Main.HomePage History

Hide minor edits - Show changes to output

Changed line 4 from:
'''Mailing list: [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]]'''
to:
'''Mailing list: None'''
October 11, 2012, at 09:00 AM EST by 18.26.4.179 - no more mailing list subscription requests!
Deleted lines 15-16:

To receive further announcements get on the seminar mailing list, use Mailman to subscribe to [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
Changed line 40 from:
* 07/20:
to:
* 07/20: Exploits [[http://www.cs.utah.edu/~ccutler/Malsem-jul20.pdf | Slides]]
July 16, 2012, at 01:52 PM EST by 155.99.183.146 -
Changed lines 26-27 from:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]] [[http://www.cs.utah.edu/~ccutler/crackme_2.exe | Obfuscated Crackme]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.odp |.odp]]).
to:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]]. [[http://www.cs.utah.edu/~ccutler/crackme_2.exe | Obfuscated Crackme]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.odp |.odp]]).
Changed lines 30-31 from:
* 06/15: Automatic unpacking. [[UnpackingNotes | Notes]]
to:
* 06/15: Automatic unpacking. [[UnpackingNotes | Notes]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/03-auto-unpacking.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/03-auto-unpacking.odp |.odp]]).
Changed lines 36-38 from:
* 07/06: Modern malware: Stuxnet, Duqu, Flame [[ModernMalware | Notes]]

* 07
/13: More examples: PDF malware, and rootkits [[PDFAndRootkits | Notes]]
to:
* 07/06: Modern malware: Stuxnet, Duqu, Flame [[ModernMalware | Notes]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/04-modern-malware.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/04-modern-malware.odp |.odp]]).

* 07/13: More examples: PDF malware, and rootkits [[PDFAndRootkits | Notes]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/05-more-examples.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/05-more-examples.odp |.odp]]).
Changed lines 34-38 from:
* 06/29:

*
07/06:

* 07/13
:
to:
* 06/29: No seminar

*
07/06: Modern malware: Stuxnet, Duqu, Flame [[ModernMalware | Notes]]

* 07/13: More examples: PDF malware, and rootkits [[PDFAndRootkits | Notes]]
June 22, 2012, at 11:48 AM EST by 155.98.60.157 -
Changed line 32 from:
* 06/22:
to:
* 06/22: Basic dynamic analysis [[dynanal | Notes]]
June 14, 2012, at 12:31 PM EST by 155.99.180.73 -
Changed line 30 from:
* 06/15:
to:
* 06/15: Automatic unpacking. [[UnpackingNotes | Notes]]
June 08, 2012, at 02:38 PM EST by 155.98.60.157 -
Changed line 28 from:
* 06/08: Malware Sample 1 (gamarue.I)
to:
* 06/08: Malware Sample 1 (gamarue.I) [[http://www.cs.utah.edu/~ccutler/ida-dumps.tgz | IDA dumps]]
June 05, 2012, at 03:48 PM EST by 155.98.60.157 -
Changed line 28 from:
* 06/08:
to:
* 06/08: Malware Sample 1 (gamarue.I)
June 01, 2012, at 03:56 PM EST by 155.99.162.205 -
Changed lines 26-27 from:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]] [[http://www.cs.utah.edu/~ccutler/crackme_2.exe | Obfuscated Crackme]]
[[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.odp |.odp]]).
to:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]] [[http://www.cs.utah.edu/~ccutler/crackme_2.exe | Obfuscated Crackme]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.odp |.odp]]).
June 01, 2012, at 03:55 PM EST by 155.99.162.205 -
Added line 27:
[[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/02-anti-debugging.odp |.odp]]).
June 01, 2012, at 02:46 PM EST by 155.98.60.157 -
Changed line 26 from:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]].
to:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]] [[http://www.cs.utah.edu/~ccutler/crackme_2.exe | Obfuscated Crackme]]
June 01, 2012, at 10:55 AM EST by 155.99.162.205 -
Changed line 26 from:
* 06/01:
to:
* 06/01: Anti-debugging techniques. [[AntiDebugNotes | Notes]].
Changed line 24 from:
* 05/25:
to:
* 05/25: [[Tools]]
Changed lines 22-24 from:
* 05/18: Recap of the ASM language

[[ASMNotes | Notes]]. [[ASMExamples | Examples]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | Slides]](LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]]).
to:
* 05/18: Recap of the ASM language. [[ASMNotes | Notes]]. [[ASMExamples | Examples]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | Slides]] (LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]]).
Changed line 24 from:
[[ASMNotes | Notes]]. [[ASMExamples | Examples]]. [[[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | Slides .pdf]], [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]] (LibreOffice)].
to:
[[ASMNotes | Notes]]. [[ASMExamples | Examples]]. [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | Slides]](LibreOffice [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]]).
Changed line 24 from:
[[ASMNotes | Notes]] [[ASMExamples | Examples]] Slides ([[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | .pdf]], [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]] (LibreOffice))
to:
[[ASMNotes | Notes]]. [[ASMExamples | Examples]]. [[[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | Slides .pdf]], [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]] (LibreOffice)].
Changed lines 22-24 from:
* 05/18: Recap of the ASM language [[ASMExamples | Examples]]
to:
* 05/18: Recap of the ASM language

[[ASMNotes | Notes]] [[ASMExamples | Examples]] Slides ([[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.pdf | .pdf]], [[http://www.cs.utah.edu/~aburtsev/malw-sem/slides/01-asm.odp |.odp]] (LibreOffice))
Changed line 22 from:
* 05/18: Recap of the ASM language
to:
* 05/18: Recap of the ASM language [[ASMExamples | Examples]]
Changed line 15 from:
The seminar will be structured as a series of presentations, and in-class analysis sessions. We'll prepare Emulab images for you to do exersizes, and try your own experiments.
to:
The seminar will be structured as a series of presentations, and in-class analysis sessions. We'll prepare Emulab images for you to do exercises, and try your own experiments.
Changed line 6 from:
This seminar is an introduction to practical aspects of malware analysis. Our draft plan is to cover the following topics with the emphasis on gaining practical analysis skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
to:
This seminar is an introduction to practical aspects of malware analysis. Our plan is to cover the following topics with the emphasis on gaining practical analysis skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
Changed line 22 from:
* 05/18: ASM language
to:
* 05/18: Recap of the ASM language
Changed line 22 from:
* 05/18:
to:
* 05/18: ASM language
Changed line 6 from:
This seminar is aimed as an introduction to practical aspects of malware analysis. Our rough plan is to cover the following topics with the emphasis on gaining practical analysis skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
to:
This seminar is an introduction to practical aspects of malware analysis. Our draft plan is to cover the following topics with the emphasis on gaining practical analysis skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
Changed lines 6-7 from:
This seminar is aimed to study practical aspects of malware analysis. Our rough plan is to cover the following topics with the emphasis on gaining practical reverse engineering skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
to:
This seminar is aimed as an introduction to practical aspects of malware analysis. Our rough plan is to cover the following topics with the emphasis on gaining practical analysis skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
Added lines 14-15:

The seminar will be structured as a series of presentations, and in-class analysis sessions. We'll prepare Emulab images for you to do exersizes, and try your own experiments.
Changed lines 6-8 from:

The
seminar will cover practical approaches to malware analysis techniques:
to:
This seminar is aimed to study practical aspects of malware analysis. Our rough plan is to cover the following topics with the emphasis on gaining practical reverse engineering skills, in-depth understanding of malware implementation techniques, and experience with static and dynamic analysis tools:
Changed line 10 from:
* anti-debugging techniques
to:
* common anti-debugging techniques
Changed line 13 from:
* discussion of classic and advanced exploit techniques
to:
* low-level mechanics of classic and advanced exploit techniques
May 13, 2012, at 12:04 AM EST by 155.97.237.229 -
Changed line 16 from:
To receive announcements get on the seminar mailing list, use Mailman to subscribe to [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
to:
To receive further announcements get on the seminar mailing list, use Mailman to subscribe to [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
May 13, 2012, at 12:04 AM EST by 155.97.237.229 -
Changed lines 3-6 from:
'''Time and place:''' Fridays, 1:00pm, Flux Conference Room (3485 MEB)\\
'''Mailing list:''' [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
to:
'''Time and place: Fridays, 1:00pm, Flux Conference Room (3485 MEB)'''\\
'''
Mailing list: [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]]'''
Changed line 16 from:
To get on the class mailing list, use Mailman to subscribe to [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
to:
To receive announcements get on the seminar mailing list, use Mailman to subscribe to [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
May 13, 2012, at 12:02 AM EST by 155.97.237.229 -
Changed lines 3-4 from:
'''Time and place:''' Fridays, 1:00pm, Flux Conference Room (3485 MEB)
\\'''Mailing list:''' [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
to:
'''Time and place:''' Fridays, 1:00pm, Flux Conference Room (3485 MEB)\\
'''Mailing list:''' [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
May 13, 2012, at 12:02 AM EST by 155.97.237.229 -
Changed lines 4-5 from:
'''Mailing list:''' [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
to:
\\'''Mailing list:''' [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
May 13, 2012, at 12:01 AM EST by 155.97.237.229 -
Added line 2:
Added line 4:
May 13, 2012, at 12:00 AM EST by 155.97.237.229 -
Changed lines 2-3 from:
!Time and place: Fridays, 1:00pm, Flux Conference Room (3485 MEB)
!Mailing list: [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
to:
'''Time and place:''' Fridays, 1:00pm, Flux Conference Room (3485 MEB)
'''Mailing list:''' [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
May 12, 2012, at 11:59 PM EST by 155.97.237.229 -
Changed lines 3-5 from:
!Overview
to:
!Mailing list: [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
Deleted lines 14-15:
!Mailing list
Added line 17:
Changed line 46 from:
* 08/17:
to:
* 08/17:
May 12, 2012, at 11:57 PM EST by 155.97.237.229 -
Added lines 3-4:

!Overview
May 12, 2012, at 11:57 PM EST by 155.97.237.229 -
Added lines 12-15:

!Mailing list

To get on the class mailing list, use Mailman to subscribe to [[http://mailman.cs.utah.edu/mailman/listinfo/malw-sem | malw-sem]].
May 12, 2012, at 11:54 PM EST by 155.97.237.229 -
Added line 2:
!Time and place: Fridays, 1:00pm, Flux Conference Room (3485 MEB)
May 12, 2012, at 11:52 PM EST by 155.97.237.229 -
Changed lines 4-5 from:
* bdcscasics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
to:
* basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
Changed lines 18-40 from:
* 06/01:
to:
* 06/01:

* 06/08:

* 06/15:

* 06/22:

* 06/29:

* 07/06:

* 07/13:

* 07/20:

* 07/27:

* 08/03:

* 08/10:

* 08/17:
May 12, 2012, at 11:49 PM EST by 155.97.237.229 -
Changed line 4 from:
* basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
to:
* bdcscasics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
May 12, 2012, at 11:49 PM EST by 155.97.237.229 -
May 12, 2012, at 11:48 PM EST by 155.97.237.229 -
Changed lines 11-17 from:
!Schedule
to:
!Schedule

* 05/18:

* 05/25:

* 06/01:
May 12, 2012, at 11:46 PM EST by 155.97.237.229 -
Changed lines 3-4 from:
The seminar will cover practical approaches to malware analysis
techniques:
* basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
to:
The seminar will cover practical approaches to malware analysis techniques:
* basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
May 12, 2012, at 11:46 PM EST by 155.97.237.229 -
Changed lines 4-10 from:
techniques:
* basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
* tools: IDA, OllyDBG
* anti-debugging techniques
* packers and approaches to unpacking
* in-class reverse engineering sessions
* discussion of classic and advanced exploit techniques
to:
techniques: * basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
* tools: IDA, OllyDBG
* anti-debugging techniques
* packers and approaches to unpacking
* in-class reverse engineering sessions
*
discussion of classic and advanced exploit techniques
May 12, 2012, at 11:45 PM EST by 155.97.237.229 -
Changed lines 5-17 from:

- basics: asm language, calling conventions, relevant low-level parts
of CPU, and OS interface

- tools: IDA, OllyDBG

- anti-debugging techniques

- packers and approaches to unpacking

- in-class reverse engineering sessions

- discussion of classic and advanced exploit techniques
to:
* basics: asm language, calling conventions, relevant low-level parts of CPU, and OS interface
* tools: IDA, OllyDBG
* anti-debugging techniques
* packers and approaches to unpacking
* in-class reverse engineering sessions
* discussion of classic and advanced exploit techniques
May 12, 2012, at 11:34 PM EST by 155.97.237.229 -
Changed lines 3-17 from:
to:
The seminar will cover practical approaches to malware analysis
techniques:

- basics: asm language, calling conventions, relevant low-level parts
of CPU, and OS interface

- tools: IDA, OllyDBG

- anti-debugging techniques

- packers and approaches to unpacking

- in-class reverse engineering sessions

- discussion of classic and advanced exploit techniques
May 12, 2012, at 11:26 PM EST by 155.97.237.229 -
Changed lines 1-3 from:
!%center% Organizers: Cody Cutler, Anton Burtsev
to:
!Organizers: [[http://www.cs.utah.edu/~ccutler | Cody Cutler]], [[http://www.cs.utah.edu/~aburtsev | Anton Burtsev]]
May 12, 2012, at 11:24 PM EST by 155.97.237.229 -
Changed line 1 from:
%center% !Organizers: Cody Cutler, Anton Burtsev
to:
!%center% Organizers: Cody Cutler, Anton Burtsev
May 12, 2012, at 11:23 PM EST by 155.97.237.229 -
Changed line 1 from:
%center% [++Organizers: Cody Cutler, Anton Burtsev++]
to:
%center% !Organizers: Cody Cutler, Anton Burtsev
May 12, 2012, at 11:20 PM EST by 155.97.237.229 -
Changed line 1 from:
%center% ++Organizers: Cody Cutler, Anton Burtsev++
to:
%center% [++Organizers: Cody Cutler, Anton Burtsev++]
May 12, 2012, at 11:20 PM EST by 155.97.237.229 -
Changed line 1 from:
%center%++Organizers: Cody Cutler, Anton Burtsev++
to:
%center% ++Organizers: Cody Cutler, Anton Burtsev++
May 12, 2012, at 11:19 PM EST by 155.97.237.229 -
Added lines 1-3:
%center%++Organizers: Cody Cutler, Anton Burtsev++

!Schedule
May 12, 2012, at 11:01 PM EST by 155.97.237.229 -
Deleted lines 0-11:
Welcome to PmWiki!

A local copy of PmWiki's
documentation has been installed along with the software,
and is available via the [[PmWiki/documentation index]].

To continue setting up PmWiki, see [[PmWiki/initial setup tasks]].

The [[PmWiki/basic editing]] page describes how to create pages
in PmWiki. You can practice editing in the [[wiki sandbox]].

More information about PmWiki is available from http://www.pmwiki.org.