lots of useful contacts - and the location, of course, couldn't hav
ClamAV vs. Content IQ Test, part 2
This is the second post in a series of blog posts about the Content IQ Test. Please see ClamAV vs. Content IQ Test, part 1. Let's see how ClamAV does with test files that contain auto-executing embedded active content. Test file 10 contains the target string in an obfuscate
MIDI Karaoke Background or Malware Vector?
MD5's of samples found in the wild up to now: - 6249ac0674574c7df2f81801a41b85a5 - 9d63609e49e18f87973e66bdbc4236b4 - d3410dd27ba25c780abcd5c4df573303 - 1a4c84227cbf6da8724699b9b6fbb71b - bbc2d8cb3f8ed9a3a5292408d476af14 - c91703bc8d5509003c1d0a634dcbbd06 - 2b988374bb9
Some Snort discussion about Murofet, Kazy, or whatever we're calling it..
One of the fun parts about malware analysis is the name you give it. I try to name my coverage in ClamAV similar to what other vendors are naming the same samples so there is some correlation and consistency. Sometimes it works...this is one of the cases where it doesn't.