<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Malware Analysis</title>
	<link>http://www.malware-analysis.net</link>
	<description>A look at malicious code and it&#039;s behavior</description>
	<lastBuildDate>Thu, 19 Aug 2010 21:53:31 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0" -->

	<item>
		<title>Ramnit.A Virus</title>
		<description><![CDATA[Wow it has been quite a while since I last posted and life/work/etc&#8230; have been crazy. But I wanted to post about a new infection we&#8217;re really starting to see take off in the forums. W32/Ramnit.A &#8211; aka Packed.Win32.Krap by Kaspersky or W32/Infector by Avira and others Analysis Virus Total Results ThreatExpert Analysis The good [...]]]></description>
		<link>http://www.malware-analysis.net/?p=321</link>
			</item>
	<item>
		<title>The Appropriately Named Winlock Trojan</title>
		<description><![CDATA[The dropper sample analyzed here was picked up from a colleague in the forums. It&#8217;s identified as Trojan Winlock, Calelk.C, and other various names. It has also been known to partner up with the TDSS rootkit, although this sample did not drop that component of the infection. Analysis On the date of analysis less than [...]]]></description>
		<link>http://www.malware-analysis.net/?p=295</link>
			</item>
	<item>
		<title>The Persistent Security Tool Malware Rogue</title>
		<description><![CDATA[I was recently doing some testing in the VM with several of the various rogues that we are seeing lately. This testing was mainly looking at how Malware modifies proxy settings and such (will be in a later article). One of the rogues that that landed was the Security Tool Malware. Most of these rogues [...]]]></description>
		<link>http://www.malware-analysis.net/?p=285</link>
			</item>
	<item>
		<title>Max++ &#8220;version 2&#8243; Rootkit Analysis</title>
		<description><![CDATA[Although not widespread there is a rootkit that has been going around for the past few months called ZAccess, aka Zeloaces, or aka Max++ (version 2). It is really nothing like &#8220;version 1&#8243; of Max++ and the mode of operation is quite simple, at least on the surface. I have not seen too many of [...]]]></description>
		<link>http://www.malware-analysis.net/?p=236</link>
			</item>
	<item>
		<title>The Zimuse Worm ~ A Hard Drive Killer</title>
		<description><![CDATA[This one has been big in the news as of late and I received a few samples to play with. I have not seen any cases in the forums yet but I&#8217;m wondering if it&#8217;s because of the fact there are almost no indications of it running. This could be unfortunate because if it goes [...]]]></description>
		<link>http://www.malware-analysis.net/?p=208</link>
			</item>
	<item>
		<title>Playing around with a Banker Trojan</title>
		<description><![CDATA[I know what some of you might say&#8230;.&#8221;why would you want do that?&#8221; As the man said when asked why did you climb the mountain? &#8220;Because it was there&#8221;. My answer is, &#8220;because I can!&#8221; Summary The analysis done here is as usual within an isolated virtual machine. The sample was picked up from a [...]]]></description>
		<link>http://www.malware-analysis.net/?p=179</link>
			</item>
	<item>
		<title>Internet Security 2010</title>
		<description><![CDATA[Introduction: Just picked up a downloader trojan for Internet Security 2010 rogue from a fellow researcher. This is a fairly new variant that is only picked up by 5 out of the 41 scanners at Virus Total as Malware. Analysis here was done in a virtual machine as the file is not VM aware. Note [...]]]></description>
		<link>http://www.malware-analysis.net/?p=133</link>
			</item>
	<item>
		<title>Bagle Analysis</title>
		<description><![CDATA[Bagle Malware appears to be making a comeback lately. Not as much in the US but more so in Europe, although that&#8217;s subject to change as it can spread fast. Bagle is not necessarily new, although new variants are constantly being developed. Usually nastier with each version. This new version is absolutely nasty. Some symptoms [...]]]></description>
		<link>http://www.malware-analysis.net/?p=93</link>
			</item>
	<item>
		<title>IObit using blackhat SEO to promote product</title>
		<description><![CDATA[WARNING: The material presented here may be offensive to some readers. It relates to the promotion of online porn and other questionable practices. If you are not comfortable with it then please surf away from here. In follow up discussions and investigations of IObit, it has been discovered that part of their marketing plan is [...]]]></description>
		<link>http://www.malware-analysis.net/?p=83</link>
			</item>
	<item>
		<title>Analysis of a Rogue installation</title>
		<description><![CDATA[In the forums we are often asked &#8220;How did this happen? How did I get infected?&#8221; I would like to detail just one of the ways this can happen. Now keep in mind this is only one way. There are many others, such as through file sharing sites, cracks and keygens, and email attachments. You [...]]]></description>
		<link>http://www.malware-analysis.net/?p=53</link>
			</item>
</channel>
</rss>
