Penetration Testing mailing list archives
Re: [PEN-TEST] Suspect .EXE Trojan
From: Tomi Tuominen <Tomi.Tuominen () F-SECURE COM>
Date: Mon, 18 Dec 2000 08:17:48 +0200
Hello, Bob Dog wrote:
I would like to respond to this with my own question. Is there an orginization that I could send a suspected file to that could tell me whether or not it was malicious? Will AV vendors give you such information?
If you have any suspected files, feel free to send them to samples () F-Secure com Regards, --T -- [ Tomi 'T' Tuominen [ F-Secure Corporation / Security Research [ http://www.F-Secure.com ------8<---------------------------------------------------------------- "Ruso, Anthony" <aruso () POSITRON QC CA> wrote:
I have a suspect executable that I think may be a Trojan. A search on the .exe doesn't return any result with any virus vendor. Are there any tools that would allow me to execute the file in isolation and actually see what's going on. The file was already executed on two workstations and it killed Outlook in both cases. I know I can use tripwire and similar products to see what files it makes changes to but I don't want to risk killing outlook again.
Current thread:
- Re: [PEN-TEST] Suspect .EXE Trojan, (continued)
- Re: [PEN-TEST] Suspect .EXE Trojan Mark Curphey (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Yonatan Bokovza (Dec 15)
- Re: [PEN-TEST] Suspect .EXE Trojan Eaton, Arthur (Dec 15)
- Re: [PEN-TEST] Suspect .EXE Trojan Ben Ford (Dec 15)
- Re: [PEN-TEST] Suspect .EXE Trojan Nexus (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Pierre Vandevenne (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan MadHat (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Nexus (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Frank Knobbe (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Andrew Lawton (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Bob Dog (Dec 16)
- Re: [PEN-TEST] Suspect .EXE Trojan Tomi Tuominen (Dec 19)
- Re: [PEN-TEST] Suspect .EXE Trojan Jensen, Greg (Dec 17)
- Re: [PEN-TEST] Suspect .EXE Trojan Marty Richards (Dec 18)