Full Disclosure mailing list archives

Re: Using Magic Values along with filetype to find malicious files (was RE: Google Malware Search)


From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Mon, 17 Jul 2006 17:27:30 -0400

On 7/17/06, Debasis Mohanty <debasis.mohanty.listmails () gmail com> wrote:
Nice .. Realy nice pointers H.D. !! :)


Really nice pointers yourself!

By searching for:

site:.il signature: 00004550 filetype:pif

I find a site with badtrans.b

www.arava.co.il/matan/svgalib/hypermail/att-1469/01-fun.MP3.pif

Hmm, any bets on who is the most infected TLD...  :-)

-JP<who is betting on .ru>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: