Re: Malware database

"Sandeep Cheema " <[email protected]> Mon, 17 Jan 2011 14:25:13 +0000
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
That's odd. Seriously. I thought all securityfocus mailing lists are manual=
ly filtered. Strange I didn't receive that.

Regards, Sandeep
Sent from BlackBerry=AE on Airtel

-----Original Message-----
From: Jay Scalf <[email protected]>
Date: Mon, 17 Jan 2011 14:08:50=20
To: <[email protected]>
Subject: Re: Malware database

This is to notify all that I received a message regarding my supposed =0A=
request of Mastercard via this list. I do no have a Mastercard. Everyone =
=0A=
beware. If this happens again I will request to be removed form the list =
=0A=
even though everyone seems knowledgeable and I appreciate reading your =0A=
views.=0A=
=0A=
On 1/14/2011 3:23 PM, David H. Lipman wrote:=0A=
> I agree with this assertion.=0A=
>=0A=
> Malware encyclopedias are NOT what they used to be 7~10 years ago.=0A=
>=0A=
> New variants of malware are created daily and often hourly.=A0 So often t=
hat encyclopedias (librariies) just can't be=0A=
> kept up to date.=0A=
>=0A=
> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, etc=
), ZBot, Gromozon, FakeAV,=0A=
> FakeAlert, yada, yada.=A0 And in that we can have generalities about how =
the malware conducts itself and what=0A=
> changes it makes to the OS.=0A=
>=0A=
> As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that data =
colleected is often incomplete.=A0 Especially in light=0A=
> of the AntiVM routines of much of the malware I see.=A0 ANUBIS the same a=
nd it can't handle .NET files.=A0 COMODO=0A=
> is limited and supplies very little information.=A0 The University of Man=
aheim's sandbox is very good but it is=0A=
> presently down and won't be back up until the third or 4th week of this m=
onth.=A0 Stefan B. has an excellent system=0A=
> but it is underfunded and underpowered and I am afraid if I mention his s=
ystem you will all use it and it will get=0A=
> overloaded and it'll take days to get reports returned.=0A=
>=0A=
> We return back to the original question about 'srvpool.exe'.=0A=
>=0A=
> Google is ONLY good to tell you if it is a known process.=A0 However, any=
 file can be named anything.=A0 It isn't=0A=
> enough to know the name of the file but the fully qualified name and path=
 to the file.=0A=
>=0A=
> We know SVCHOST.EXE is a legitimate process.=0A=
> Not if it is loaded from %appdata%.=0A=
>=0A=
> Malware deliberately hides itsalf in names of legitimate files or slight =
variation thereof.=0A=
> SVCHOST.EXE is the most prevalent of names forged or use variations like =
SCVHOST.EXE or LSASS.EXE as=0A=
> Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on 'spoolsv.exe'=
 the Print Spooler Service.=A0 The problem is=0A=
> any file can be called anything and the libraries are just not able to ke=
ep up with all the new malware.=0A=
>=0A=
>=0A=
> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 :-)=0A=
>=0A=
> Dave=0A=
>=0A=
>=0A=
>=0A=
>=0A=
> Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 -0700 (MST=
)=0A=
> Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 11:24:33 =
-0500 (EST)=0A=
> Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus-return-3806@security=
focus.com=0A=
> From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose Nazario<jos=
[email protected]>=0A=
> Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware database=
=0A=
> To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen Dobac=
k<[email protected]>=0A=
> Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus@securityfocus.=
com,=A0 [email protected]=0A=
>=0A=
>> virus names used to be unique, but not so much any more.=0A=
>>=0A=
>> prevx, for example, lets you search by filename. plenty of sites have ni=
ce=0A=
>> writeups of "what is file foo.exe and what does it do?" for legitimate=
=0A=
>> files. prevx mostly handles malicious files, and their writeups are vagu=
e=0A=
>> or misleading at best in that database.=0A=
>>=0A=
>> as for fine grained details sandbox reports are very useful.=0A=
>> threatexpert.com is one of the more comprehensive and searchable. if you=
=0A=
>> have a file hash (md5) that's the best way to get such details.=0A=
>>=0A=
>> virustotal.com is also a useful place to get pointers.=0A=
>>=0A=
>> i do not trust or respect most AV writeups, they're very inadequate or=
=0A=
>> just plain wrong.=0A=
>>=0A=
>> ________=0A=
>> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 http://monkey=
.org/~jose/=0A=
>>=0A=
>>=0A=
>> ------------------------------------------------------------------------=
---=0A=
>> This list is sponsored by: Black Hat=0A=
>>=0A=
>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=
=0A=
>> technical event for ICT security experts. Featuring 30 hands-on training=
=0A=
>> courses and 90 Briefings presentations with lots of new content and new=
=0A=
>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product=
=0A=
>> displays by 30 top sponsors in a relaxed setting.=0A=
>>=0A=
>> http://www.blackhat.com=0A=
>> ------------------------------------------------------------------------=
---=0A=
>>=0A=
>=0A=
>=0A=
>=0A=
> --=0A=
>=0A=
>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman=0A=
>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected]=0A=
>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman=0A=
>=0A=
>=0A=
>=0A=
> -------------------------------------------------------------------------=
--=0A=
> This list is sponsored by: Black Hat=0A=
>=0A=
> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=
=0A=
> technical event for ICT security experts. Featuring 30 hands-on training=
=0A=
> courses and 90 Briefings presentations with lots of new content and new=
=0A=
> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product=
=0A=
> displays by 30 top sponsors in a relaxed setting.=0A=
>=0A=
> http://www.blackhat.com=0A=
> -------------------------------------------------------------------------=
--=0A=
>=0A=
>=0A=
=0A=
---------------------------------------------------------------------------=
=0A=
This list is sponsored by: Black Hat=0A=
=0A=
Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier =
=0A=
technical event for ICT security experts. Featuring 30 hands-on training =
=0A=
courses and 90 Briefings presentations with lots of new content and new =0A=
tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product =
=0A=
displays by 30 top sponsors in a relaxed setting.=A0 =0A=
=0A=
http://www.blackhat.com=0A=
---------------------------------------------------------------------------

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------