Penetration Testing mailing list archives

Re: [PEN-TEST] Suspect .EXE Trojan


From: WernerC <WernerC () SEC GOV>
Date: Thu, 14 Dec 2000 15:36:35 -0500

There's a commercial product by finjan called SurfinShield that purports to
create a "sandbox" to isolate unknown malicious code.   Here's a blurb from
the product description:

"Behavior Monitoring of active content in real-time in SurfinShield's
sandbox including Executables, ActiveX controls, Java applets, Scrap files
(.shs), and all Windows scripting host files (e.g., .VBS, .JS, .WSH, etc.)"

The website (finjan.com) doesn't have pricing, but there is an option to
download an evaluation copy.  Don't know if it will help you or not.

--Carol Werner

-----Original Message-----
From: Ruso, Anthony [mailto:aruso () POSITRON QC CA]
Sent: Thursday, December 14, 2000 1:59 PM
To: PEN-TEST () SECURITYFOCUS COM
Subject: [PEN-TEST] Suspect .EXE Trojan


Hi,

I have a suspect executable that I think may be a Trojan. A search on the
.exe doesn't return any result with any virus vendor. Are there any tools
that would allow me to execute the file in isolation and actually see what's
going on. The file was already executed on two workstations and it killed
Outlook in both cases. I know I can use tripwire and similar products to see
what files it makes changes to but I don't want to risk killing outlook
again.

Thanks

Anthony Ruso


Current thread: