Re: ** Re: sophie not detecting some viruses (fwd)
Bill Earle <[email protected]>
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
Vanja, I have opened a call with Sophos Support. my inital incident no: EDA-19-EMR Michele felt the need to assign yet another, incident no.: EAA-19-QPG After this inital response from support, they have forwarded the request on to the "product manager" and I'm told "... they will most likely need to be in contact with Vanja." How this is going to procede is not very well defined. I'm told the product manager will assign someone to work on the problem and I can keep hounding Sophos Support to see what shakes out from my end. Anything that you can do will be appreciated. - Bill William B. Earle Computing & Information Technology University at Buffalo Voice: 716.645.6580 301 Computing Center Fax: 716.645.5972 Buffalo, NY 14260 ---------- Forwarded message ---------- Date: Mon, 19 Jan 2004 16:05:30 -0500 From: [email protected] Reply-To: [email protected] To: Bill Earle <[email protected]> Subject: Re: ** Re: [vtools] sophie not detecting some viruses (fwd) Hello, Sophie is a daemonized version of Sophos, or SAVI. Because of this, the version of the engine that is loaded into memory must be reloaded when a new IDE file is placed on the system. When customers are using MailMonitor (similar product to Sophie) they must restart the MailMonitor daemon after adding a new IDE file. I would imagine that the same is true for Sophie. Please let me know if you have further questions. Regards, Michele Morelock Sophos Support To: <[email protected]> cc: Bill Earle <[email protected]> bcc: From: Bill Earle <[email protected]> Date: 01/19/2004 03:58 PM Subject: ** Re: [vtools] sophie not detecting some viruses (fwd) Attached file: 2004-01-19-virus-undetected-Profile-720974.html.bin Is undetectable using sophie and the Sophos SAVI library. Sweep does detect the virus as does Norton Anti0virus on a PC. What options are required to be enabled for the SAVI libraries to identifiy the virus in the file. - Bill ---------- Forwarded message ---------- Date: Mon, 19 Jan 2004 15:29:32 -0500 (EST) From: Bill Earle <[email protected]> To: [email protected] Subject: Update: Virus Scanners!! Can someone with a PC and Anti-virus software test the file to see if it is really a Virus? http://www.space.net/~maex/Profile-720974.html.bin I have "turned on" every option configurable in our version of Sophie and re-compiled and I get the same results. Others on the vtools list, including the author, have tried the latest release of Sophie and are having no luck either. Our scanners have NEVER reported any "Sefex" virus / trojan - our daily summary reports begin on 2003-04-06 and continue through last night. Sophos's description of Troj/Sefex-A: http://www.sophos.com/virusinfo/analyses/trojsefexa.html Mailscan1's Virus summary for yesterday: ======================================= 153 W32/Dumaru-A 98 W32/Klez-H 74 W32/Gibe-F 45 W32/Bagle-A 21 W32/Sobig-F 7 W32/Bugbear-B 5 W32/Sober-C 2 W32/Bugbear-Dam 1 W32/Parite-A 1 W32/Rox-A 1 W32/Parite-B The other scanners had similar results with the same list of viruses. - Bill William B. Earle Computing & Information Technology University at Buffalo Voice: 716.645.6580 301 Computing Center Fax: 716.645.5972 Buffalo, NY 14260 ---------- Forwarded message ---------- Date: Mon, 19 Jan 2004 14:31:04 -0500 (EST) From: Bill Earle <[email protected]> Reply-To: Discussion about Virge/Sophie/Trophie/... <[email protected]> To: Discussion about Virge/Sophie/Trophie/... <[email protected]> Subject: Re: [vtools] sophie not detecting some viruses We have the same problem with an earlier version of sophie, v 1.43, and Sophos 3.76NSV. The sample file Profile-720974.html.bin: ======================================== sophie does NOT identify it as a virus: --------------------------------------- - If a virus was identified we would have seen a line similar to: "Scan result : './eicar.com' infected with virus 'EICAR-AV-Test'" $ sophie -d -f ~/Profile-720974.html.bin Initializing : Grp* options (engine >= 2.14) Initializing : Sophos engine version 2.18 Initializing : Sophos IDE version 3.76N (detects 86253 viruses) [...] Sophie version : 1.43 Scanning file : '/home/bill/Profile-720974.html.bin' [debug] Scanning file : '/home/bill/Profile-720974.html.bin' [debug] pSAVI cleaned up and released/terminated Cleanup : Sophos cleaned up and terminated sweep identifies Troj/Sefex-A virus: ------------------------------------ $ sweep -f -archive ~/Profile-720974.html.bin SWEEP virus detection utility Version 3.76N NSV, December 2003 [Linux/Intel] Includes detection for 86253 viruses, trojans and worms Copyright (c) 1989,2003 Sophos Plc, www.sophos.com System time 01:48:55 PM, System date 19 January 2004 Command line qualifiers are: -f -archive [...] Full Sweeping >>> Virus 'Troj/Sefex-A' found in file /home/bill/Profile-720974.html.bin 1 file swept in 3 seconds. 1 virus was discovered. 1 file out of 1 was infected. Please send infected samples to Sophos for analysis. For advice consult www.sophos.com, email [email protected] or telephone +44 1235 559933 End of Sweep. sophie compile time options: ---------------------------- $ sophie -c Initializing : Grp* options (engine >= 2.14) +-----------------------------------+-----+-----+ | Configuration parameter | Type|Value| +-----------------------------------+-----+-----+ | GrpSuper | 9 | 0 | | GrpArchiveUnpack | 9 | 1 | | GrpSelfExtract | 9 | 1 | | GrpExecutable | 9 | 1 | | GrpInternet | 9 | 1 | | GrpMSOffice | 9 | 1 | | GrpMisc | 9 | 1 | | GrpDisinfect | 9 | 0 | | GrpClean | 9 | 2 | | PEHandling | 3 | 1 | | Emulation | 3 | 1 | | PeEmulator | 3 | 1 | | DynamicDecompression | 3 | 1 | | Upx | 3 | 1 | | ExecFileDisinfection | 3 | 1 | | Ole2FileDisinfection | 3 | 1 | | Elf | 3 | 1 | | MachO | 3 | 1 | | SfxArchives | 3 | 0 | | ZipDecompression | 3 | 0 | | ZipUseChd | 3 | 1 | | ArjDecompression | 3 | 0 | | RarDecompression | 3 | 0 | | UueDecompression | 3 | 0 | | GZipDecompression | 3 | 0 | | CmzDecompression | 3 | 0 | | MSCabinet | 3 | 0 | | ISCabinet | 3 | 0 | | ISCabinetFull | 3 | 1 | | ITSS | 3 | 0 | | TarDecompression | 3 | 0 | | TnefAttachmentHandling | 3 | 0 | | TnefEmbedHandling | 3 | 0 | | Lha | 3 | 0 | | MSCompress | 3 | 0 | | ActiveMimeHandling | 3 | 1 | | Pdf | 3 | 1 | | HqxDecompression | 3 | 0 | | MbinDecompression | 3 | 0 | | AppleSingle | 3 | 0 | | Bzip2 | 3 | 0 | | Stuffit | 3 | 0 | | LoopBackEnabled | 3 | 0 | | OpenMacRf | 3 | 1 | | PalmPilotHandling | 3 | 1 | | Rtf | 3 | 1 | | Html | 3 | 1 | | OLE2Handling | 3 | 1 | | WordB | 3 | 1 | | VBA3Handling | 3 | 1 | | VBA5Handling | 3 | 1 | | DecompressVBA5 | 3 | 1 | | Vba5p | 3 | 0 | | ExcelFormulaHandling | 3 | 1 | | ProjectHandling | 3 | 1 | | ScrapObjectHandling | 3 | 1 | | VisioFileHandling | 3 | 1 | | OleDataMsoHandling | 3 | 1 | | OleScriptHandling | 3 | 1 | | OleRawHandling | 3 | 1 | | SrpStreamHandling | 3 | 1 | | Office2001Handling | 3 | 1 | | Vba5Dir | 3 | 0 | | PowerPointMacroHandling | 3 | 1 | | PowerPointEmbeddedHandling | 3 | 1 | | IgnoreTemplateBit | 3 | 1 | | OF95DecryptHandling | 3 | 1 | | DelVBA5Project | 3 | 1 | | HelpHandling | 3 | 1 | | Skip | 3 | 1 | | Mime | 3 | 0 | | Base64 | 3 | 0 | | Vbe | 3 | 1 | | OutlookExpress | 3 | 0 | | VbFiltering | 3 | 0 | | UTF16 | 3 | 1 | | Java | 3 | 1 | | Access | 3 | 1 | | CleanJpeg | 3 | 1 | | CleanBmp | 3 | 1 | | CleanGif | 3 | 1 | | CleanRiff | 3 | 1 | | CleanTiff | 3 | 1 | | CleanPng | 3 | 1 | | Xml | 3 | 0 | | FullMacroSweep | 3 | 0 | | FullPdf | 3 | 0 | | FullSweep | 3 | 0 | | StorageReport | 3 | 0 | | StorageReportAll | 3 | 0 | | StorageDetOnly | 3 | 0 | | DeleteAllMacros | 3 | 0 | | UnixArchive | 3 | 0 | | Rpm | 3 | 0 | | MaxRecursionDepth | 2 | 16 | | NamespaceSupport | 3 | 0 | | VirusDataDir | 10 | /usr/local/sav | | VirusDataName | 10 | vdl | | IdeDir | 10 | /usr/local/sav | | AllowPartialVirusData | 3 | 0 | +-----------------------------------+-----+-----+ - Bill William B. Earle Computing & Information Technology University at Buffalo Voice: 716.645.6580 301 Computing Center Fax: 716.645.5972 Buffalo, NY 14260 On Mon, 19 Jan 2004, Markus Stumpf wrote: > On Mon, Jan 19, 2004 at 08:01:32PM +0100, Vanja Hrustic wrote: > > The file which you've put online - how did it "get" into unpacked shape? > > > > Basically, what I'm wondering is if this arrived in an email (and had > > proper MIME headers, etc.), or it was a webpage downloaded from somewhere, > > or ... ? > > Yes ist was an email. The file as put on the webserver - was part of a > "photos.zip", an encrypted ZIP file with the password in the email: > ------------------------------------------------------------------------ > Subject: My Photo > Date: Sun, 18 Jan 2004 09:23:14 -0800 > From: Katie <[email protected]> > To: <[email protected]> > > hi, > just as i promised, i'm sending you my photo. > > ps: password is 123, so noone else would look ;) > ------------------------------------------------------------------------ > The attachment was the "photo.zip". > The ZIP file contained an image (JPG) and the "Profile-720974.html". > I have put the photo.zip on > http://www.space.net/~maex/photo.zip > Sorry, should have done that initially. > I was curious about the content, as it looked rather suspicious and > used the sweep utility for a quick check and it noticed the virus. > > I made a "mistake" and sent the .html file only on to a colleague with a > note. The "mistake" was that it shouldn't have passed the scanner and > generate an error, if sent from that host. > I was rather astonished it didn't :/ > > > Either it is a combination of config options that simply don't match > > (maybe something has to be turned off in Sophie config in order to detect > > this one), or Sweep uses something I am not aware of. > > Thanks. > I'll send the file to Sophos and see if I can get some additional > information. > > \Maex > > -- > SpaceNet AG | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0 > Research & Development | D-80807 Muenchen | Fax: +49 (89) 32356-299 > "The security, stability and reliability of a computer system is reciprocally > proportional to the amount of vacuity between the ears of the admin" > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools > _______________________________________________ vtools mailing list [email protected] http://www.vanja.com/list/listinfo.cgi/vtools Document ID: 9E8124556A9E2BB085256E2000732FFB The following attachments have been removed: 2004-01-19-virus-undetected-Profile-720974.html.bin 20031 Bytes