Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

UPX issues in virus analysis

From: Chris Ess <azarin(at)tokimi.net>
Date: Mon Jul 07 2003 - 14:34:02 EDT


I'm not sure I've found the right list, but here we go...

I'm trying to do an analysis of what I think is a modified strain of the Mindjail IRC worm. (We have discussed the first strain already on the incidents@securityfocus.com list. The thread can be found at http://www.securityfocus.com/archive/75/327153/2003-06-26/2003-07-02/1 )

I've extracted the executable for this strain. Since the previous strain was stored via UPX, I figure this one was as well. However, trying to decompress the executable through upx, I get the following error:

upx: javax.sun.base.exe: CantUnpackException: file is modified/hacked/protected; take care!!!

Has anyone else experienced this and come up with a way to work around it? If not, how would you suggest I proceed? (I don't have a throwaway box to infect, so that's a bit out of the question. Could you use vmware to set up a "sandbox" that you could infect safely without impacting the system otherwise?)

Sorry if I'm asking newbie-ish questions, but this is a hobby for me rather than a career. I'd appreciate any advice you would be willing to give.

Many thanks in advance.

Sincerely,

Do you need help?X

Chris Ess
System Administrator / CDTT (Certified Duct Tape Technician)



Received on Tue Jul 8 09:07:49 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:40 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library