Read more of this story at Slashdot.
As I sit in my hotel room in Washington DC at the SANSFIRE 2013 conference, preparing to present Memory Analysis with Volatility to a SANS@Night crowd (7:15 International Ballroom Center), an opportunity arose from which to get you warmed up for tonight's talk or inspire you to become a Volatility user (you should be already).
We received an advisory from a faithful reader indicating that he had uploaded "a dropper we got blitzed with from a spam campaign today" to ISC. We love us some malware samples, so I got busy.
A typical review of the sample (invoice.exe) on a Windows VM gave us the basic behavioral details as seen in this ProcDOT visualization (ProcDOT also rules).

We can see that the invoice.exe process makes two Internet calls, spawns some shells to run reg.exe and create some registry entries, and creates a log file along with replicating itself to mc.exe in the victim user Application Data directory, before hiding itself from visible user APIs. Anubis provides better detail, but of concern was that fact that invoice.exe and mc.exe (same file, same hash) exhibited only one AV detection via Virustotal as this was written (certain to change soon). As such, we don't have much to go from as to what malware family we're really dealing with here.
But wait...Volatility to the rescue. I grapped a memory image from the compromised VM, copied the memory dump to my faithful SIFT 2.14 VM, and issued three simple commands that gave me all I needed to know.
Here's the play by play.
I upload said .dmp file to Virustotal and voila, now we know what we're dealing with. Our faithful reader is the proud owner of a W32.Shadesrat (Blackshades) variant. This is one malware family where they apparently caught the bad guy last year (not before he sold his warez to many a miscreant as is evident here).
Wise man say "What I hear I forget, what I see I remember, what I do with Volatility I understand."
Hope to see you tonight at SANSFIRE 2013 for some Volatility 101 across the full lifecycle of security analytics (penetration testing, monitoring, incident response).
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Read more of this story at Slashdot.
Small Picture’s Fargo 0.8 connects outlines and blogging. An outline can be an entire website.
Small Picture is Dave Winer and Kyle Shank. Occasionally other iOS and Mac developers ask me if they should follow what Dave is working on. The answer is yes.
Dave has been a big part of some big things, some of which I’m sure you love: outlining, inter-application communication on Macs, blogging, RSS and OPML, and inter-application communication over the web.
And he’s always been a voice for freedom, for openness over lock-in, for a human and humane web.
I used to work at UserLand Software, Dave’s company in the ’90s and early 2000s. And I quite frequently had no idea where he was going with something. It took me a couple years to be interested in RSS! But I knew enough to pay attention and give the technology time to mature — and to give myself time to understand it.
If you’re like me, a Mac and iOS developer, right now you’re thinking about iOS 7 and OS X Mavericks. You’re figuring out how to make a living on the various App Stores. You’re watching the WWDC videos and wondering what cool new things you can do.
And you might look at Fargo and not know right off the bat how it’s going to change the world or even be relevant to what you’re doing. I don’t know either — yet. Which is totally fine. I’m going to pay attention and let it sink in, and you should too.
I’ll put it another way. I can take a good idea and make a nice app, but Dave can make a good idea.