Malware Activity
RSS Feed

mwcollect.org Blog

Malware Observations and Recent Threats

nepenthes 0.2.2

Nepenthes has just been released in version 0.2.2, grab your copy from SourceForge.

Georg Wicherski // 2008-02-14 13:32 CET

Defeating Allaple DB Polution

The pesky Allaple worm has bugged us long enough. Since it is polymorphic, each instance of this binary has a new, unique MD5 hash and hence appears as a new binary in the mwcollect Alliance repository. However, developing a certain hash function, I was able to group most of the Allaple binaries together, now appearing as a mere of 33 distinct entries in the Browse Specimens view:

PE Hash based Allaple grouping

I will disclose some of the details behind this in my talk on DeepSec.

Georg Wicherski // 2007-10-16 19:07 CET

teamSparta won C.I.P.H.E.R. CTF

teamSparta (Hans-Christian Ebke, Dennis Mohr, Jan-Thorsten Peter, Mark Schloesser, Georg Wicherski) won the first place in the C.I.P.H.E.R. CTF Hacking Challenge. Was a great game!

Georg Wicherski // 2007-07-15 17:03 CET

*.mwcollect.org Back Online

The main mwcollect.org server is now fully operational again after a downtime of more than a week. One of the harddrives failed during sunday afternoon and it took some time to get new ones and replace the old ones.

During this reinstall, beta.mwcollect.org also now became the official alliance.mwcollect.org.

Georg Wicherski // 2007-06-27 23:22 CET

Page Fixed

The new mwcollect Alliance Webinterface (still work in progress) has moved to a new server, where fonts are properly installed. Thus the image in the header of this page has a legend again.

I hope to finish the new webinterface with Markus and Paul at our mini GetTogether, we will have from 23rd to 26th of March in Aachen. Tillmann, who recently joined the mwcollect.org Crew, will also be there. Sounds like gonna be fun!

Georg Wicherski // 2007-03-09 22:59 CET
All Entries »