Blog
Recent
May 1, 2012 10:16

Razorback 0.5.0 released

The Razorback team has released version 0.5.0. You can find the new version of Razorback here:  http://sfi.re/JlWZ0U.  We have also updated the virtual machine, which you can get here: http://sfi.re/IAW1oa. This release adds support for running inspection nuggets on Windows. At t

April 26, 2012 10:30

ClamAV vs. Content IQ Test, part 3

This is the third post in a series of blog posts about the Content IQ Test. Please see ClamAV vs. Content IQ Test, part 1 and ClamAV vs. Content IQ Test, part 2. Today we look at how ClamAV would handle detecting the target string when embedded in polymorphic files. If you were

April 17, 2012 23:35

Prototyping Mitigations with DBI Frameworks

A couple weeks ago I had the privilege of both attending my first Austin Hackers Association meeting and speaking at the first Infosec Southwest conference in Austin, Texas. I had been wanting to visit Austin for several years now and was excited to see the dynamics of the local

April 17, 2012 14:50

Snort Performance and IP-Only Rules

One of the most frequent topics that comes up when I'm out speaking to customers, or when anyone from the VRT is discussing Snort on a mailing list, IRC channel, etc., is performance. Everyone wants to know how to make their rules faster - and many people are willing to go to

April 12, 2012 17:06

Special Delivery -- Phoenix Exploit Kit

You would think that spam masquerading as a delivery company would be getting a little long in the tooth, but that isn't the case.Last week the winner was "DHL Attention 846698", which looks something like this: Good day! Dear Consumer , Recipient's address

April 4, 2012 14:52

Adventures in Domain Takedowns

I gave a presentation entitled "Adventures in Domain Takedowns" recently at the APCERT 2012 conference in Bali, Indonesia. The conference itself was excellent - plenty of good technical material and lots of useful contacts - and the location, of course, couldn't hav

March 21, 2012 13:14

ClamAV vs. Content IQ Test, part 2

This is the second post in a series of blog posts about the Content IQ Test. Please see ClamAV vs. Content IQ Test, part 1. Let's see how ClamAV does with test files that contain auto-executing embedded active content. Test file 10 contains the target string in an obfuscate

March 20, 2012 18:50

MIDI Karaoke Background or Malware Vector?

MD5's of samples found in the wild up to now: - 6249ac0674574c7df2f81801a41b85a5 - 9d63609e49e18f87973e66bdbc4236b4 - d3410dd27ba25c780abcd5c4df573303 - 1a4c84227cbf6da8724699b9b6fbb71b - bbc2d8cb3f8ed9a3a5292408d476af14 - c91703bc8d5509003c1d0a634dcbbd06 - 2b988374bb9

March 7, 2012 16:51

Some Snort discussion about Murofet, Kazy, or whatever we're calling it..

One of the fun parts about malware analysis is the name you give it.  I try to name my coverage in ClamAV similar to what other vendors are naming the same samples so there is some correlation and consistency.  Sometimes it works...this is one of the cases where it doesn't.