Vulnerability Development mailing list archives

Re: Suspecious JPEG Files


From: "Geoffrey Gowey" <gjgowey () gmail com>
Date: Tue, 5 Feb 2008 22:13:40 -0800

1) Install sandboxie on your system.
2) install filemon and regmon on your system
3) disconnect system from network
4) run filemon and regmon
5) run suspect program in sandbox
6) wait a little then kill, but don't delete sandbox.

Now you can look at regmon and filemon to see what the program was
trying to access/do without it killing your system.



On 1 Feb 2008 17:10:13 -0000, poddima () yahoo com <poddima () yahoo com> wrote:
Hello,


I recieved via e-mail two JPEG files, one of them was not opened properly
(Default error message was displayed on the Windows Picture Viewer).

The sender is known to me, and I suspect he was trying to attack my computer
(I recieved also an infected executable file from him just a short time
before, and I didn't opened it).


If anyone is interested in trying to analyse the files, I'd be mostly
grateful. Please contact me and I will send you the files.


Thanks!



-- 
Kindest Regards,

Geoff


Current thread: