Raul Siles

Malware Analysis / Análisis de SW malicioso

Whitepapers Tools Web AV (Online) AV (Free)

This Web page focuses on how to analize and reverse engineer malware (Malicious Software) specimens, IMHO, one of the most interesting topics in the security field, typically associated to virus, worms, trojans, spyware, adware... that is, malware.

Esta página Web contiene información sobre en análisis de software maliciosos (malware).

Whitepapers / Artículos
The Evolution of Malicious AgentsLenny ZeltserMay, 2000
Reverse Engineering MalwareLenny ZeltserMay, 2001
Reverse Engineering Hostile CodeJoe StewartOctober 23, 2002
Alien Autopsy: Reverse Engineering Win32 Trojans on LinuxJoe StewartNovember 14, 2002
Trojan HorsesEd SkoudisDecember 12, 2003
Malware Analysis for AdministratorsS. G. MasoodMay 20, 2004
Spyware explainedJoanthan ReadMay 28, 2004
Attacking Obfuscated Code with IDA ProChris Eagle. Black Hat USA 2004Summer 2004
Reverse Code Engineering: An In-Depth Analysis of the Bagle VirusKonstantin RozinovAugust 2004
Honeynet Project "Scan of the Month" challenges, SotM 32David Pérez, Jorge Ortiz y Raúl SilesSeptember 2004
Anti-spyware Test (Guide)Eric L. HowesOctober, 2004
Honeynet Project "Scan of the Month" challenges, SotM 33Nicolas BrulezDecember 2004
MS AntiSpyware vs Ad-Aware vs SpyBotTeam FlexbetaJanuary 2005
Red Pill... or how to detect VMM using (almost) one CPU instructionJoanna Rutkowska
Introduction to Reverse Engineering Win32 ApplicationstrewMay 2005
Malicious Malware: attacking the attackers, part 1T. Holz, F. RaynalJanuary 2006
Malicious Malware: attacking the attackers, part 2T. Holz, F. RaynalFebruary 2006

Tools / Herramientas
mwcollectGeorg WicherskiSolution to collect worms and other autonomous spreading malware in FreeBSD or Linux
SysinternalsMark RussinovichAdvanced Windows tools: File/TDI/P/Disk/Port/RegMON, PSTools, TCPView...
IDA Pro Disassembler Data RescueThe "commercial" debugger/disassembler (Eval for Windows)
LordPEYodaPE (Portable Executable) files editor and manager

Web
LURQMalware technical analysis
SpywarewarriorRogue/Suspect Anti-Spyware Products & Web Sites, comparisons, testing...
Malware.comWindows vulnerabilities and exploits


Sophos virus infoMaterial about viruses, hoaxes, trojans, spyware...
McAfee virus infoRemoval tools, current threads...
Symantec security responseRemoval tools, current threads...
Trendmicro security informationVirus rating and current threads...
F-Secure virus informationVirus stats, current threads...
Messagelabs IntelligenceGlobal e-mail security threats
FortiProtectCenterVirus and attacks encyclopedia

AntiVirus (online)
Virustotal Multi-analysis malware engine (using several antivirus)
Norman Sandbox (NSIC) Malware analysis engine (sandbox)
McAfee Free Scan McAfee VirusScan AV
Symantec Security Check Security Scan and Virus Detection
Trendmicro HouseCall Free online Trendmicro virus scanner
Bitdefender scan online Free online Bitdefender virus scan
Parasites Find unsolicited commercial software in your system
Panda ActiveScanFree online Panda antivirus

Free AntiVirus and Malware detection software
AntiVirPersonal Edition Classic (for Windows 98/Me and XP (XP&2000&NT), Linux/OpenBSD/FreeBSD/Solaris)
AVG Anti-VirusWindows
F-ProtWindows, Linux, DOS, Solaris, BSD
AvastHome Edition - Windows
Spybot Search & DestroyWindows (Spyware)
Ad-awareSE Personal - Windows (Adware)
MS Windows AntiSpyware (Beta)Windows (Spyware)