Re: sophie not detecting some viruses
Bill Earle <[email protected]>
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
We have the same problem with an earlier version of sophie,
v 1.43, and Sophos 3.76NSV.
The sample file Profile-720974.html.bin:
========================================
sophie does NOT identify it as a virus:
---------------------------------------
- If a virus was identified we would have seen a line similar to:
"Scan result : './eicar.com' infected with virus 'EICAR-AV-Test'"
$ sophie -d -f ~/Profile-720974.html.bin
Initializing : Grp* options (engine >= 2.14)
Initializing : Sophos engine version 2.18
Initializing : Sophos IDE version 3.76N (detects 86253 viruses)
[...]
Sophie version : 1.43
Scanning file : '/home/bill/Profile-720974.html.bin'
[debug] Scanning file : '/home/bill/Profile-720974.html.bin'
[debug] pSAVI cleaned up and released/terminated
Cleanup : Sophos cleaned up and terminated
sweep identifies Troj/Sefex-A virus:
------------------------------------
$ sweep -f -archive ~/Profile-720974.html.bin
SWEEP virus detection utility
Version 3.76N NSV, December 2003 [Linux/Intel]
Includes detection for 86253 viruses, trojans and worms
Copyright (c) 1989,2003 Sophos Plc, www.sophos.com
System time 01:48:55 PM, System date 19 January 2004
Command line qualifiers are: -f -archive
[...]
Full Sweeping
>>> Virus 'Troj/Sefex-A' found in file
/home/bill/Profile-720974.html.bin
1 file swept in 3 seconds.
1 virus was discovered.
1 file out of 1 was infected.
Please send infected samples to Sophos for analysis.
For advice consult www.sophos.com, email [email protected]
or telephone +44 1235 559933
End of Sweep.
sophie compile time options:
----------------------------
$ sophie -c
Initializing : Grp* options (engine >= 2.14)
+-----------------------------------+-----+-----+
| Configuration parameter | Type|Value|
+-----------------------------------+-----+-----+
| GrpSuper | 9 | 0 |
| GrpArchiveUnpack | 9 | 1 |
| GrpSelfExtract | 9 | 1 |
| GrpExecutable | 9 | 1 |
| GrpInternet | 9 | 1 |
| GrpMSOffice | 9 | 1 |
| GrpMisc | 9 | 1 |
| GrpDisinfect | 9 | 0 |
| GrpClean | 9 | 2 |
| PEHandling | 3 | 1 |
| Emulation | 3 | 1 |
| PeEmulator | 3 | 1 |
| DynamicDecompression | 3 | 1 |
| Upx | 3 | 1 |
| ExecFileDisinfection | 3 | 1 |
| Ole2FileDisinfection | 3 | 1 |
| Elf | 3 | 1 |
| MachO | 3 | 1 |
| SfxArchives | 3 | 0 |
| ZipDecompression | 3 | 0 |
| ZipUseChd | 3 | 1 |
| ArjDecompression | 3 | 0 |
| RarDecompression | 3 | 0 |
| UueDecompression | 3 | 0 |
| GZipDecompression | 3 | 0 |
| CmzDecompression | 3 | 0 |
| MSCabinet | 3 | 0 |
| ISCabinet | 3 | 0 |
| ISCabinetFull | 3 | 1 |
| ITSS | 3 | 0 |
| TarDecompression | 3 | 0 |
| TnefAttachmentHandling | 3 | 0 |
| TnefEmbedHandling | 3 | 0 |
| Lha | 3 | 0 |
| MSCompress | 3 | 0 |
| ActiveMimeHandling | 3 | 1 |
| Pdf | 3 | 1 |
| HqxDecompression | 3 | 0 |
| MbinDecompression | 3 | 0 |
| AppleSingle | 3 | 0 |
| Bzip2 | 3 | 0 |
| Stuffit | 3 | 0 |
| LoopBackEnabled | 3 | 0 |
| OpenMacRf | 3 | 1 |
| PalmPilotHandling | 3 | 1 |
| Rtf | 3 | 1 |
| Html | 3 | 1 |
| OLE2Handling | 3 | 1 |
| WordB | 3 | 1 |
| VBA3Handling | 3 | 1 |
| VBA5Handling | 3 | 1 |
| DecompressVBA5 | 3 | 1 |
| Vba5p | 3 | 0 |
| ExcelFormulaHandling | 3 | 1 |
| ProjectHandling | 3 | 1 |
| ScrapObjectHandling | 3 | 1 |
| VisioFileHandling | 3 | 1 |
| OleDataMsoHandling | 3 | 1 |
| OleScriptHandling | 3 | 1 |
| OleRawHandling | 3 | 1 |
| SrpStreamHandling | 3 | 1 |
| Office2001Handling | 3 | 1 |
| Vba5Dir | 3 | 0 |
| PowerPointMacroHandling | 3 | 1 |
| PowerPointEmbeddedHandling | 3 | 1 |
| IgnoreTemplateBit | 3 | 1 |
| OF95DecryptHandling | 3 | 1 |
| DelVBA5Project | 3 | 1 |
| HelpHandling | 3 | 1 |
| Skip | 3 | 1 |
| Mime | 3 | 0 |
| Base64 | 3 | 0 |
| Vbe | 3 | 1 |
| OutlookExpress | 3 | 0 |
| VbFiltering | 3 | 0 |
| UTF16 | 3 | 1 |
| Java | 3 | 1 |
| Access | 3 | 1 |
| CleanJpeg | 3 | 1 |
| CleanBmp | 3 | 1 |
| CleanGif | 3 | 1 |
| CleanRiff | 3 | 1 |
| CleanTiff | 3 | 1 |
| CleanPng | 3 | 1 |
| Xml | 3 | 0 |
| FullMacroSweep | 3 | 0 |
| FullPdf | 3 | 0 |
| FullSweep | 3 | 0 |
| StorageReport | 3 | 0 |
| StorageReportAll | 3 | 0 |
| StorageDetOnly | 3 | 0 |
| DeleteAllMacros | 3 | 0 |
| UnixArchive | 3 | 0 |
| Rpm | 3 | 0 |
| MaxRecursionDepth | 2 | 16 |
| NamespaceSupport | 3 | 0 |
| VirusDataDir | 10 | /usr/local/sav |
| VirusDataName | 10 | vdl |
| IdeDir | 10 | /usr/local/sav |
| AllowPartialVirusData | 3 | 0 |
+-----------------------------------+-----+-----+
- Bill
William B. Earle Computing & Information Technology
University at Buffalo
Voice: 716.645.6580 301 Computing Center
Fax: 716.645.5972 Buffalo, NY 14260
On Mon, 19 Jan 2004, Markus Stumpf wrote:
> On Mon, Jan 19, 2004 at 08:01:32PM +0100, Vanja Hrustic wrote:
> > The file which you've put online - how did it "get" into unpacked shape?
> >
> > Basically, what I'm wondering is if this arrived in an email (and had
> > proper MIME headers, etc.), or it was a webpage downloaded from somewhere,
> > or ... ?
>
> Yes ist was an email. The file as put on the webserver - was part of a
> "photos.zip", an encrypted ZIP file with the password in the email:
> ------------------------------------------------------------------------
> Subject: My Photo
> Date: Sun, 18 Jan 2004 09:23:14 -0800
> From: Katie <[email protected]>
> To: <[email protected]>
>
> hi,
> just as i promised, i'm sending you my photo.
>
> ps: password is 123, so noone else would look ;)
> ------------------------------------------------------------------------
> The attachment was the "photo.zip".
> The ZIP file contained an image (JPG) and the "Profile-720974.html".
> I have put the photo.zip on
> http://www.space.net/~maex/photo.zip
> Sorry, should have done that initially.
> I was curious about the content, as it looked rather suspicious and
> used the sweep utility for a quick check and it noticed the virus.
>
> I made a "mistake" and sent the .html file only on to a colleague with a
> note. The "mistake" was that it shouldn't have passed the scanner and
> generate an error, if sent from that host.
> I was rather astonished it didn't :/
>
> > Either it is a combination of config options that simply don't match
> > (maybe something has to be turned off in Sophie config in order to detect
> > this one), or Sweep uses something I am not aware of.
>
> Thanks.
> I'll send the file to Sophos and see if I can get some additional
> information.
>
> \Maex
>
> --
> SpaceNet AG | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0
> Research & Development | D-80807 Muenchen | Fax: +49 (89) 32356-299
> "The security, stability and reliability of a computer system is reciprocally
> proportional to the amount of vacuity between the ears of the admin"
> _______________________________________________
> vtools mailing list
> [email protected]
> http://www.vanja.com/list/listinfo.cgi/vtools
>