Pocket PC Addict Forums



» BoxWave
BoxWave Corporation
» More Resources

Welcome to the Pocket PC Addict Forums!

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, download files, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   Pocket PC Addict Forums > General Discussion > Pocket PC Addict Archive

view more in our Photo Gallery...

Pocket PC Addict Archive Old news but good news. Anything 2003 and earlier is in here.

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 10-12-2004, 02:48 PM
Brad Isaac's Avatar
Honorary Addict!
Extraordinary Addict!
 
Join Date: Jan 2002
Location: North Carolina
Posts: 5,193
Downloads: 0
Uploads: 0
Reverse-Engineering the First Pocket PC Trojan


I have always been sort of fascinated with the way that antivirus firms can receive a virus attachment or trojan and within a couple of hours have a patch repairing said virus. How exactly do they get into the code? How do they figure out what's going on and the payload of the thousands of reported viruii each year? Well, by way of Geekzone we saw Reverse-Engineering the First Pocket PC Trojan (Part 1 and 2). This article seems to provide a pretty detailed analysis on how you or I could become virus super sleuths using hex editors and some searching tools of our own.
"The first step to reverse-engineering a malicious binary is to see what you can find out about it online. When the Brador Trojan first made headlines, it was sensationalized as being a widespread threat, which it really wasn't. Many of the larger antivirus companies that analyzed Brador later changed their descriptions of this Trojan (take a look at some of the change logs for more details). Brador may not be as widespread as originally thought, but it certainly is a threat that can be difficult for a beginner to detect and remove.
Before we dive into the full reverse-engineering process, we take a quick look at the binary using a hex editor. (Many free hex editors are available online.) As Figure 1 shows, the author's email address (brokensword@ukr.net) is included in the Trojan code. This Trojan implements an SMTP-based notification system that sends the victim's details to the author's email address. This email address is the key to the origins of this Trojan. Traced back, this email address originates from Russia, giving us a starting point for our search. Knowing that the Trojan originated in Russia and knowing the email address gives us enough information to begin uncovering the birthplace and author of this Trojan. "
__________________
Experts say 97% of people get goal setting wrong. Here's how to get it right!
Reply With Quote
Sponsored Links
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:20 PM.




Content Relevant URLs by vBSEO 3.3.0
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2006 by Pocket PC Addict