|
|||||||||||
|
UPX issues in virus analysis
From: Chris Ess <azarin(at)tokimi.net>
Date: Mon Jul 07 2003 - 14:34:02 EDT
I'm trying to do an analysis of what I think is a modified strain of the Mindjail IRC worm. (We have discussed the first strain already on the incidents@securityfocus.com list. The thread can be found at http://www.securityfocus.com/archive/75/327153/2003-06-26/2003-07-02/1 ) I've extracted the executable for this strain. Since the previous strain was stored via UPX, I figure this one was as well. However, trying to decompress the executable through upx, I get the following error: upx: javax.sun.base.exe: CantUnpackException: file is modified/hacked/protected; take care!!! Has anyone else experienced this and come up with a way to work around it? If not, how would you suggest I proceed? (I don't have a throwaway box to infect, so that's a bit out of the question. Could you use vmware to set up a "sandbox" that you could infect safely without impacting the system otherwise?) Sorry if I'm asking newbie-ish questions, but this is a hobby for me rather than a career. I'd appreciate any advice you would be willing to give. Many thanks in advance. Sincerely,
Chris Ess
Received on Tue Jul 8 09:07:49 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:40 EDT |
||||||||||
|
|||||||||||