Penetration Testing mailing list archives

Re: [PEN-TEST] Suspect .EXE Trojan


From: Tomi Tuominen <Tomi.Tuominen () F-SECURE COM>
Date: Mon, 18 Dec 2000 08:17:48 +0200

Hello,

Bob Dog wrote:
I would like to respond to this with my own question.
Is there an orginization that I could send a suspected
file to that could tell me whether or not it was
malicious? Will AV vendors give you such information?

If you have any suspected files, feel free to send
them to samples () F-Secure com

Regards,

--T

--
[   Tomi 'T' Tuominen
[   F-Secure Corporation / Security Research
[   http://www.F-Secure.com

------8<----------------------------------------------------------------

"Ruso, Anthony" <aruso () POSITRON QC CA> wrote:
I have a suspect executable that I think may be a Trojan.
A search on the .exe doesn't return any result with any virus
vendor. Are there any tools that would allow me to execute the
file in isolation and actually see what's going on. The file was
already executed on two workstations and it killed Outlook in both
cases. I know I can use tripwire and similar products to see
what files it makes changes to but I don't want to risk killing
outlook again.


Current thread: