sudosecure.net

              is anything truly secure…

Archive for the 'Site Update' Category


Storm Binary Tracker Update

Posted by jeremy on 8th March 2008

I just added a search by IP feature to the Storm Binary Tracker page after talking with the guys over at Malware Domain List . If your unfamiliar with this site you really ought to go give it a serious look over as they house some really good information for anyone interested in malware and malware analysis. Boban Spasic aka Bobby, the creator of Malzilla posts there regularly about updates for his tool, and I even read in some of the forums where he was taking ideas from posters to better his tool. If your unfamiliar with Malzilla, it is one awesome tool for exploring malicious websites and you should really give it a try. When I first started trying to explore and deobfusticate malicious web pages I would use a large mixture of tools such as wget, SpiderMonkey (JavaScript Engine), miscellaneous bash tools, and a whole lot of custom Perl scripts that would do conversions for me, but now I pretty much only ever use those tools when I can't get Malzilla to do it for me, which might I add has almost never happened since I started using it. What prevented me from using it at first is it is a Windows only application and I run Linux on most of my computers. Once I figured out how to get it to work in Wine (the Windows API for Linux), which again may I add was as simple as sucking the package down and executing it with Wine, I haven't looked back since.

Posted in Site Update, Storm Worm | No Comments »