- About us
- Code of Conduct
- Google SoC
- Recent posts
- Security Workshops
As part of this year’s Summer of Code, I programmed an extension for the shellcode detection and analysis library libemu. The main goal of the project was to increase the performance when executing shellcode, with the help of a virtualizer. Prior to this extension, libemu made use of a custom emulator, which supported only instructions mostly used in shellcode. With this extension, libemu utilizes a full-blown, completely functioning virtualizer, which executes code presumably the same way a real CPU does.
We've set up a demonstration site for HoneyViz (Project #3) at
As the deadline of GSOC has passed, I would like to announce the APKinspector Beta1.0. APKinspector is a tool to help Android application analysts and reverse engineers to analyze the compiled Android packages and their corresponding codes. You can review the Alpha version report and the page of this project to know more about it.
Chinese viewers may view the demo at: http://v.youku.com/v_show/id_XMjk3ODAwMzU2.html
Based on the Alpha release, APKinspector has added some features as follows:
We build up a project in google code, you can browse AxMock by the link
AxMock is a detection tool for malicious webpage attacking ActiveX controls. It runs in Internet Explorer 7 and the formal version.
It is tested in Visual Studio 2008 and Python 2.6 with pywin32 package, though I believe that you can also compile it in later version.
For more using information, please check out Wiki in my project google code page.
While the "pencil down" date is approaching, i would like to announce the latest situation at Webviz project. From the last time till time, there have been some changes at the visualization:
* The size of the visualization increased
* A better map is located as base map
* Mesh working principle is changed from country based to IP based. The returning database results are grouped by IP.
* Legends are detailed
* For a better distributed results, an IP set that is collected for a long period is also added to the database.
The latest result is as below:
The whole implementation is mainly consisted of 4 modules: central controller, emulator, dummy control and list. Central controller is a dynamic link library written in C++. Emulator and dummy control are COM components written in python and registered into registry by win32com.server.register.UseCommandLine. List is a text file in a certain format to read and modify.
Cuckoo Sandbox is a malware analysis system capable to outline the
behavior of a malware during its execution.
In order to generate such results, Cuckoo performs hooking of a number
of selected Windows functions, intercept their calls and after storing
the relevant informations and eventually performing additional actions,
returns the exection to the original code.
Until now it made use of latest Microsoft Detours Express. Part of the
work of this Google Summer of Code was to implement a custom hooking
engine to completely replace the old one.
I am pleased to announce the next forensic challenge: Forensic Challenge 9 - "Mobile Malware".
The challenge has been created by by Franck Guenichot from French Chapter, Mahmud Ab Rahman and Ahmad Azizan Idris from Malaysia Chapter and Matt Erasmus from South Africa Chapter.
Submission deadline is September 4th and we will be announcing winners around the third week of September. We have a few small prizes for the top three submissions.
The Honeynet Project
the submission deadline for the Forensic Challenge 8 – “Malware Reverse Engineering” - put up by Guido Landi and Angelo Dell'Aera from the Sysenter Chapter - has passed. We have received 6 submissions and will be announcing results on Wed, Aug 31th 2011. The top three submissions will be awarded little prizes.
For your information a new Forensic Challenge will start in a few hours. This time you will be asked to dive into the mobile malware world. Stay tuned!
The Honeynet Project
The GUI tool for static analysis of Android malware is ready for an alpha release. For more details regarding this project, check here.
In the alpha release, the following features have been finished.
(1) Show the CFG (control flow graph) for a given method
(2) Show the smali codes for a given method.
(3) Show the Java codes for a given java file.
(4) Show the betecodes for a given method.
(5) Show all strings, methods and classes.
(6) Show the APK's related information.
(7) Drag and zoom in/out the CFG.