Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Analyzing Suspicious Attachment |
|---|---|
| Date: | Thu, 17 Jan 2008 10:22:23 -0800 |
Silly! Send out a company newsletter stating never to open attachments from an unidentified source (if you can't walk over and smack them, don't open the file). Try the following tools to see if you may have been compromised: Hijack This, Sbybot Search & Destroy/File_Anayzer (don't forget about the tools under the advanced view), Sysinternals "Process Explorer", ADS Spy, Rootkit Revealer. Sniff your network for strange traffic. What are you using to open ZIP files??? -----Original Message----- From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On Behalf Of Al Cooper Sent: Thursday, January 17, 2008 12:18 PM To: security-basics@securityfocus.com Subject: Analyzing Suspicious Attachment We had a user open a suspicious attachment. The attachment did not open so she sent it to two of her colleges. One of her colleges was also unable to open the file, but the third person did successfully open the file. The attachment did not match the original email and IT was eventually called, a few hours later. The three computer have been removed from the network. I have the attachment. It is a zip file. Inside the zip file is one .scr file. The antivirus (Symantec) did not catch anything when the file was opened. The email is an HTML email and there are pictures that can be downloaded. Outside of the obvious policy and training issues, what is the best way to determine what if any damage has been done to the network? What tools do I need to analysis the attachment to see what it is and how it works? Thanks for your help, -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean.
| Previous by Date: | Re: Analyzing Suspicious Attachment, brian . bevers |
|---|---|
| Next by Date: | RE: Honeypot Server, Timmothy Lester |
| Previous by Thread: | RE: Analyzing Suspicious Attachment, Nick Vaernhoej |
| Next by Thread: | RE: Analyzing Suspicious Attachment, Richard Golodner |
| Indexes: | [Date] [Thread] [Top] [All Lists] |