Re: Malware database
"Sandeep Cheema " <[email protected]> Mon, 17 Jan 2011 14:25:13 +0000
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
That's odd. Seriously. I thought all securityfocus mailing lists are manual= ly filtered. Strange I didn't receive that. Regards, Sandeep Sent from BlackBerry=AE on Airtel -----Original Message----- From: Jay Scalf <[email protected]> Date: Mon, 17 Jan 2011 14:08:50=20 To: <[email protected]> Subject: Re: Malware database This is to notify all that I received a message regarding my supposed =0A= request of Mastercard via this list. I do no have a Mastercard. Everyone = =0A= beware. If this happens again I will request to be removed form the list = =0A= even though everyone seems knowledgeable and I appreciate reading your =0A= views.=0A= =0A= On 1/14/2011 3:23 PM, David H. Lipman wrote:=0A= > I agree with this assertion.=0A= >=0A= > Malware encyclopedias are NOT what they used to be 7~10 years ago.=0A= >=0A= > New variants of malware are created daily and often hourly.=A0 So often t= hat encyclopedias (librariies) just can't be=0A= > kept up to date.=0A= >=0A= > At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, etc= ), ZBot, Gromozon, FakeAV,=0A= > FakeAlert, yada, yada.=A0 And in that we can have generalities about how = the malware conducts itself and what=0A= > changes it makes to the OS.=0A= >=0A= > As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that data = colleected is often incomplete.=A0 Especially in light=0A= > of the AntiVM routines of much of the malware I see.=A0 ANUBIS the same a= nd it can't handle .NET files.=A0 COMODO=0A= > is limited and supplies very little information.=A0 The University of Man= aheim's sandbox is very good but it is=0A= > presently down and won't be back up until the third or 4th week of this m= onth.=A0 Stefan B. has an excellent system=0A= > but it is underfunded and underpowered and I am afraid if I mention his s= ystem you will all use it and it will get=0A= > overloaded and it'll take days to get reports returned.=0A= >=0A= > We return back to the original question about 'srvpool.exe'.=0A= >=0A= > Google is ONLY good to tell you if it is a known process.=A0 However, any= file can be named anything.=A0 It isn't=0A= > enough to know the name of the file but the fully qualified name and path= to the file.=0A= >=0A= > We know SVCHOST.EXE is a legitimate process.=0A= > Not if it is loaded from %appdata%.=0A= >=0A= > Malware deliberately hides itsalf in names of legitimate files or slight = variation thereof.=0A= > SVCHOST.EXE is the most prevalent of names forged or use variations like = SCVHOST.EXE or LSASS.EXE as=0A= > Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on 'spoolsv.exe'= the Print Spooler Service.=A0 The problem is=0A= > any file can be called anything and the libraries are just not able to ke= ep up with all the new malware.=0A= >=0A= >=0A= > Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 :-)=0A= >=0A= > Dave=0A= >=0A= >=0A= >=0A= >=0A= > Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 -0700 (MST= )=0A= > Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 11:24:33 = -0500 (EST)=0A= > Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus-return-3806@security= focus.com=0A= > From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose Nazario<jos= [email protected]>=0A= > Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware database= =0A= > To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen Dobac= k<[email protected]>=0A= > Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus@securityfocus.= com,=A0 [email protected]=0A= >=0A= >> virus names used to be unique, but not so much any more.=0A= >>=0A= >> prevx, for example, lets you search by filename. plenty of sites have ni= ce=0A= >> writeups of "what is file foo.exe and what does it do?" for legitimate= =0A= >> files. prevx mostly handles malicious files, and their writeups are vagu= e=0A= >> or misleading at best in that database.=0A= >>=0A= >> as for fine grained details sandbox reports are very useful.=0A= >> threatexpert.com is one of the more comprehensive and searchable. if you= =0A= >> have a file hash (md5) that's the best way to get such details.=0A= >>=0A= >> virustotal.com is also a useful place to get pointers.=0A= >>=0A= >> i do not trust or respect most AV writeups, they're very inadequate or= =0A= >> just plain wrong.=0A= >>=0A= >> ________=0A= >> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 http://monkey= .org/~jose/=0A= >>=0A= >>=0A= >> ------------------------------------------------------------------------= ---=0A= >> This list is sponsored by: Black Hat=0A= >>=0A= >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier= =0A= >> technical event for ICT security experts. Featuring 30 hands-on training= =0A= >> courses and 90 Briefings presentations with lots of new content and new= =0A= >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product= =0A= >> displays by 30 top sponsors in a relaxed setting.=0A= >>=0A= >> http://www.blackhat.com=0A= >> ------------------------------------------------------------------------= ---=0A= >>=0A= >=0A= >=0A= >=0A= > --=0A= >=0A= >=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman=0A= >=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected]=0A= >=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman=0A= >=0A= >=0A= >=0A= > -------------------------------------------------------------------------= --=0A= > This list is sponsored by: Black Hat=0A= >=0A= > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier= =0A= > technical event for ICT security experts. Featuring 30 hands-on training= =0A= > courses and 90 Briefings presentations with lots of new content and new= =0A= > tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product= =0A= > displays by 30 top sponsors in a relaxed setting.=0A= >=0A= > http://www.blackhat.com=0A= > -------------------------------------------------------------------------= --=0A= >=0A= >=0A= =0A= ---------------------------------------------------------------------------= =0A= This list is sponsored by: Black Hat=0A= =0A= Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier = =0A= technical event for ICT security experts. Featuring 30 hands-on training = =0A= courses and 90 Briefings presentations with lots of new content and new =0A= tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product = =0A= displays by 30 top sponsors in a relaxed setting.=A0 =0A= =0A= http://www.blackhat.com=0A= --------------------------------------------------------------------------- --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------