Re: Malware database
Jay Scalf <[email protected]> Mon, 17 Jan 2011 08:39:57 -0600
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Organization | James F. Scalf & Associates, Architects, AIA |
| Message-ID | <[email protected]> |
Yeap, me too. If someone can't slip by and take advantage of anything=20 they will anymore. As someone noted, these attacks happen hourly. The=20 days of it being a kid in his garage are gone - there is either a=20 financial or terrorist motive. On 1/17/2011 8:25 AM, Sandeep Cheema wrote: > That's odd. Seriously. I thought all securityfocus mailing lists are ma= nually filtered. Strange I didn't receive that. > > Regards, Sandeep > Sent from BlackBerry=AE on Airtel > > -----Original Message----- > From: Jay Scalf<[email protected]> > Date: Mon, 17 Jan 2011 14:08:50 > To:<[email protected]> > Subject: Re: Malware database > > This is to notify all that I received a message regarding my supposed > request of Mastercard via this list. I do no have a Mastercard. Everyon= e > beware. If this happens again I will request to be removed form the lis= t > even though everyone seems knowledgeable and I appreciate reading your > views. > > On 1/14/2011 3:23 PM, David H. Lipman wrote: >> I agree with this assertion. >> >> Malware encyclopedias are NOT what they used to be 7~10 years ago. >> >> New variants of malware are created daily and often hourly. So often = that encyclopedias (librariies) just can't be >> kept up to date. >> >> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, = etc), ZBot, Gromozon, FakeAV, >> FakeAlert, yada, yada. And in that we can have generalities about how= the malware conducts itself and what >> changes it makes to the OS. >> >> As for ThreatExpert. It is just OK. I use it but, I find that data c= olleected is often incomplete. Especially in light >> of the AntiVM routines of much of the malware I see. ANUBIS the same = and it can't handle .NET files. COMODO >> is limited and supplies very little information. The University of Ma= naheim's sandbox is very good but it is >> presently down and won't be back up until the third or 4th week of thi= s month. Stefan B. has an excellent system >> but it is underfunded and underpowered and I am afraid if I mention hi= s system you will all use it and it will get >> overloaded and it'll take days to get reports returned. >> >> We return back to the original question about 'srvpool.exe'. >> >> Google is ONLY good to tell you if it is a known process. However, an= y file can be named anything. It isn't >> enough to know the name of the file but the fully qualified name and p= ath to the file. >> >> We know SVCHOST.EXE is a legitimate process. >> Not if it is loaded from %appdata%. >> >> Malware deliberately hides itsalf in names of legitimate files or slig= ht variation thereof. >> SVCHOST.EXE is the most prevalent of names forged or use variations li= ke SCVHOST.EXE or LSASS.EXE as >> Isass.exe. Here we have 'srvpool.exe' which is a take on 'spoolsv.exe= ' the Print Spooler Service. The problem is >> any file can be called anything and the libraries are just not able to= keep up with all the new malware. >> >> >> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this. :-) >> >> Dave >> >> >> >> >> Date forwarded: Fri, 14 Jan 2011 09:26:47 -0700 (MST) >> Date sent: Fri, 14 Jan 2011 11:24:33 -0500 (EST) >> Forwarded by: [email protected] >> From: Jose Nazario<[email protected]> >> Subject: Re: Malware database >> To: Huffen Doback<[email protected]> >> Copies to: [email protected], focus-virus-ret= [email protected] >> >>> virus names used to be unique, but not so much any more. >>> >>> prevx, for example, lets you search by filename. plenty of sites have= nice >>> writeups of "what is file foo.exe and what does it do?" for legitimat= e >>> files. prevx mostly handles malicious files, and their writeups are v= ague >>> or misleading at best in that database. >>> >>> as for fine grained details sandbox reports are very useful. >>> threatexpert.com is one of the more comprehensive and searchable. if = you >>> have a file hash (md5) that's the best way to get such details. >>> >>> virustotal.com is also a useful place to get pointers. >>> >>> i do not trust or respect most AV writeups, they're very inadequate o= r >>> just plain wrong. >>> >>> ________ >>> jose nazario, ph.d. http://monkey.org/~jose/ >>> >>> >>> ---------------------------------------------------------------------= ------ >>> This list is sponsored by: Black Hat >>> >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's prem= ier >>> technical event for ICT security experts. Featuring 30 hands-on train= ing >>> courses and 90 Briefings presentations with lots of new content and n= ew >>> tools. Network with 4,000 delegates from 70 nations. Visit product >>> displays by 30 top sponsors in a relaxed setting. >>> >>> http://www.blackhat.com >>> ---------------------------------------------------------------------= ------ >>> >> >> >> -- >> >> Mr. David H. Lipman >> [email protected] >> Yahoo IM: david_h_lipman >> >> >> >> ----------------------------------------------------------------------= ----- >> This list is sponsored by: Black Hat >> >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premi= er >> technical event for ICT security experts. Featuring 30 hands-on traini= ng >> courses and 90 Briefings presentations with lots of new content and ne= w >> tools. Network with 4,000 delegates from 70 nations. Visit product >> displays by 30 top sponsors in a relaxed setting. >> >> http://www.blackhat.com >> ----------------------------------------------------------------------= ----- >> >> > -----------------------------------------------------------------------= ---- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie= r > technical event for ICT security experts. Featuring 30 hands-on trainin= g > courses and 90 Briefings presentations with lots of new content and new > tools. Network with 4,000 delegates from 70 nations. Visit product > displays by 30 top sponsors in a relaxed setting.=20 > > http://www.blackhat.com > -----------------------------------------------------------------------= ---- > -------------------------------------------------------------------------= -- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20 technical event for ICT security experts. Featuring 30 hands-on training=20 courses and 90 Briefings presentations with lots of new content and new=20 tools. Network with 4,000 delegates from 70 nations. Visit product=20 displays by 30 top sponsors in a relaxed setting. =20 http://www.blackhat.com -------------------------------------------------------------------------= --