Malware Activity

2008-05-01

Reflect Yourself

Mayday 2008 was a total blast, DJ Korsakoff made a hell of a performance. Eventhough I didn't sleep the last 30 hours or so, I'm still rather awake due to the coffinated water they sold. I'll update this blog post with some own trashy mobile phone video later.

We are still here!

Labels:

2008-03-13

Botnet Monitoring Frontend

BotMon

Labels: ,

2007-12-15

Spam, please

Please send me your spam or malware!

Labels:

2007-09-27

REP(N)Z and the EFLAGS

Working on some debugger like automation code for EmsiSoft, I recently discovered a funny property when single stepping REPNZ prefixed SCAS and CMPS instructions using the TF bit set in EFLAGS. As expected, for each single byte / word / doubleword, a debug event occurs. However, the EFLAGS register's status bits (e.g. ZF) are not correct for each single iteration but the last.

I tested this in Windows XP in a VmWare, didn't have the time to reproduce on a physical machine yet. Let me know if you run over this quirk, too.

Labels:

2007-09-11

My ISP Blocks YouPorn

Arcor, my home ISP, yesterday started blocking YouPorn. Welcome to China!

Labels: ,

2007-08-30

Alliance Public Submissions

You can now upload your samples to the Alliance manually, without being a member of the mwcollect Alliance. Submissions are correlated with automatically collected samples:

interface

Labels: