Welcome to Community Server Sign in | Join | Help

March 2006 - Posts

I was analyzing Win32/Valla.2048 today, a file infector written in x86 Assembly. It keeps almost all of its variables (file handles, API function addresses, etc.) at the end of its section and it references these variables relative to EDI: Read More
Scott Lambert and I will be giving a two-day training course at Black Hat in Las Vegas this summer on Advanced Malware Deobfuscation (http://www.blackhat.com/html/bh-usa-06/train-bh-us-06-sl-advmal.html). This isn't a class where we lecture you Read More