papers_and_news:advanced_computer_networks-polymorphic_shellcode_detection_2006_gratl.pdf
by Christoph Gratl
http://discovery.csc.ncsu.edu/pubs/ASIACCS07a.pdf
Permission to make digital or hard copies of all or part of this work for
personal or classroom use is granted without fee provided that copies are
not made or distributed for profit or commercial advantage and that copies
bear this notice and the full citation on the first page. To copy otherwise, to
republish, to post on servers or to redistribute to lists, requires prior specific
permission and/or a fee.
ASIACCS’07, March 20-22, 2007, Singapore.
Copyright 2007 ACM 1-59593-574-6/07/0003 ...$5.00
by Qinghua Zhang, Douglas S. Reeves, Peng Ning, S. Purushothaman Iyer
papers_and_news:defending_against_polymorphic_attacks-recent_results_and_open_questions_2006_terena_polychronakis.pdf by Michalis Polychronakis
papers_and_news:detecting_network-based_obfuscated_code_injection_attacks_using_sandboxing_2006_anderson.pdf
by Stig Andersson, Andrew Clark and George Mohay
papers_and_news:hybrid_engine_for_polymorphic_shellcode_detection_positif_2006_teufl.pdf by Udo Payer, Peter Teufl, Mario Lamberger
papers_and_news:network_level_polymorphic_shellcode_detection_terena_2006_polychronakis.pdf
by Michalis Polychronakis , Kostas G. Anagnostakis , and Evangelos P. Markatos
Life, Love, and War in the Underground
Rob Thomas 5 November 2003
http://www.cert.pl/PDF/secure2003/thomas1.pdf
From: Stephanie Wehner
http://homepages.cwi.nl/~wehner/worms/
From: Stephanie Wehner
http://arxiv.org/abs/cs.CR/0504045
papers_and_news:new_fields_of_application_for_honeynets.pdf Master Thesesis by Thorsten Holz
This Worm is mainly unknown, no real analysis yet, but as we receive that many samples from doxpar, here are some links to av vendors ‘analysis’ reports.
If you want a sample to write a better analysis, contact us.
The sample has the md5sum 17028f1eda9d3a3f7423f47bd2f525f6 , current nepenthes is able to catch the virus in no time.
http://securityresponse.symantec.com/avcenter/venc/data/w32.poxdar.html
http://www.sophos.com/virusinfo/analyses/w32doxpara.html
Exploiting Underlying Structure for Detailed Reconstruction of an Internet Scale Event
http://www.cc.gatech.edu/~akumar/witty.html
http://www.cc.gatech.edu/~akumar/witty-draft.pdf
INCOMPLETE
INCOMPLETE