Re: Problem solved, bug in sophie found
Bill Earle <[email protected]>
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
You guys are onto something with the MIME setting. The file from Markus Stumpf is Tolfger-h, which the ide has NOT been releases as of yet. I received the .ide from Sophos Support directly, after they had analyzed the file. I'm still trying to determine, what is the proper thing to detect, the Sefex-A distribution method or the Tofger-h payload? I spoke with support to support via telephone after this also to see if I can get a recommendation as to the best settings to use when calling the SVI library. So far they haven't been able to provide that, but they are still digging. Here is the last written response I have: ---------------------------------------- Date: Wed, 21 Jan 2004 09:01:38 -0500 From: [email protected] To: Bill Earle <[email protected]> Subject: Re: [vtools] sophie not detecting some viruses (fwd) Hi Bill, I now have a more satisfactory answer on what is going on with sweep/sophie and this particular virus. Sefex-A is a generic way of distributing trojans which basically consists of HTML with a mime embedded exe and a vb script at the end to run it. Tofger-H is a specific trojan that in this case is being distributed via the Sefex-A method. The configuration option that is causing the confusion is the MIME option. - With MIME turned OFF (true in this case for sweep) the engine treats the file as plain text, scans it and detects the Sefex-A format. - With MIME turned ON (true in this case for sophie) the engine finds the embedded executable and specifically scans it as such. The problem before yesterday was that the Tofger-H trojan was not recognised and so the file was thought to be clean. Now with the addition of the new Tofger-H IDE the engine finds the trojan and reports the infection. Please let me know if you have any further questions. Regards, Michele - Bill On Thu, 22 Jan 2004, Markus Stumpf wrote: > On Thu, Jan 22, 2004 at 06:36:22AM -0800, Renato wrote: > > I recompile Sophie with this new setting, but using > > 3.76 and 3.77b on Linux I still can't scan for > > Troj/Sefex-A. I guess there are some bugs in libsavi > > as well. > > In order to scan for Troj/Sefex-A it is essential to have > Mime: 0 > This is also according to a support answer from Sophos. > Als the Mime option belongs to the GrpInternet and you want to have > GrpInternet: 1 > it is essential that you explicitely set Mime to 0, later. > It is also important that all the Grp* options are set prior to any > other option, so keep those at the top of your sophie.savi file. > > "Mime enables decoding and scanning inside a MIME encoded message block". > IMHO the broken MIME mimic of Troj/Sefex-A causes the SAVI to > incorrectly handle the file that's why you can detect the virus with > sweep -mime either. > > \Maex > > -- > SpaceNet AG | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0 > Research & Development | D-80807 Muenchen | Fax: +49 (89) 32356-299 > "The security, stability and reliability of a computer system is reciprocally > proportional to the amount of vacuity between the ears of the admin" > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools >