Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Malware Search Through Google

    Last week, news has it that Google can help you search for EXE files, specifically Win32 PE (Portable Executable) files, scattered around the Internet. This can be done though the use of the Google keyword “Signature:”.



    H.D. Moore (of Metasploit fame) has extended this PE file search capabilities into searching for Win32 malware itself.

    Apparently, Google does not only search for PE files, but also parses the PE headers itself! It is this ability of Google that Moore used for his malware seach. Google has these additional search keywords:





    • Time Date Stamp

    • Size of Image

    • Entry Point

    • Size of Code


    Using these keywords, it is possible to identify specific malware strains, as is shown to us by Moore’s malware search.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice