Full Disclosure mailing list archives

Re: SDbot Virus


From: Thierry Zoller <Thierry () sniff-em com>
Date: Sat, 2 Apr 2005 11:05:00 +0200

Dear Jeffry Bilder,

Upload it here:
http://virusscan.jotti.org

Also the sandbox from NORMAN [1] will help you a great deal with
"analysis", it tells you the IRC server, room, password and name
your exe was configured to use. I met some nice poeple using that
method ;)

[1]
http://sandbox.norman.no/live_4.html

-- 
Thierry Zoller



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: