Forums: Analyzing A Suspicious File - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Analyzing A Suspicious File What tools and what ways?

#1 User is offline   IcedOut3E 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 154
  • Joined: 12-February 04

Posted 26 May 2005 - 06:28 AM

Whats up all.

I was wondering as to what steps everyone takes in analyzing a suspicisous file.

I received an virul email with an exe attached and I want to find out more about it.

These were the tools I was thinking I needed:
1. A safe environment (vmware or such)
2. A hex editor
3. Possibly a decompiler
4. PEID to detect what packer was used.

Can anyone else suggest any more tools that I might use in this process.

Thanks for your help.

Iced.
0

#2 User is offline   White Scorpion 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 674
  • Joined: 05-September 04

Posted 26 May 2005 - 07:19 AM

filemon and regmon from sysinternals.. for the rest the most important tool is your brain... also a debugger like ollydbg to step through the program could be extremely useful IMO.
The path of access leads to the server of wisdom..

The Syringe - My Latest Project.
Errors, Vulnerabilities & Exploits explained.
----
www.white-scorpion.nl
www.info-sec.eu
www.info-sec.info
0

#3 User is offline   FiNaLBeTa 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 461
  • Joined: 26-December 03

Posted 26 May 2005 - 07:40 AM

a verry good tool is Icntr (or in control), released by pc magazine some years ago, compares registry and file system before and after. what files changed, added deleted, same for registry. (basicly file and regmon in one)

Also it's wise to start a sniffer... for the obvious reasons.
0

#4 User is offline   IcedOut3E 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 154
  • Joined: 12-February 04

Posted 26 May 2005 - 08:08 AM

Awesome stuff guys, thanks a lot.

This definitely puts me in the right direction. Good idea with the sniffer, I didn't even think of that one.
0

#5 User is offline   FiNaLBeTa 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 461
  • Joined: 26-December 03

Posted 26 May 2005 - 09:18 PM

It seems incntr5 is hard to find these days. Google no longer returns anything.
So I've uploaded it for you on this board, since I think it's useful for many.

http://www.governmen...t=0#entry116546
0

#6 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 26 May 2005 - 09:51 PM

Softice can be used as well, if you run Win98 in your environment. Instead of decompiler, a disassembler is better. Because there's no decompiler that reconstructs all the source.
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#7 User is offline   ozzy 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 24
  • Joined: 05-November 04

Posted 26 May 2005 - 10:15 PM

wath you say abaut this tool: Total Uninstall..

hxxp://www.softpedia.com/get/Tweak/Uninstallers/Total-Uninstall.shtml

ozzy
0

#8 User is offline   METAHUMAN 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 28
  • Joined: 17-March 04

Posted 30 May 2005 - 02:15 AM

IDAPro .. I hear it is the best Disassembler.. todate.
0

#9 User is offline   own3dripy 

  • Private
  • Icon
  • Group: Members
  • Posts: 8
  • Joined: 24-June 05

Posted 25 June 2005 - 11:51 PM

This is the exact topic i was lookin for.

Thanks for the tips.I'll analyze the .exe that i received today as a email
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting