CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

What software do u guys use to test links??

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
blades777

Cadet
Cadet


Joined: Mar 02, 2008
Posts: 4
Location: New_Zealand

PostPosted: Mon Mar 31, 2008 5:20 am    Post subject: What software do u guys use to test links??
Reply with quote

sorry if this is a little off topic but when you guys go to all these malware links in here and you upload the malware to virus total
what software do you use to prevent all this malware from infecting your pc??

Back to top
View users profile Send private message
YounGun

1st Responder
Site Moderator

Joined: Dec 11, 2004
Posts: 4369

1st Responders Moderators MVP Rootkit Responders SRT Team F@H

PostPosted: Mon Mar 31, 2008 7:43 am    Post subject:
Reply with quote

Hi Blades.

I can't speak for everyone, but when I go out to catch and try malware, I use a virtualized environment. What that means is that by using tools like VirtualPC or Vmware, you can run a separate operating system within your current working system that is isolated.

For instance I have 2 virtual machines, an XP Sp1 and a Vista Ultimate Sp1 on which I try new malware or test removal procedures.


_________________
IT Stuff
Back to top
View users profile Send private message Visit posters website
bobby_

MIRT Hunter


Joined: Nov 04, 2006
Posts: 237
Location: Austria
MIRT

PostPosted: Mon Mar 31, 2008 8:05 pm    Post subject:
Reply with quote

@YoungGun
More than 50% of todays malware will detect the VM and stop the execution to prevent you finding the actions it normally does.

@blades777
I do not run malware on my PC to see if it will download something, or to take notes about the connection it makes. You have a lot of online sandboxes to do this for you (Anubis, CWSandbox etc.)
I only get the page's source and analyze it to see what does the exploit(s) download and run.
I use my own app for such tasks - Malzilla.
Malzilla is available from http://malzilla.sourceforge.net/


_________________
ASAP member
Back to top
View users profile Send private message Visit posters website
YounGun

1st Responder
Site Moderator

Joined: Dec 11, 2004
Posts: 4369

1st Responders Moderators MVP Rootkit Responders SRT Team F@H

PostPosted: Mon Mar 31, 2008 8:18 pm    Post subject:
Reply with quote

Hi bobby_ Smile

I'm not sure if you percentage is accurate. I would say more 30%-40%. I have a spare Celeron 1.0 Ghz XP SP1 for those exceptions. Anubius is great, but it 1. Doesn't tell you everything 2. You don't get to try an clean the mess the malware makes Very Happy


_________________
IT Stuff
Back to top
View users profile Send private message Visit posters website
solcroft

MIRT Hunter


Joined: Apr 01, 2007
Posts: 188

MIRT

PostPosted: Tue Apr 01, 2008 12:45 pm    Post subject:
Reply with quote

Malzilla is a great tool. Otherwise, Sandboxie + Proxomitron when I'm feeling lazy. I find that Avira helps a great deal when it comes to pinpointing exploit scripts, since it has absolutely paranoid detection for them.

Back to top
View users profile Send private message
blades777

Cadet
Cadet


Joined: Mar 02, 2008
Posts: 4
Location: New_Zealand

PostPosted: Tue Apr 01, 2008 6:13 pm    Post subject:
Reply with quote

does Proxomitron filter out malware when surfing sites with malware?

Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Wed Apr 02, 2008 3:40 am    Post subject:
Reply with quote

I like Process Guard . It asks to let everything you have not whitelisted run . Copy the file and select deny .

You got your sample and it did not run .

Back to top
View users profile Send private message Send email
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Wed Apr 02, 2008 6:37 pm    Post subject:
Reply with quote

I use a combination of sandboxie and malzilla to download files.
I never run them, even sandboxed.

I post virustotal results and links to the MIRT page.

nosirrah wrote:
I like Process Guard
Is this still being updated?

Online Armor also do this, if I understand correctly.

Back to top
View users profile Send private message
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Thu Apr 03, 2008 12:50 pm    Post subject:
Reply with quote

I use a couple of tools....

Main ones are:

Malzilla
Sandboxie
VMware workstation
Tiny Watcher
Kaspersky Anti Virus/Internet Security 8 HIPS
ANUBIS sandbox analyser

When first visiting a suspected malicious domain, I will download source code using malizlla (running inside sandboxie just incase) and manually look through source for suspicious code/script

If I find something suspicious, use malzilla to save to file and I collect all of these potential samples inside sandboxie, disabling them by adding a _ to the end (e.g. load.exe_) to stop myself accidentally infecting myself.

I then either submit the samples to the ANUBIS sandbox for analysis, or let them loose inside my virutal machine (although bobby_ has mentioned that this method is becoming less effective)...and use tiny watcher/kaspersky HIPS to track the changes and any files created or downloaded.

Finally, I collect any additional samples I can gather via sandbox report or the virutal machine and submit them to virustotal and listserv.


_________________
Kaspersky Lab Forum Moderator
KL Cert PSP
Virusinfo.info External Specialist
Alliance of Security Analysis Professionals Member
http://malwarecrawler.com - honeypot@malwarecrawler.com
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer