RE: New Trojan on the block [CIA Trojan]

"Davis, Myron" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <D0CD1BF9C88ED511B6E100508BBB43BD049149BE@jnu-exchange.dec.state.ak.us>
I don't know where you generated the list, but please add clamav (the open
source virus definitions) to that list.

http://www.clamav.net/sendvirus.html

There are a lot of people using the windows (http://clamwin.net) and unix
ports of this GPL scanner.

-Myron

-----Original Message-----
From: Nick FitzGerald [mailto:[email protected]] 
Sent: Sunday, August 29, 2004 3:08 PM
To: [email protected]
Subject: Re: [Intrusions] New Trojan on the block [CIA Trojan]

<snip>

   Authentium (Command Antivirus)  <[email protected]>
   Computer Associates (US)        <[email protected]>
   Computer Associates (Vet/EZ)    <[email protected]>
   DialogueScience (Dr. Web)       <[email protected]>
   Eset (NOD32)                    <[email protected]>
   F-Secure Corp.                  <[email protected]>
   Frisk Software (F-PROT)         <[email protected]>
   Grisoft (AVG)                   <[email protected]>
   H+BEDV (AntiVir, Vexira engine) <[email protected]>
   Kaspersky Labs                  <[email protected]>
   Network Associates (McAfee)     <[email protected]>
     (use a ZIP file with the password 'infected' without the quotes)
   Norman (NVC)                    <[email protected]>
   Panda Software                  <[email protected]>
   Sophos Plc.                     <[email protected]>
   Symantec (Norton)               <[email protected]>
   Trend Micro (PC-cillin)         <[email protected]>
     (Trend may only accept files from users of its products)

Most of these addresses are monitored either by 24x365 malware support 
and analysis teams, or have distributed processing around the globe 
providing (close to) 24x365 coverage.  Several have automated code 
analysis systems that get the "first look" at submitted files, 
classifying them for further attention or simply sending back canned 
reports of the "we detect it in the DEF update that should ship at X or 
you can download a pre-QA copy at Y".  Depending on the nature of the 
files you submit, you should get several quite prompt responses, at 
some of which you'll have to ignore (e.g. a downloader detection is 
pretty meaningless as the target of a downloader is usually considered 
to be a non-code variable and ignored by any semi-intelligent detection 
of that downloader, so the same downloader can be used multiple times 
configured to snag stuff from different URLs and will always be 
detected as the same downloader and variant).


-- 
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3529854

_______________________________________________
Intrusions mailing list
[email protected] http://www.dshield.org/mailman/listinfo/intrusions
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.