<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://arnoth.net/earnoth/dokuwiki/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://arnoth.net/earnoth/dokuwiki/feed.php">
        <title>Arnoth.net Documentation Trove</title>
        <description></description>
        <link>http://arnoth.net/earnoth/dokuwiki/</link>
        <image rdf:resource="http://arnoth.net/earnoth/dokuwiki/lib/images/favicon.ico" />
       <dc:date>2010-01-24T16:56:26-06:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:9d64e6a0dc6a3353770916d53350c2ac"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:ubuntu:general"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:linux:commandline"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:0fc38cc0e7f8f732a79b976fd79d9a76"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:1df34209b750a6651f94388897d0f737"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:f981992c0f944aa29ab9a217b98d7172"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:bd618f92139641ac7a2800c9f895a2ce"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:61b0eb271ad8b4417ad3b5e292e4b545"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:a4c0f6ed2dbb15e8dbfbcf261531a1f6"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:ef0d2bf1947b1ff2ffdd572e484f531d"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:0ada2a2f49fd01b56b7c0ca69de2dbf6"/>
                <rdf:li rdf:resource="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:90eef215f1ab82cf891731cace23ac9b"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://arnoth.net/earnoth/dokuwiki/lib/images/favicon.ico">
        <title>Arnoth.net Documentation Trove</title>
        <link>http://arnoth.net/earnoth/dokuwiki/</link>
        <url>http://arnoth.net/earnoth/dokuwiki/lib/images/favicon.ico</url>
    </image>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:9d64e6a0dc6a3353770916d53350c2ac">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-23T14:58:29-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:9d64e6a0dc6a3353770916d53350c2ac</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:9d64e6a0dc6a3353770916d53350c2ac</link>
        <description>Research Notes for bd618f92139641ac7a2800c9f895a2ce

Summary

Notes

2010-01-23


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343.  Installed an agent that started massive communications with a multitude of hosts on the Internet, primarily over port 80 but seeming to use encrypted channels.</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:ubuntu:general">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-23T14:12:49-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:ubuntu:general</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:ubuntu:general</link>
        <description>Ubuntu General Documents

This section contains my documentation for generic features that are typically common across different Ubuntu versions.

Administration

Installing package clusters

Using Apt, one can install many different packages for a purpose using the meta-packages.  For example, the different developer packages (gcc, make, bison, etc) required for compiling most different open source projects can be installed using build-essential:</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-23T13:51:44-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware</link>
        <description>Tracking Sites

&lt;http://www.nothink.org&gt;
 malware irc control sites


Research Notes


 e797cdc4dc4badc3c639bfc2f71240b6 

 53e38a165518036db28523eed3bac45e 

 289567012392e5739fcd5f73043a005e 

 3018e3b251119fd3215489f1f233a328 

 1f443c0271f1d699164521fb8b3dd408</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:linux:commandline">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-11T19:08:25-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:linux:commandline</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:linux:commandline</link>
        <description>The following is a list of useful commands that I've learned for Linux, but that I use so rarely, I tend to forget until I need them again.

Creating a CD ISO


To rip an entire normal data-cd (ISO filesystem) from a CD-ROM:

dd if=/dev/cdrom of=my_cd_image.iso
Making an ISO from a file system


To create an iso using files in Linux:</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:0fc38cc0e7f8f732a79b976fd79d9a76">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:46:51-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:0fc38cc0e7f8f732a79b976fd79d9a76 - created</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:0fc38cc0e7f8f732a79b976fd79d9a76</link>
        <description>Research Notes for 0fc38cc0e7f8f732a79b976fd79d9a76

Summary

Notes

2010-01-10


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343, OS complains that the file “is not a valid Win32 application”.

Links


 virustotal analysis</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:1df34209b750a6651f94388897d0f737">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:41:37-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:1df34209b750a6651f94388897d0f737 - created</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:1df34209b750a6651f94388897d0f737</link>
        <description>Research Notes for 1df34209b750a6651f94388897d0f737

Summary

Notes

2010-01-10


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343.  Received a dialog box that exclaimed, “W32.NytemareV2 says 'Your kung-fu is no good!'”  Will try on a bare-metal victim device tomorrow.</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:f981992c0f944aa29ab9a217b98d7172">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:29:46-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:f981992c0f944aa29ab9a217b98d7172 - created</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:f981992c0f944aa29ab9a217b98d7172</link>
        <description>Research Notes for f981992c0f944aa29ab9a217b98d7172

Summary

Notes

2010-01-10


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343, OS complains that the file “is not a valid Win32 application”.

Executed on Win2KSP0 running in VMware ESX Server 110271, OS complains that the file “is not a valid Win32 application”.</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:bd618f92139641ac7a2800c9f895a2ce">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:26:28-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:bd618f92139641ac7a2800c9f895a2ce - created</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:bd618f92139641ac7a2800c9f895a2ce</link>
        <description>Research Notes for bd618f92139641ac7a2800c9f895a2ce

Summary

Notes

2010-01-10


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343, OS complains that the file “is not a valid Win32 application”.

Executed on Win2KSP0 running in VMware ESX Server 110271, OS complains that the file “is not a valid Win32 application”.</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:61b0eb271ad8b4417ad3b5e292e4b545">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:10:28-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:61b0eb271ad8b4417ad3b5e292e4b545 - created</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:61b0eb271ad8b4417ad3b5e292e4b545</link>
        <description>Research Notes for 61b0eb271ad8b4417ad3b5e292e4b545

Summary

Notes

2010-01-10


Executed on Win2KSP0 running in VMware ESX Server 110271.  Application spawned, but has not yet shown any appreciable network behavior.  Continuing to run the test overnight.</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:a4c0f6ed2dbb15e8dbfbcf261531a1f6">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:07:07-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:a4c0f6ed2dbb15e8dbfbcf261531a1f6</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:a4c0f6ed2dbb15e8dbfbcf261531a1f6</link>
        <description>Research Notes for a4c0f6ed2dbb15e8dbfbcf261531a1f6

Summary

Notes

2010-01-09


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343.  No appreciable network behavior.  Test terminated.

Links</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:ef0d2bf1947b1ff2ffdd572e484f531d">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-10T21:06:50-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:ef0d2bf1947b1ff2ffdd572e484f531d - created</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:ef0d2bf1947b1ff2ffdd572e484f531d</link>
        <description>Research Notes for ef0d2bf1947b1ff2ffdd572e484f531d

Summary

Notes

2010-01-09


Executed on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343.  No appreciable network behavior.  Test terminated.

Links</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:0ada2a2f49fd01b56b7c0ca69de2dbf6">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-09T10:32:55-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:0ada2a2f49fd01b56b7c0ca69de2dbf6</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:0ada2a2f49fd01b56b7c0ca69de2dbf6</link>
        <description>Research Notes for 0ada2a2f49fd01b56b7c0ca69de2dbf6

Summary

Notes

2010-01-09


Unable to execute on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343, OS complains that the file “is not a valid Win32 application”.

Links


 virustotal analysis</description>
    </item>
    <item rdf:about="http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:90eef215f1ab82cf891731cace23ac9b">
        <dc:format>text/html</dc:format>
        <dc:date>2010-01-09T10:31:57-06:00</dc:date>
        <dc:creator>earnoth</dc:creator>
        <title>techdocs:security:malware:90eef215f1ab82cf891731cace23ac9b</title>
        <link>http://arnoth.net/earnoth/dokuwiki/techdocs:security:malware:90eef215f1ab82cf891731cace23ac9b</link>
        <description>Research Notes for 90eef215f1ab82cf891731cace23ac9b

Summary

Notes

2010-01-09


Unable to execute on WinXPHomeSP2 running in VMware Server 1.0.0 build 28343, OS complains that the file “is not a valid Win32 application”.

Links


 virustotal analysis</description>
    </item>
</rdf:RDF>
