.exe activity monit...
 
Notifications
Clear all

.exe activity monitor

5 Posts
3 Users
0 Reactions
490 Views
(@research1)
Estimable Member
Joined: 17 years ago
Posts: 165
Topic starter  

If I had a virus or spy ware binary, not the source code, and I wanted to determine the purpose, functionality, basically as much as I could find out about that software by monitoring it…what tools could I use and methods? I'm quite interested in this application to Linux and Windows testing/tools only.

This is theory, not real case.


   
Quote
(@seanmcl)
Honorable Member
Joined: 19 years ago
Posts: 700
 

You could write a whole book about this topic and, in fact, people have.

Consider

Malware Forensics, Aquilina, Casey and Malin

http//www.amazon.com/Malware-Forensics-Investigating-Analyzing-Malicious/dp/159749268X/ref=sr_1_1?ie=UTF8&s=books&qid=1272456542&sr=1-1

Malware Fighting Malicious Code, Skoudis and Zeltzer

http//www.amazon.com/Malware-Fighting-Malicious-Ed-Skoudis/dp/0131014056/ref=sr_1_4?ie=UTF8&s=books&qid=1272456542&sr=1-4

For starters…


   
ReplyQuote
(@research1)
Estimable Member
Joined: 17 years ago
Posts: 165
Topic starter  

Thanks for that, I just want some tools people use to monitor activity of packets outgoing etc, ethereal, wire shark etc.


   
ReplyQuote
(@seanmcl)
Honorable Member
Joined: 19 years ago
Posts: 700
 

No problem. You can also consider Windows Sysinternals tools (Procmon is especially informative though it generates volumes of data). We also use sandboxes to look at these. There is a commercial product, CWSandbox, which supports malware analysis.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

JFYI
http//virusremoval.pro/thread-11.html

And a low cost/limited freeware tool
http//virusremoval.pro/thread-9.html

jaclaz


   
ReplyQuote
Share: