<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Sampling a Malicious Site</title>
	<atom:link href="http://blog.didierstevens.com/2008/08/10/sampling-a-malicious-site/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/08/10/sampling-a-malicious-site/</link>
	<description>(blog \'DidierStevens)</description>
	<lastBuildDate>Mon, 10 Jun 2013 08:49:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: suggested reading&#160;&#124;&#160;VistaSpyware.com</title>
		<link>http://blog.didierstevens.com/2008/08/10/sampling-a-malicious-site/#comment-33488</link>
		<dc:creator><![CDATA[suggested reading&#160;&#124;&#160;VistaSpyware.com]]></dc:creator>
		<pubDate>Sat, 20 Sep 2008 01:44:07 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=544#comment-33488</guid>
		<description><![CDATA[[...] Sa&#173;mpli&#173;n&#173;g a&#173; Ma&#173;li&#173;ci&#173;o&#173;u&#173;s Si&#173;te « Di&#173;di&amp;...a nice l&#173;it&#173;t&#173;l&#173;e video&#173;&#173; sh&#173;o&#173;&#173;wing t&#173;h&#173;e ex&#173;t&#173;r&#173;act&#173;io&#173;&#173;n o&#173;&#173;f&#173; mal&#173;war&#173;e f&#173;r&#173;o&#173;&#173;m a mal&#173;icio&#173;&#173;us sit&#173;e&#8230; [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Sa&#173;mpli&#173;n&#173;g a&#173; Ma&#173;li&#173;ci&#173;o&#173;u&#173;s Si&#173;te « Di&#173;di&#38;&#8230;a nice l&#173;it&#173;t&#173;l&#173;e video&#173;&#173; sh&#173;o&#173;&#173;wing t&#173;h&#173;e ex&#173;t&#173;r&#173;act&#173;io&#173;&#173;n o&#173;&#173;f&#173; mal&#173;war&#173;e f&#173;r&#173;o&#173;&#173;m a mal&#173;icio&#173;&#173;us sit&#173;e&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pocket Virus Lab &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/08/10/sampling-a-malicious-site/#comment-33423</link>
		<dc:creator><![CDATA[Pocket Virus Lab &#171; Didier Stevens]]></dc:creator>
		<pubDate>Thu, 04 Sep 2008 18:57:57 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=544#comment-33423</guid>
		<description><![CDATA[[...] Pocket Virus&#160;Lab Filed under: Hardware, Malware, nslu2 &#8212; Didier Stevens @ 18:57   Slugs are versatile little machines. I installed Slugos on my NSLU2, followed by the tools I used in my sampling video. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Pocket Virus&nbsp;Lab Filed under: Hardware, Malware, nslu2 &#8212; Didier Stevens @ 18:57   Slugs are versatile little machines. I installed Slugos on my NSLU2, followed by the tools I used in my sampling video. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: randy</title>
		<link>http://blog.didierstevens.com/2008/08/10/sampling-a-malicious-site/#comment-33320</link>
		<dc:creator><![CDATA[randy]]></dc:creator>
		<pubDate>Tue, 12 Aug 2008 13:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=544#comment-33320</guid>
		<description><![CDATA[Thanks for the video! It&#039;s always nice to see how other professionals conduct their work for a self check.

I&#039;ve been conducting analysis with basically the same methodology as you show here and it works great. What I wasn&#039;t doing was automating stuff with the use of extractscripts and your modified spidermonkey.  You can bet that I will be now though! Much nicer than writing a Perl or ruby script to deobfuscate the JavaScript. ;)

One added step I like to do is use the sandbox at Sunbelt Software to see what file/registry/network activity an executable causes. Helps when manually verifying if a system is truly infected or not. [http://research.sunbelt-software.com/Submit.aspx]

Keep up the great posts!]]></description>
		<content:encoded><![CDATA[<p>Thanks for the video! It&#8217;s always nice to see how other professionals conduct their work for a self check.</p>
<p>I&#8217;ve been conducting analysis with basically the same methodology as you show here and it works great. What I wasn&#8217;t doing was automating stuff with the use of extractscripts and your modified spidermonkey.  You can bet that I will be now though! Much nicer than writing a Perl or ruby script to deobfuscate the JavaScript. <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>One added step I like to do is use the sandbox at Sunbelt Software to see what file/registry/network activity an executable causes. Helps when manually verifying if a system is truly infected or not. [http://research.sunbelt-software.com/Submit.aspx]</p>
<p>Keep up the great posts!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://blog.didierstevens.com/2008/08/10/sampling-a-malicious-site/#comment-33311</link>
		<dc:creator><![CDATA[Dave]]></dc:creator>
		<pubDate>Mon, 11 Aug 2008 16:42:29 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=544#comment-33311</guid>
		<description><![CDATA[Thank you for such a fascinating tour of what you do, and how to do it safely.  I must admit that I don&#039;t use Linux much but you&#039;ve certainly stimulated me into investigating.

I have used wget.exe to download .html files then I&#039;ve opened them into Notepad (or Notepad++).  I&#039;ve resorted to putting in the line breaks etc. manually and eventually come across the file name of the malicious executable(s) within the JavaScript.  Your way is much more elegant!

I&#039;ll be on the lookout for malicious sites and investigate further.  I get a number of spam e-mails from banking sites (which I see via my webmail) so I think that one of these will be the topic for my investigation.]]></description>
		<content:encoded><![CDATA[<p>Thank you for such a fascinating tour of what you do, and how to do it safely.  I must admit that I don&#8217;t use Linux much but you&#8217;ve certainly stimulated me into investigating.</p>
<p>I have used wget.exe to download .html files then I&#8217;ve opened them into Notepad (or Notepad++).  I&#8217;ve resorted to putting in the line breaks etc. manually and eventually come across the file name of the malicious executable(s) within the JavaScript.  Your way is much more elegant!</p>
<p>I&#8217;ll be on the lookout for malicious sites and investigate further.  I get a number of spam e-mails from banking sites (which I see via my webmail) so I think that one of these will be the topic for my investigation.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
