RE: [Full-Disclosure] MyDoom download info

From: first last (randnut_at_hotmail.com)
Date: 01/31/04

  • Next message: Scott Taylor: "Re: [Full-Disclosure] MyDoom download info"
    To: full-disclosure@lists.netsys.com
    Date: Fri, 30 Jan 2004 23:44:14 +0000
    
    

    > > >IE: how do you know that the behavior you see in the lab reflects
    > > >behavior in
    > > >the real world? (I get a kind of 'schrodingers cat' deja vu).
    > >
    > > You can always disassemble the virus, which is what people
    > > will do if it's a real "popular" one such as MyDoom.
    >
    >IIRC there are viruses that are encrypted and are almost impossible
    >to disassemble?
    >
    >Would that be true?
    >

    Sobig.F was packed with tElock. It's a PE file protector. It "encrypts" the
    program's code and data, and tries to detect debuggers before giving control
    to the real program. If you don't have the right tools and skills it could
    be difficult to unpack it. IIRC, it took the anti-virus companies two days
    to successfully unpack the program. All they really needed to do was dump it
    from memory while it was running and they could've analyzed it immediately
    with any disassembler.

    _________________________________________________________________
    High-speed users—be more efficient online with the new MSN Premium Internet
    Software. http://join.msn.com/?pgmarket=en-us&page=byoa/prem&ST=1

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Scott Taylor: "Re: [Full-Disclosure] MyDoom download info"

    Relevant Pages

    • Re: McCalls 2233 - chefs coat
      ... duh wrote: ... IIRC, you are trying to make something like: ... cost ones, and disassemble it for a pattern. ...
      (alt.sewing)
    • Re: McCalls 2233 - chefs coat
      ... duh wrote: ... IIRC, you are trying to make something like: ... cost ones, and disassemble it for a pattern. ...
      (alt.sewing)
    • Re: [Full-Disclosure] MyDoom download info
      ... >> You can always disassemble the virus, ... > IIRC there are viruses that are encrypted and are almost impossible ... Nico Golde nico ngolde de ...
      (Full-Disclosure)
    • Re: MSFT and random numbers
      ... but you may be able to disassemble the VB library and ... The VB.NET version is compatible with the VB6 version IIRC, ... Mattias Sjögren [MVP] mattias @ mvps.org ... Please reply only to the newsgroup. ...
      (microsoft.public.dotnet.languages.vb)