Re: Problem solved, bug in sophie found

Bill Earle <[email protected]>
Newsgroups gmane.comp.security.virus.vtools
Message-ID <[email protected]>
You guys are onto something with the MIME setting. The file from
Markus Stumpf is Tolfger-h, which the ide has NOT been releases as
of yet. I received the .ide from Sophos Support directly, after they
had analyzed the file.

I'm still trying to determine, what is the proper thing to detect,
the Sefex-A distribution method or the Tofger-h payload?

I spoke with support to support via telephone after this also
to see if I can get a recommendation as to the best settings to
use when calling the SVI library. So far they haven't been able
to provide that, but they are still digging.


Here is the last written response I have:
----------------------------------------
Date: Wed, 21 Jan 2004 09:01:38 -0500
From: [email protected]
To: Bill Earle <[email protected]>
Subject: Re: [vtools] sophie not detecting some viruses (fwd)


Hi Bill,

I now have a more satisfactory answer on what is going on with
sweep/sophie
and this particular virus.

Sefex-A is a generic way of distributing trojans which basically consists
of HTML with a mime embedded exe and a vb script at the end to run it.
Tofger-H is a specific trojan that in this case is being distributed via
the Sefex-A method.

The configuration option that is causing the confusion is the MIME option.
- With MIME turned OFF (true in this case for sweep) the engine treats the
file as plain text, scans it and detects the Sefex-A format.
- With MIME turned ON (true in this case for sophie) the engine finds the
embedded executable and specifically scans it as such. The problem before
yesterday was that the Tofger-H trojan was not recognised and so the file
was thought to be clean. Now with the addition of the new Tofger-H IDE the
engine finds the trojan and reports the infection.

Please let me know if you have any further questions.

Regards,
Michele


- Bill


On Thu, 22 Jan 2004, Markus Stumpf wrote:

> On Thu, Jan 22, 2004 at 06:36:22AM -0800, Renato wrote:
> > I recompile Sophie with this new setting, but using
> > 3.76 and 3.77b on Linux I still can't scan for
> > Troj/Sefex-A. I guess there are some bugs in libsavi
> > as well.
>
> In order to scan for Troj/Sefex-A it is essential to have
>     Mime: 0
> This is also according to a support answer from Sophos.
> Als the Mime option belongs to the GrpInternet and you want to have
>     GrpInternet: 1
> it is essential that you explicitely set Mime to 0, later.
> It is also important that all the Grp* options are set prior to any
> other option, so keep those at the top of your sophie.savi file.
>
> "Mime enables decoding and scanning inside a MIME encoded message block".
> IMHO the broken MIME mimic of Troj/Sefex-A causes the SAVI to
> incorrectly handle the file that's why you can detect the virus with
> sweep -mime either.
>
> 	\Maex
>
> --
> SpaceNet AG            | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0
> Research & Development |       D-80807 Muenchen    | Fax: +49 (89) 32356-299
> "The security, stability and reliability of a computer system is reciprocally
>  proportional to the amount of vacuity between the ears of the admin"
> _______________________________________________
> vtools mailing list
> [email protected]
> http://www.vanja.com/list/listinfo.cgi/vtools
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.