Press
Mobile virus collection needed
Submitted by rijans on Mon, 2009-09-28 03:54. Presshey all i need all type of mobile viruses on symbian , palm , windowsMobile , Blackberry etc. if anyone have mobileviruse collection plz contact with me @ vrijans@gmail.com .
thanks
rijans
Analysis of Braviax.exe
Submitted by obscurant1st on Thu, 2009-08-27 19:31. Analysis and Samples | PressHi,
i got some files named braviax.exe which is downloading the rogues. all of them are of somewhat same sizes. Also when i try to pass it in olly something wrong happens.
http://www.offensivecomputing.net/?q=ocsearch&ocq=4dcfc3c51e92fd35127fb0ec96e2ce8a
this is one of those samples.
when i execute them, using process xplorer i found that there are lots of malware filenames and urls to the malwares are there.(but in (properties->strings->memory)
And when i passed it to die_0.64 which is a tool like PEiD, it showed the file is entropy packed.
A new member of the Offensive Computing team - Dante Allegro
Submitted by dante.allegro on Wed, 2008-10-15 12:09. Administrivia | Exploits | Malware | Press | Research | Reversing Challenges | Scanner | Shellcode | toolsHello everyone!
My name is Dante Allegro , and as the newest member of the team my job is to work with members of the commercial community who wish to purchase products and services from Offensive Computing.
If you or your company would like to utilize the Offensive Computing malware database in your commercial product, or if you have a specific job that you feel the Offensive Computing team can assist you with , please contact me and I will be quite happy to assist you.
As I am on the road quite a bit please contact me directly at dallegro ( at ) offensivecomputing.net.
Race to Zero: A Golden Opportunity for the Antivirus Industry
Submitted by dannyquist on Sun, 2008-04-27 11:03. Malware | PressA new contest called Race to Zero is being held at Defcon this year. The premise is that you take a modern virus and modify it to evade detection by antivirus companies. The AV industry is officially crying foul, saying that this only encourages bad behavior. The organizers say it will point out the shortcomings of modern AV engines.
I'm going to ruin part of the contest: It's scandalously easy to circumvent any antivirus engine with a trivial amount of work. There has been evidence of this: The Consumer Reports scandal is one of them. The point is that it is not difficult to apply some seemingly minor and trivial modification that completely evades detection. The AV companies know it, the malware authors know it, the only people who don't have a clue are the consumers. Shaking their confidence of spending $60 per year on updates is something that the AV vendors fear. That's why the lawyers are probably going to get involved very quickly.
In lieu of this sure to be scandalous con drama, I propose a secondary contest. Antivirus vendors all race each other to develop signatures for the new variants as quickly as possible. Bring your best analysts to Defcon, or engage the home analysts, and show the true value of a good AV company: its signature development and reverse engineering teams.
Russian Business Network study
Submitted by Zeno on Tue, 2007-12-04 23:09. Malware | PressFor Reading - Russian Business Network study
There are some places in the world where life is dangerous. Internet has some dark zones too and RBN is one of them. RBN stands for Russian Business Network and it’s a nebulous organisation which aims to fulfil cyber crime.
This study aims to provide some enlightenment on RBN activities and tries to detail how they work. Indeed RBN has many constituents and it’s hard to have an exact idea on the goal of some of them and the way they’re linked with other constituents.
There are some countermeasures available but they don't make sense for home users or even companies. Only ISPs, IXPs and internet regulators can help mitigating risks originating from RBN and other malicious groups.
You may download, the pdf in these links:
+ http://research-labs.net/news/13-Russian+Business+Network+study.html
+ www.bizeul.org/files/RBN_study.pdf
just fyi..
Regards,
~ Zeno
SecurityFocus Interviews the MPack Author
Submitted by dannyquist on Fri, 2007-07-20 09:33. PressRob Lemos contacted the MPack author and interviewed them. He writes, "In June 2006, three Russian programmers started testing a collection of PHP scripts and exploit code to automate the compromise of computers that visit malicious Web sites."
Vista Will Get Malware
Submitted by dannyquist on Mon, 2007-04-23 17:39. PressRyan Naraine has an article about Mark Russinovich admitting that Vista will get malware. I suppose the news worthy portion of this statement is that Mark is admitting it, which seems to be a change in direction. There have already been reports of spyware working for Vista, so this is not too surprising. All the viruses and malware I've test run on Vista work without trouble.
ZDNet - Ryan Naraine Mentions the OC / Irnbot situation
Submitted by valsmith on Fri, 2007-03-09 09:45. Press"The botnet operator behind the virulent Nirbot Trojan is having a field day taunting anti-virus researchers.
While it is common to find messages and shout-outs buried in virus code, the person(s) behind Nirbot is rather talkative, leaving hostile threates directed at specific individuals, a strange apology for something involving "hospital computers" and even a mock CNN interview that discusses the bot's intent."
More press, links, citations
Submitted by valsmith on Fri, 2006-08-11 12:35. Press | Site Discussionhttp://www.internetnews.com/xSP/article.php/3625351
http://press.xtvworld.com/article13268.html
http://www.informationweek.com/news/showArticle.jhtml?articleID=190600023&subSection=All+Stories
http://tech.monstersandcritics.com/news/article_1183845.php/New_search_engine_to_track_down_viruses
http://www.extremetech.com/article2/0,1697,1990464,00.asp
http://www.scenta.co.uk/scenta/news.cfm?cit_id=983681&FAArea1=widgets.content_view_1
http://www.windowsitpro.com/mobile/pda/Article.cfm?ArticleID=93103&News=1
http://www.windowsitpro.com/windowspaulthurrott/Article/ArticleID/93103/windowspaulthurrott_93103.html
Offended by offensive computing
Submitted by Pi on Tue, 2006-08-08 20:43. PressPlease check the attachment :)
