<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>inREVERSE</title>
	<atom:link href="http://www.inreverse.net/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.inreverse.net</link>
	<description></description>
	<lastBuildDate>Thu, 17 Nov 2011 10:54:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>More on callbacks: ObRegisterCallbacks</title>
		<link>http://www.inreverse.net/?p=1740</link>
		<comments>http://www.inreverse.net/?p=1740#comments</comments>
		<pubDate>Sun, 10 Jul 2011 11:53:12 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[callbacks]]></category>
		<category><![CDATA[internals]]></category>
		<category><![CDATA[kernel]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1740</guid>
		<description><![CDATA[Today is ObRegisterCallbacks&#8216;s turn: available since Vista SP1, permits to &#8220;register a list of callback routines for thread and process handle operations&#8221;. Together with the last blog from Zairon should cover the main callbacks. After a few checks on the parameters passed the function iterates over the Operations array, checking that every entry (of type [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1740</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>CARO2011 &#8211; Java Malware Presentation</title>
		<link>http://www.inreverse.net/?p=1687</link>
		<comments>http://www.inreverse.net/?p=1687#comments</comments>
		<pubDate>Sat, 07 May 2011 15:30:38 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[conference]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[papers]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[slides]]></category>
		<category><![CDATA[talk]]></category>
		<category><![CDATA[trick]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1687</guid>
		<description><![CDATA[Hi all from Prague, I had the pleasure to be a speaker at CARO2011. My talk was about Java Malware, here is a brief recap of the content: Exploring the Playground Java Strings Notions Meeting the beast: Java Malware Java Malware overview How to Analyze Tools of the trade and their limitations Hunting time: CVE [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1687</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DynTrace: Playing with DBI and Malware</title>
		<link>http://www.inreverse.net/?p=1668</link>
		<comments>http://www.inreverse.net/?p=1668#comments</comments>
		<pubDate>Mon, 21 Mar 2011 22:32:06 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[DBI]]></category>
		<category><![CDATA[IDA Pro]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1668</guid>
		<description><![CDATA[It happens sometimes that I have to analyze a piece of malware which is really annoying: fake calls, fake APIs and lots of opaque constructs and following the code on IDA it&#8217;s a pain, so I wanted a quick way to extract some info to ease my job. My solution was to do some tracing [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1668</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java Midi Malware</title>
		<link>http://www.inreverse.net/?p=1610</link>
		<comments>http://www.inreverse.net/?p=1610#comments</comments>
		<pubDate>Sat, 12 Feb 2011 23:21:24 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1610</guid>
		<description><![CDATA[Hello all, today I am going to detail a new family of Java Malware, which exploits a (known) vulnerability in the JVM. This is probably the first time we found this vulnerability publically exploited by malware. I want to thank Tom and Mila for providing me the sample that I am going to analyze. Let&#8217;s [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1610</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>JaZeus: when Zeus meets Java</title>
		<link>http://www.inreverse.net/?p=1551</link>
		<comments>http://www.inreverse.net/?p=1551#comments</comments>
		<pubDate>Wed, 03 Nov 2010 18:57:49 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[botnet]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1551</guid>
		<description><![CDATA[Hello, This is the first analysis as far as I know, of a Zeus malware that uses a Java engine to infect a victim system, by using a multi-stage approach. The sample is md5: 92869c9f958b5bfddefc09d6bfc03591. Are you curious to know more about? If so, please follow me. Part 1 : The main EXE If you [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1551</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Again rootkit packers</title>
		<link>http://www.inreverse.net/?p=1456</link>
		<comments>http://www.inreverse.net/?p=1456#comments</comments>
		<pubDate>Thu, 21 Oct 2010 09:25:03 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[kernel]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rootkit]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1456</guid>
		<description><![CDATA[Today I will go through two of the last rootkit packers I analyzed recently. The first is a TDL3 rootkit (654f4a3d02f7cc4b0442a5fee44419d948fa0048) 1/40 on VT (as of 12 Oct) which is consistent with the recent timestamp. From a first analysis it shows some weird characteristics: 1. contains multiple resources (which is weird for drivers, if you [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1456</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Malware Reflection</title>
		<link>http://www.inreverse.net/?p=1472</link>
		<comments>http://www.inreverse.net/?p=1472#comments</comments>
		<pubDate>Tue, 19 Oct 2010 17:37:27 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1472</guid>
		<description><![CDATA[Thanks to Sean McLinden and Mila, I have the sample (md5: f79cdd1a958ffe430fff8362642dafb6) that I am going to analyze. In this analysis I will focus on a trick that the Java malware is using to avoid detections. The malware contains a &#8220;reflective-class&#8220;, which is interesting since it uses reflection to provide additional &#8220;protection&#8221; to the real [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1472</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java Class-name Evasion Trick</title>
		<link>http://www.inreverse.net/?p=1430</link>
		<comments>http://www.inreverse.net/?p=1430#comments</comments>
		<pubDate>Thu, 30 Sep 2010 20:14:16 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[antidebug]]></category>
		<category><![CDATA[internals]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[trick]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1430</guid>
		<description><![CDATA[Today I am going to show a nice trick to prevent usual unpacking of JAR files, before presenting the trick, please let me introduce some terms that we are going to use: JAR file, Manifest and Constant Pool. JAR file. From Oracle SE documentation: “JAR stands for Java ARchive. It&#8217;s a file format based on [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1430</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Crimepack 3.1.3 &#8211; checking vital signs</title>
		<link>http://www.inreverse.net/?p=1401</link>
		<comments>http://www.inreverse.net/?p=1401#comments</comments>
		<pubDate>Sun, 26 Sep 2010 21:41:34 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[java]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1401</guid>
		<description><![CDATA[Today I am going to analyze the so called CrimePack 3.1.3, thanks to Mila. I will focus on the interesting parts, such as: a recent Java vulnerability (CVE-2010-0840) and a malicious PDF-generator on demand. Let’s start! Part 1: Java Exploit As stated above, I focus on a malware that exploits a recent JRE vulnerability: CVE-2010-0840 [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1401</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Sleeping beauty exploit</title>
		<link>http://www.inreverse.net/?p=1356</link>
		<comments>http://www.inreverse.net/?p=1356#comments</comments>
		<pubDate>Mon, 13 Sep 2010 18:31:10 +0000</pubDate>
		<dc:creator>Donato Ferrante ( ratsoul )</dc:creator>
				<category><![CDATA[fun]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1356</guid>
		<description><![CDATA[Hello, I am not going to show you a new exploit, but a cool and interesting way to obfuscate a known exploit in order to break detections. Today my friend Mila provided to me the following sample (md5: eeb80aa4f0575a7d595ec9d636cc1b2e) that I am going to analyze. This sample is contained in a HTML page. By taking [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&#038;p=1356</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
