A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #19643  by TwinHeadedEagle
 Fri Jun 14, 2013 1:59 pm
What is the simplest way to find out adress of server that downloader contacts to download more malware...

Can you point me some informations, tools or articles.

Thanks
 #19699  by dn5
 Wed Jun 19, 2013 3:12 pm
Either Wireshark as EP_X0FF posted or track UrlDownloadToFile API in OllyDbg.

Regards.

References:
//hxxp://msdn.microsoft.com/en-us/library/ms775123(v=vs.85).aspx