Penetration Testing mailing list archives

Re: [PEN-TEST] Suspect .EXE Trojan


From: Ben Ford <bford () TALONTECH COM>
Date: Thu, 14 Dec 2000 16:46:29 -0800

If you have access to a Linux or other unix type box, the easiest way is to run
'strings' on the file.  That will give you all the text information contained
within it and would tell you any registry keys modified or files accessed etc.

Good luck.

-b



"Ruso, Anthony" wrote:

Hi,

I have a suspect executable that I think may be a Trojan. A search on the
.exe doesn't return any result with any virus vendor. Are there any tools
that would allow me to execute the file in isolation and actually see what's
going on. The file was already executed on two workstations and it killed
Outlook in both cases. I know I can use tripwire and similar products to see
what files it makes changes to but I don't want to risk killing outlook
again.

Thanks

Anthony Ruso


Current thread: