<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>CERT.at Downloads</title>
  <link rel="alternate" href="http://www.cert.at" />
  <subtitle>All CERT.at downloads as a feed</subtitle>
  <entry>
    <title>(Summary) - Downloads</title>
    <link rel="alternate" href="http://www.cert.at/downloads/summary/summary_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-09-24T10:13:22Z</updated>
    <published>2009-09-24T10:13:22Z</published>
    <summary type="html">&lt;h1&gt;Downloads&lt;/h1&gt;
In this area of our homepage we offer you material for free download. Please read the related licence agreements.
&lt;p /&gt;
Downloads which are only available in German language will be shortly mentioned in the English area as well, but the full description and the download-link itself will only be found in the German area.
&lt;p /&gt;
These are the available categories for downloads:
&lt;h2&gt;Data&lt;/h2&gt;
Here you'll find files that contain information for the purpose of being read by machines (i.e.: configuration files).
&lt;h2&gt;Papers&lt;/h2&gt;
This area contains all papers that have been published by CERT.at so far.
&lt;h2&gt;Press&lt;/h2&gt;
This is the place for all material that are of typical use for the public press (i.e.: CERT.at's logo).
&lt;h2&gt;Software&lt;/h2&gt;
"Open" software with its root in CERT.at's daily work will be found here, including descriptions.
&lt;!--h2&gt;Grouped by topic&lt;/h2&gt;
This special area bundles all the downloads being spread over the categories that are sharing the same topic as a list of links. The corresponding descriptions, though, will still be found under the detail-categories.--&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-09-24T10:13:22Z</dc:date>
  </entry>
  <entry>
    <title>(Papers) - An Analysis of the Skype IMBot Logic and Functionality</title>
    <link rel="alternate" href="http://www.cert.at/downloads/papers/skype_imbot_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2010-03-08T13:12:20Z</updated>
    <published>2010-03-08T13:12:20Z</published>
    <summary type="html">&lt;h1&gt;An Analysis of the Skype IMBot Logic and Functionality&lt;/h1&gt;
2010/03/08
&lt;p /&gt;
An Analysis of the Skype IMBot Logic and Functionality. 
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-an_analysis_of_the_skype_imbot_logic_and_functionality_1.2.pdf"&gt;Download&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
March, 08th 2010

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner, L. Aaron Kaplan

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;History&lt;/h2&gt;
You can download the full document in pdf format
&lt;a href="http://www.cert.at/static/downloads/papers/cert.at-an_analysis_of_the_skype_imbot_logic_and_functionality_1.2.pdf"&gt;here&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
The following report analyzes the Skype Instant Messenger Bot ("Skype IMBot", a variation of the W32.Nytemare trojan) and reports our reverse engineering efforts. One peculiar aspect of Skype IMBot was the way it controlled Skype (and other Instant Messengers) - simulating user input and user keystrokes. This reminded us of a limited Turing Test: did the malware or a true user send the URL? 

The report covers the reverse engineering of the Skype IMbot, network logic and recommendations to CERTs, users and Skype. It closed with an outlook on further instant messenger bots.</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2010-03-08T13:12:20Z</dc:date>
  </entry>
  <entry>
    <title>(Papers) - Mass Malware Analysis: A Do-It-Yourself Kit</title>
    <link rel="alternate" href="http://www.cert.at/downloads/papers/mass_malware_analysis_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-10-14T15:29:37Z</updated>
    <published>2009-10-14T15:29:37Z</published>
    <summary type="html">&lt;h1&gt;Mass Malware Analysis: A Do-It-Yourself Kit&lt;/h1&gt;
2009/10/14
&lt;p /&gt;
Theory, practice and a construction manual for an automated analysis station for malware using trivial and free instruments.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-mass_malware_analysis_1.0.pdf"&gt;Download&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
October, 14th 2009

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;History&lt;/h2&gt;
You can download the full document in pdf format
&lt;a href="http://www.cert.at/static/downloads/papers/cert.at-mass_malware_analysis_1.0.pdf"&gt;here&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
This paper outlines the relevant steps to build up a customizable automated malware analysis station 
by using only freely available components with the exception of the target OS (Windows XP) itself. 
Further a special focus lies in handling a huge amount of malware samples and the actual implementation 
at CERT.at. As primary goal the reader of this paper should be able to build up her own specific 
installation and configuration while being free in her decision which components to use.
&lt;p /&gt;
The first part of this document will cover all the theoretical, strategic and methodological aspects. 
The second part is focusing on the practical aspects by diving into CERT.at's automated malware analysis 
station closing with an easy to follow step-by-step tutorial, how to build up CERT.at's implementation 
for your own use. So feel free to skip parts.</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-10-14T15:29:37Z</dc:date>
  </entry>
  <entry>
    <title>(Papers) - Detecting Conficker in your Network</title>
    <link rel="alternate" href="http://www.cert.at/downloads/papers/confickerdetection_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-09-17T13:18:01Z</updated>
    <published>2009-09-17T13:18:01Z</published>
    <summary type="html">&lt;h1&gt;Detecting Conficker in your Network&lt;/h1&gt;
2009/02/11
&lt;p /&gt;
Description of a method to detect earlystate Conficker worm infections through blocklists
fitting the needs of small and medium enterprises.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/TR_Conficker_Detection.pdf"&gt;Download&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
2009/02/11

&lt;h2&gt;Author&lt;/h2&gt;
Adi Kriegisch

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;Download&lt;/h2&gt;
You can download the full document in pdf format &lt;a href="http://www.cert.at/static/downloads/papers/TR_Conficker_Detection.pdf"&gt;here&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
Conficker is a computer worm spreading on Windows operating system by mainly
using a buffer overflow or the Windows Autorun feature. The worm itself does not contain
malware functions but contains a routine to load such code after infection. The purpose of
this article is to sketch a way to detect such a worm in a small to medium business network
as early as possible so that the effects of the worm can be minimized.</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-09-17T13:18:01Z</dc:date>
  </entry>
  <entry>
    <title>(Papers) - Patching Nameservers: Austria reacts to VU#800113</title>
    <link rel="alternate" href="http://www.cert.at/downloads/papers/0802_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-09-24T10:04:43Z</updated>
    <published>2009-09-24T10:04:43Z</published>
    <summary type="html">&lt;h1&gt;Patching Nameservers: Austria reacts to VU#800113&lt;/h1&gt;
2008/07/24
&lt;p /&gt;
A report on the patch-rate of Austrian nameservers 
following announcement of the DNS cache poisoning vulnerabilty.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-0802-DNS-patchanalysis.pdf"&gt;Download Original&lt;/a&gt;
	&lt;p /&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-0802bis-DNS-patchanalysis-update.pdf"&gt;Download Update&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
July, 24th 2008

&lt;h2&gt;Authors&lt;/h2&gt;
Otmar Lendl and L. Aaron Kaplan

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;History&lt;/h2&gt;
You can download the full document in pdf format
&lt;a href="http://www.cert.at/static/downloads/papers/cert.at-0802-DNS-patchanalysis.pdf"&gt;here&lt;/a&gt;.
&lt;p&gt;
We also published a &lt;a href="http://www.cert.at/static/downloads/papers/cert.at-0802bis-DNS-patchanalysis-update.pdf"&gt;short update&lt;/a&gt; on July 28th.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
This paper analyses the impact of the coordinated efforts to patch Austria's recursive DNS server 
infrastructure following the revealings of Dan Kaminsky (US-CERT VU#800113) which showed 
that almost all DNS servers on the Internet are vulnerable to DNS cache poisoning.  CERT.at -- 
being run by nic.at, the Austrian domain registry -- is in a special position to be able to assess the 
reaction of the Austrian nameserver operators to the discovered DNS vulnerability. We analyzed the 
rate at which DNS servers were patched from an insecure to more secure state. The paper discusses 
a methodology to measure the patch level "score" of a recursive DNS server. We believe that this 
score methodology can be applied to cleanly discern patched from unpatched DNS servers.
&lt;p /&gt;
We describe a methodology how a TLD operator can use his query logs to check which operators 
have patched their DNS resolvers according to the published advisories. 
&lt;p /&gt;
The conclusions are rather grim so far -- more than two thirds of the Austrian Internet's recursive 
DNS servers are unpatched while at the same time the upgrade adoption rate seems rather slow. 
Our findings are matched by the observations of Alexander Klink of Cynops GmbH who analyzed 
the results of the online vulnerability test on Dan Kaminsky's doxpara site. 
&lt;p /&gt;
We hereby present the information to the concerned public in the  hope that DNS -- a central and 
crucial part of the Internet -- remains secure.
&lt;p /&gt;
Our recommendation to IT system administrators is to update their recursive DNS servers 
immediately and check that their upgrades were successful.
&lt;p /&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-09-24T10:04:43Z</dc:date>
  </entry>
  <entry>
    <title>(Software) - Bytehist</title>
    <link rel="alternate" href="http://www.cert.at/downloads/software/bytehist_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-10-12T10:22:43Z</updated>
    <published>2009-10-12T10:22:43Z</published>
    <summary type="html">&lt;h1&gt;Bytehist&lt;/h1&gt;
A tool for generating byte-usage-histograms for all types of files with a special focus on binary executables in  PE-format (Windows).
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/windows/bytehist_beta_1.zip"&gt;Download latest Windows version&lt;/a&gt;
	&lt;p /&gt;
	&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/linux/bytehist_beta_1.zip"&gt;Download latest Linux version&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;License&lt;/h2&gt;
&lt;a href="http://en.wikipedia.org/wiki/ISC_license"&gt;ISCL&lt;/a&gt;

&lt;table cellpadding=0 cellspacing=0&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;h2&gt;Releases&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;width:100%;"&gt;&lt;h2&gt;Changes&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;img src="http://www.cert.at/static/icons/icon_windows_small.gif" /&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;img src="http://www.cert.at/static/icons/icon_linux_small.gif" /&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;img src="http://www.cert.at/static/icons/icon_apple_small.gif" /&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;1.0 beta 1&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;-&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/windows/bytehist_beta_1.zip"&gt;&amp;nbsp;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/linux/bytehist_beta_1.zip"&gt;&amp;nbsp;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;x&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;

&lt;hr /&gt;

&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
	&lt;li&gt;Makes byte-usage-histograms of any file of any size&lt;/li&gt;
	&lt;li&gt;Histograms are generated as sorted and unsorted diagrams&lt;/li&gt;
	&lt;li&gt;Sub-histograms for each section of binary executables (PE)&lt;/li&gt;
	&lt;li&gt;Quick overview with GUI navigation in case of sub-histograms&lt;/li&gt;
	&lt;li&gt;Percentage for the share in the total filesize for sub-histograms&lt;/li&gt;
	&lt;li&gt;Sourcerelated names for sub-histograms (= section-names in case of PEs)&lt;/li&gt;
	&lt;li&gt;Results can be saved as .jpg, .bmp and .png files&lt;/li&gt;
	&lt;li&gt;Works as GUI and also as commandline tool (for scripting purposes)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Syntax&lt;/h2&gt;
&lt;tt&gt;bytehist [&lt;i&gt;options&lt;/i&gt; &lt;i&gt;file&lt;/i&gt;]&lt;/tt&gt;
&lt;p /&gt;
Executing &lt;i&gt;bytehist&lt;/i&gt; without any parameters activates full GUI-mode.&lt;p /&gt;
&lt;table style="margin-left:-3px"&gt;
	&lt;tr&gt;&lt;td&gt;&lt;i&gt;options&lt;/i&gt;: &lt;/td&gt;&lt;td&gt;-nogui&lt;/td&gt;&lt;td&gt;... don't bring up any GUI&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;
	&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;-save file&lt;/td&gt;&lt;td&gt;... save histogram to given file (bmp, png or jpg)&lt;/td&gt;&lt;/tr&gt;
	&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;-h&lt;/td&gt;&lt;td&gt;... show a short help&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;

&lt;h2&gt;Description&lt;/h2&gt;
Statistics can be a very good method if you want to detect encrypted or packed data. Data that has been manipulated in such a way usually comes up with a very even distribution of bytes being used. In contrast &lt;i&gt;normal&lt;/i&gt; data typically has some bytes that are used constantly, which is caused by any kind of structures. So the byte-distribution of unencrypted and unpacked clear text, database-files, ... and even executable binaries differ massevily from the encrypted and/or packed ones. By putting this "phenomenon" into a picture this difference can be easily visualized by histograms.
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;Examples:&lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_file.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_file.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_packed_archive.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_packed_archive.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
The first example shows an unpacked file. In fact the source of this histogram was a log-file - so that's human readable information.&lt;br&gt;
The second example roots in an usual ZIP-archive.&lt;br&gt;
So as formerly said, to see the difference between them is an easy one.
&lt;p /&gt;
Let's take a closer look at these examples. Both of them have a green and a red section. In the green section every pixel-column complies to it's positional matching bytecode and visualizes the number of occurrences in a vertical bar. In other words, a tall green bar on the most left side tells us that the byte-code 0h had lots of occurrences. And on the most right side you'll find byte-code FFh.&lt;br&gt;
The red section has the same roots like the green section but this time we got all the possible byte-codes in a descending order regarding their occurrences. This makes it much easier to see the evenness.&lt;br&gt;
Besides that two sections you'll also find the filename being shown on the top right corner and a percentage.&lt;br&gt;
&lt;br&gt;
To get an understanding for what this percentage is trying to tell, let's take a look at what more &lt;i&gt;bytehist&lt;/i&gt; can do for us. &lt;i&gt;bytehist&lt;/i&gt; can split up histograms in sub-histograms. At the moment the most senseful situation of providing sub-histograms is when you have to deal with binary executables. Binary executables are usually internally split up in a number of sections. There are sections for containing data, code, and so on. It is a common approach that executables are being packed or/and even encrypted before they get publicly rolled out. Especially in the malware-sector encryption and packing is massively used as a kind of hurdle to hinder deep analysis through reversing (i.e.). So, in the case of a binary executable in PE format - that's the one Microsoft Windows uses - &lt;i&gt;bytehist&lt;/i&gt; will come up with an overall-histogram as well as providing one histogram per section it found and even one for possible rest behind the last section. Regarding the percentage the overall-histogram will still say "100%" but all the others will tell the percentage of their specific share in the total filesize.
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;Examples:&lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_executable.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_executable.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_packed_executable.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_packed_executable.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
Both of the examples have a scrollarea on the right side showing thumbs of the relating (sub-)histogram. By clicking them with the left mouse-button they can be zoomed. Once again we have firstly an unpacked and secondly a packed file, but this time, binary executables.
&lt;p /&gt;
This feature gives a reverser the possibility to instantly find out the section that's containing (if so) packed/encrypted data.
&lt;p /&gt;
Full examples ...
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;Packed data behind sections:&lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec01.CODE.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec01.CODE.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec02.DATA.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec02.DATA.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec03.BSS.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec03.BSS.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec04..idata.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec04..idata.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec05..tls.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec05..tls.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec06..rdata.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec06..rdata.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec07..reloc.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec07..reloc.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec08..rsrc.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec08..rsrc.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.Rest.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.Rest.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;An UPX packed executable: &lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.sec01.UPX0.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.sec01.UPX0.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.sec02.UPX1.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.sec02.UPX1.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.sec03..rsrc.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.sec03..rsrc.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;&lt;i&gt;bytehist&lt;/i&gt; itself - unpacked: &lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec01..code.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec01..code.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec02..text.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec02..text.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec03..rdata.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec03..rdata.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec04..data.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec04..data.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec05..rsrc.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec05..rsrc.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-10-12T10:22:43Z</dc:date>
  </entry>
  <entry>
    <title>(Software) - Minibis</title>
    <link rel="alternate" href="http://www.cert.at/downloads/software/minibis_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2010-08-17T21:02:30Z</updated>
    <published>2010-08-17T21:02:30Z</published>
    <summary type="html">&lt;h1&gt;Minibis&lt;/h1&gt;
Software and tips to easily build up an automated malware analysis station based on a concept introduced in the paper
&lt;a href="../papers/mass_malware_analysis_en.html"&gt;"Mass Malware Analysis: A Do-It-Yourself Kit"&lt;/a&gt;.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_29_29.zip"&gt;Download latest version&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;License&lt;/h2&gt;
&lt;a href="http://en.wikipedia.org/wiki/ISC_license"&gt;ISCL&lt;/a&gt;

&lt;table cellpadding=0 cellspacing=0&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;h2&gt;Releases&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;width:100%;"&gt;&lt;h2&gt;Changes&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;h2&gt;Download&lt;/h2&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 (29/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;Release 2.0&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_29_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 beta (28/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;Forceable quit / Recovers from crashes&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_beta_28_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 beta (27/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;Check Internet connectivity / Exit only if analysis paused&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_beta_27_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 beta (25/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;-&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_beta_25_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;

&lt;hr /&gt;

&lt;h2&gt;Stay Informed!&lt;/h2&gt;
If you are interested in the actual state and the progress of upcoming features you might want to take a look at Minibis'
Twitter channel: &lt;a href="https://twitter.com/CERTat_Minibis"&gt;https://twitter.com/CERTat_Minibis&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Table of Contents&lt;/h2&gt;
&lt;ul&gt;
	&lt;li&gt;&lt;a href="#background"&gt;Background&lt;/a&gt;&lt;/li&gt;
	&lt;!--li&gt;&lt;a href="#faq"&gt;FAQ - Frequently Asked Questions&lt;/a&gt;&lt;/li--&gt;
	&lt;li&gt;&lt;a href="#installation"&gt;Installation Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#configuration"&gt;Configuration Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#oneloopcycle"&gt;One Loop-Cycle&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#commontools"&gt;Scripting of Common Tools and Tasks&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#screenshots"&gt;Screenshots&lt;/a&gt;&lt;/li&gt;
	&lt;!--li&gt;&lt;a href="#future"&gt;Future&lt;/a&gt;&lt;/li--&gt;
&lt;/ul&gt;

&lt;hr /&gt;

&lt;a name="background"&gt;&lt;/a&gt;
&lt;h2&gt;Background&lt;/h2&gt;
For detailed information on the underlying concept we recommend you read our paper 
&lt;a href="../papers/mass_malware_analysis_en.html"&gt;"Mass Malware Analysis: A Do-It-Yourself Kit"&lt;/a&gt;.

&lt;!--a name="faq"&gt;&lt;/a&gt;
&lt;h2&gt;FAQ - Frequently Asked Questions&lt;/h2--&gt;

&lt;a name="installation"&gt;&lt;/a&gt;
&lt;h2&gt;Installation Guide&lt;/h2&gt;
As a Minibis installations includes commercial software it is not possible for us to provide a
complete installation-package. The following step-by-step guide will lead you through the configuration
of a typical Minibis environment.

&lt;ol&gt;
	&lt;li&gt;Select the (physical) machine you like to be the home of your Minibis environment.&lt;/li&gt;
	&lt;li&gt;Install the latest version of Ubuntu (32 bit) on it.&lt;/li&gt;
	&lt;li&gt;Install proftpd (via "apt-get install proftpd").&lt;/li&gt;
	&lt;li&gt;Install zip (via "apt-get install zip").&lt;/li&gt;
	&lt;li&gt;Create a user "minibis" and do not forget to give it a password.&lt;/li&gt;  
	&lt;li&gt;Give your own user (the one you will start "minibis-cpr" from) full permissions to the home of "minibis" and verify that you can write to it.&lt;/li&gt;
	&lt;li&gt;Download Minibis and extract it to your desired folder.&lt;/li&gt;
	&lt;li&gt;Install SUN's VirtualBox (via "apt-get install virtualbox").&lt;/li&gt;
	&lt;li&gt;Create a new virtual machine (VM) in it using Windows XP as operating-system. All default settings for the machine and the OS are fine. Decline Autoupdate features when you get asked.&lt;/li&gt;
	&lt;li&gt;Add "minibis" as entry to Windows' hosts-file resolving it to your FTP-server's IP address.&lt;/li&gt;
	&lt;li&gt;Disconnect any (virtual) volumes from the VM (this is necessary to prevent eventual popups like autoplay, new hardware found etc.).&lt;/li&gt;
	&lt;li&gt;Transfer "minibis-cpp.exe" to the VM's Windows desktop.&lt;/li&gt;
	&lt;li&gt;Download your desired monitoring-tools to Linux. (Note: Download the ones that need "real" installation - so do not just copy - directly to Windows and install them.)&lt;/li&gt;
	&lt;li&gt;Disconnect from the network, i.e. by unplugging the network cable!&lt;/li&gt;
	&lt;li&gt;Check out if you can connect to the host ftp-daemon by using the Windows ftp-client.&lt;/li&gt;
	&lt;li&gt;Execute "minibis-cpp.exe" in the VM and answer the firewall question to NOT BLOCK this application.&lt;/li&gt;
	&lt;li&gt;You will be now asked to enter a password. This is the one of the user "minibis".&lt;/li&gt;
	&lt;li&gt;Create a VM-snapshot of this state.&lt;/li&gt;
	&lt;li&gt;Close the VM, using the option to revert to the last taken snapshot.&lt;/li&gt;
	&lt;li&gt;Bring your samples into Linux's filesystem (i.e. by mounting a CD-Rom).&lt;/li&gt;
	&lt;li&gt;Set "minibis-cpr" as executable (chmod +x minibis-cpr) and execute and configure it.&lt;/li&gt;
&lt;/ol&gt;

&lt;a name="configuration"&gt;&lt;/a&gt;
&lt;h2&gt;Configuration Guide&lt;/h2&gt;
The download package includes an example configuration. To use this copy it to Minibis' folder and rename it
to "minibis.pref". Note: Do never alter this file in an editor use Minibis for that. Just click on the 
"Config"-button in the lower left corner in the main-window.

&lt;h3&gt;Buttons behind fields&lt;/h3&gt;
As usual a click on such a button brings up a tiny wizard that provides support in finding the proper value.

&lt;h3&gt;The "check"-button&lt;/h3&gt;
By clicking this button the actual configuration is going to be checked for consistency. Note that in case of
multiple errors each click will always come up with &lt;b&gt;just one&lt;/b&gt; error. So make sure to re-check if you solved
a problem.

&lt;h3&gt;Area "Samples"&lt;/h3&gt;
By using the directory- or the file-entry you can configure a run for multiple samples or just one sample.
In case of directory-mode sub-directories are included as well.

&lt;h3&gt;Area "General"&lt;/h3&gt;
"FTP-Directory" is the path where the log-files will be transferred
to. "Samplename" is the name that will be used for the sample at the
proband. Some malware reacts to specific names, so this is the place
where you can change it. Regarding "Virtual Machine" you can switch
between the actually supported solutions (currently only VirtualBox)
and choose the right virtual machine instance.

&lt;h3&gt;Area "Timeouts"&lt;/h3&gt;
These are &lt;b&gt;the&lt;/b&gt; timeouts from the underlying concept. The extra field for cpp, which holds "10" (seconds) by default
specifies some additional time to wait before quitting monitoring if the sample exited on its own. This enables
continuation of monitoring i.e. if the sample injects itself in another process before doing something evil.

&lt;h3&gt;Area "Solutions for VBox bugs"&lt;/h3&gt;
These are settings that help to prevent processes of VirtualBox from getting stuck. If you already have
other (VBox) virtual machines running you might want to uncheck those. The first checkbox addresses stopping and
the second reverting the VM.

&lt;h3&gt;Area "VM Management"&lt;/h3&gt;
Here you can specify the commands that will be used for the corresponding VM activities. The id of the VM
is addressed by the replacement token %vmid%. Besides that, any of them has a timeout for hangup-prevention.

&lt;h3&gt;Tab "Researcher Scripting"&lt;/h3&gt;
To let you customize the researcher side there are three events (therefore three editor-fields) that can be
scripted using shell-scripting (Linux). Use the replacement token %md5% to specify the actual sample.&lt;br /&gt;
&lt;br /&gt;
For further details when those events exactly happen, see "One Loop-Cycle".
&lt;br /&gt;
You'll find tutorials and examples regarding scripting under "Scripting of Common Tools and Tasks".

&lt;h3&gt;Tab "Proband Scripting"&lt;/h3&gt;
To let you customize the Proband's side there are two events (the two lower editor-fields) that can be
scripted using batch-scripting (Windows).&lt;br /&gt;
The actions scripted for these two events are tied to the two editor-fields above called "Tools to transfer"
and "Results to transfer ([...] to ZIP)". The first ("Tools...") is used to define (name) the tools (files) that will
be copied to the Proband for use in later activities. The second ("Results...") is used to define (name) the files
that will be transferred back from the Proband. 
If the filename is enclosed in square brackets "[...]" the file will get ZIPped into an
archive after it arrives on Researcher.&lt;br /&gt;
&lt;br /&gt;
For further details when those events exactly happen and how the "Tools..." and the "Results..." are handled see
"One Loop-Cycle".
&lt;br /&gt;
More Tutorials and examples regarding scripting can be found under "Scripting of Common Tools and Tasks".

&lt;a name="oneloopcycle"&gt;&lt;/a&gt;
&lt;h2&gt;One Loop-Cycle&lt;/h2&gt;
Assuming that the sample can be executed, this is a chronological list of all actions
that can (some of them are optional) happen. 
It is important to understand that in this list the two components of Minibis
- CPR and CPP - are described as what they really are: one logical entity. 
The tags &lt;i class="r"&gt;(R)&lt;/i&gt; and &lt;i class="p"&gt;(P)&lt;/i&gt; specify the 
location (&lt;i class="r"&gt;(R)&lt;/i&gt;esearcher or &lt;i class="p"&gt;(P)&lt;/i&gt;roband) of the action:&lt;br /&gt;
&lt;ol&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Copy sample to FTP-path (config) as samplename (config) with the apropriate suffix according to the
		result of Linux' "file"-command.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the actions tied to event "Actions BEFORE Proband gets started" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the command declared under "VM Management Start" (config) and wait until the triggerfile "%md5%_start.rdy"
		exists or the timeout for "VM Management Start" occurs.	In case of the latter do the steps 14, 15, 17, 19 and return
		to step 3.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Fetch the preference file "minibis.pref" via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Fetch all tools (files) according to "Tools to transfer" (config) via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Transfer back the triggerfile "%md5%_start.rdy" via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Wait until a triggerfile "%md5%_ready.rdy" exists or the timeout for "CPR" (config) occurs.&lt;br /&gt;
		Meanwhile (optionally) execute the actions tied to event "Actions WHILE Proband runs" and optionally
		repeat this every &lt;i&gt;N&lt;/i&gt; seconds (see config field "every").&lt;br /&gt;
		If the timeout occurred then continue with step 14.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Execute the actions tied to event "Actions BEFORE sample gets executed" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Execute the sample and wait until it exits or the timeout for "CPP" (config) occurs. If the sample
		exited wait until the timeout for "CPP +" occurs.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Execute the actions tied to event "Actions AFTER sample exited or time's up" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Transfer back all files according to "Results to transfer ([...] to ZIP)" (config) via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Transfer back the triggerfile "%md5%_ready.rdy" via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Exit.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the command declared under "VM Management Stop" (config) and wait until it exits or the timeout
		for "VM Management Stop" occurs.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Optionally execute "Solutions for VBox bugs" column 1 (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the actions tied to event "Actions AFTER Proband got stopped" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the command declared under "VM Management Revert" (config) and wait until it exits or the timeout
		for "VM Management Revert" occurs.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		ZIP all files surrounded with [...] according to "Results to transfer ([...] to ZIP)" (config) into the
		archive "%md5%.zip".
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Optionally execute "Solutions for VBox bugs" column 2 (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Delete "minibis.pref" and the sample from FTP-folder.
	&lt;/li&gt;
&lt;/ol&gt;

&lt;a name="commontools"&gt;&lt;/a&gt;
&lt;h2&gt;Scripting of Common Tools and Tasks&lt;/h2&gt;
This section gives you example configurations for the integration of widely used monitoring tools into Minibis.

&lt;h3&gt;Sysinternals Process Monitor&lt;/h3&gt;
You can download the latest version of Process Monitor from &lt;a href="http://download.sysinternals.com/Files/ProcessMonitor.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;
Extract the ZIP-file and copy "Procmon.exe" to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
				Procmon.exe
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
				[procmon.pml]&lt;br /&gt;
				procmon.csv
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions BEFORE sample gets executed:&lt;br /&gt;
			&lt;div class="code"&gt;
				start Procmon.exe /AcceptEula /quiet /minimized /Backingfile procmon.pml&lt;br /&gt;
				Procmon.exe /AcceptEula /WaitForIdle
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
				Procmon.exe /AcceptEula /terminate&lt;br /&gt;
				Procmon.exe /AcceptEula /saveas procmon.csv /openlog procmon.pml
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul&gt;

&lt;h3&gt;WinDump: tcpdump for Windows&lt;/h3&gt;
You can download the latest version of WinDump from &lt;a href="http://www.mirrorservice.org/sites/ftp.wiretapped.net/pub/security/packet-capture/winpcap/windump/install/bin/windump_3_9_5/WinDump.exe"&gt;here&lt;/a&gt;.&lt;br /&gt;
You also need to install WinPcap in the Proband for WinDump to work properly. You can download the latest version of WinDump from &lt;a href="http://www.winpcap.org/install/bin/WinPcap_4_1_1.exe"&gt;here&lt;/a&gt;.&lt;br /&gt;
Copy "WinDump.exe" to Minibis' FTP-folder (config).&lt;br /&gt;
Copy "sleep.exe" (a tool of the Minibis download-package) to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
				WinDump.exe
				sleep.exe
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
				[windump.pcap]&lt;br /&gt;
				windump.txt
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions BEFORE sample gets executed:&lt;br /&gt;
			&lt;div class="code"&gt;
				start WinDump.exe -i 1 -w windump.pcap -U -s 0&lt;br /&gt;
				sleep.exe 1
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
				taskkill /f /im WinDump.exe&lt;br /&gt;
				WinDump.exe -n -p -r windump.pcap &gt; windump.txt
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul&gt;

&lt;h3&gt;Creating a Screenshot&lt;/h3&gt;
Copy "screenshot.exe" (a tool of the Minibis download-package) to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
				screenshot.exe
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
				screenshot.png
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
				screenshot.exe screenshot.png
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul&gt;

&lt;!--h3&gt;Sysinternals Process Monitor&lt;/h3&gt;
You can download the latest version of Process Monitor from &lt;a href="http://download.sysinternals.com/Files/ProcessMonitor.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;
Extract the ZIP-file and copy "Procmon.exe" to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Researcher Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Actions BEFORE Proband gets started:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions WHILE Proband runs:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER Proband got stopped:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions BEFORE sample gets executed:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul--&gt;

&lt;a name="screenshots"&gt;&lt;/a&gt;
&lt;h2&gt;Screenshots&lt;/h2&gt;
&lt;a href="http://www.cert.at/static/downloads/software/minibis/MainWindow.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/minibis/MainWindow.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/minibis/ConfigResearcher.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/minibis/ConfigResearcher.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/minibis/ConfigProband.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/minibis/ConfigProband.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;

&lt;!--a name="future"&gt;&lt;/a&gt;
&lt;h2&gt;Future&lt;/h2--&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2010-08-17T21:02:30Z</dc:date>
  </entry>
  <entry>
    <title>(Data) - Conficker Worm</title>
    <link rel="alternate" href="http://www.cert.at/downloads/data/conficker_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-10-12T10:19:30Z</updated>
    <published>2009-10-12T10:19:30Z</published>
    <summary type="html">&lt;h1&gt;Conficker Worm&lt;/h1&gt;
2009/02/09
&lt;p /&gt;
Various files regarding the worm "Conficker".&lt;!--more--&gt;
&lt;p /&gt;
&lt;table style="padding-left:30px;"&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/data/conficker/all_domains.zip"&gt;all domains&lt;/a&gt;&lt;/td&gt;
		&lt;td&gt; ... suitable for block lists (in proxies etc)&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/data/conficker/named.conf.conficker.zip"&gt;DNS named.conf file&lt;/a&gt;&lt;/td&gt;
		&lt;td&gt; ... Bind named.conf file with all conficker domain names&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="db" href="http://www.cert.at/static/downloads/data/conficker/conficker.db"&gt;sample bind zone file&lt;/a&gt;&lt;/td&gt;
		&lt;td&gt; ... suitable for the named.conf file above.&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-10-12T10:19:30Z</dc:date>
  </entry>
  <entry>
    <title>(Press material) - CERT.at Logo</title>
    <link rel="alternate" href="http://www.cert.at/downloads/pressmaterial/certatlogo_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-10-12T10:17:23Z</updated>
    <published>2009-10-12T10:17:23Z</published>
    <summary type="html">&lt;h1&gt;CERT.at Logo&lt;/h1&gt;
CERT.at-logo in various formats and sizes.&lt;!--more--&gt;
&lt;p /&gt;
&lt;table style="padding-left:30px;"&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_16.png"&gt;CERT.at-logo as 16x8 PNG-file (0.5 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_32.png"&gt;CERT.at-logo as 32x17 PNG-file (1.1 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_64.png"&gt;CERT.at-logo as 64x34 PNG-file (2.7 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_100.png"&gt;CERT.at-logo as 100x53 PNG-file (4.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_128.png"&gt;CERT.at-logo as 128x67 PNG-file (5.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_150.png"&gt;CERT.at-logo as 150x79 PNG-file (6.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_200.png"&gt;CERT.at-logo as 200x105 PNG-file (8.8 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_256.png"&gt;CERT.at-logo as 256x135 PNG-file (11.4 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_320.png"&gt;CERT.at-logo as 320x168 PNG-file (14.4 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_640.png"&gt;CERT.at-logo as 640x336 PNG-file (29.3 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_800.png"&gt;CERT.at-logo as 800x420 PNG-file (37.8 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_1024.png"&gt;CERT.at-logo as 1024x538 PNG-file (49.2 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_1280.png"&gt;CERT.at-logo as 1280x673 PNG-file (63.8 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_1600.png"&gt;CERT.at-logo as 1600x841 PNG-file (82.2 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="svg" href="http://www.cert.at/static/downloads/certatlogo/cert.at_vektorisiert_inkscape.svg"&gt;CERT.at-logo as vectorized format Inkscape-SVG (17.1 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="svg" href="http://www.cert.at/static/downloads/certatlogo/cert.at_vektorisiert_plain.svg"&gt;CERT.at-logo as vektorized format Plain-SVG (14.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/certatlogo/cert.at_logos.zip"&gt;all CERT.at-logos as ZIP-archive (311.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-10-12T10:17:23Z</dc:date>
  </entry>
  <entry>
    <title>(Press material) - HiRes Teamphotos</title>
    <link rel="alternate" href="http://www.cert.at/downloads/pressmaterial/hiresteam_en.html" />
    <author>
      <name>CERT.at</name>
    </author>
    <updated>2009-10-12T10:21:10Z</updated>
    <published>2009-10-12T10:21:10Z</published>
    <summary type="html">&lt;h1&gt;HiRes Teamphotos&lt;/h1&gt;
High resolution photographs of the CERT.at teammembers.&lt;!--more--&gt;
&lt;p /&gt;
&lt;table style="padding-left:30px;"&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/AaronKaplan_hires.jpg"&gt;Leon Aaron Kaplan&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/OtmarLendl_hires.jpg"&gt;Otmar Lendl&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/RobertSchischka_hires.jpg"&gt;Robert Schischka&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/RobertWaldner_hires.jpg"&gt;Robert Waldner&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/ChristianWojner_hires.jpg"&gt;Christian Wojner&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</summary>
    <dc:creator>CERT.at</dc:creator>
    <dc:date>2009-10-12T10:21:10Z</dc:date>
  </entry>
</feed>

