Re: Using Magic Values along with filetype to find malicious files (was RE: [Full-disclosure] Google Malware Search)



On 7/17/06, Debasis Mohanty <debasis.mohanty.listmails@xxxxxxxxx> wrote:
Nice .. Realy nice pointers H.D. !! :)


Really nice pointers yourself!

By searching for:

site:.il signature: 00004550 filetype:pif

I find a site with badtrans.b

www.arava.co.il/matan/svgalib/hypermail/att-1469/01-fun.MP3.pif

Hmm, any bets on who is the most infected TLD... :-)

-JP<who is betting on .ru>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Inflatable Clown Costume
    ... hmm, might not be completely fool proof lol ... *this signature is pointless... ...
    (rec.sport.unicycling)
  • Re: Lets hope easier multi-threaded programming gets on the RoadMap
    ... you might get an av when it disappears. ... Hmm? ... I mainly either a) spawn threads that do a lot of work and wait for the immediately or b) spawn threads that finish their job before the application shuts down, so I haven't really gotten into the issues you mention. ... But thanks for the pointers. ...
    (borland.public.delphi.non-technical)
  • Re: Help
    ... Flash Gordon wrote: ... group,I am searching for an IT job and this sunday I have an ... Interview. ... Remember that arrays and pointers are fundamentally different ...
    (comp.lang.c)
  • Re: Scottish zone engineering easements
    ... I'd imagine it would, strictly speaking, be prohibited. ... Hmm - any pointers to where I may find such wording somewhere? ...
    (uk.railway)
  • API for access to Shared Folders?
    ... pls gimme some pointers. ... But ill ask my question anyways. ... I was searching for API's ...
    (microsoft.public.win2000.security)