.
Bitland.Net Security Notes            Comments? email jwilkins-at-bitland*net
More information on the author at Jonathan Wilkins's home page
RSS feed available at http://www.bitland.net/index.rss               Add to Google
Archives: 2007, 2006, 2005, 2004, 2003, 2002, 2001, 2000


Norman Sandbox  |  (2005/12/16 10:00)

Thorsten Holz recently pointed out the Norman Sandbox on Dave Aitel's Daily Dave mailing list

This tool analyzes random malware and tells you what it does. You upload it and it prints out stuff like:

[ Network services ]
* Looks for an Internet connection.
* Connects to "lazy.irwanmartin.com" on port 6667 (TCP).
* Connects to IRC server.
* IRC: Uses nickname |521508.
* IRC: Uses username mlraczsp.
* IRC: Joins channel #bin with password 64b5e2Nb.
* IRC: Sets the usermode for user |521508 to -x-i.


Looks quite handy.

+digg  |  +del.icio.us   |    [Tools ]   |   Permanent link

RSS feed available at http://www.bitland.net/index.rss