RE: Malware database
Graham Scrowther <[email protected]> Mon, 17 Jan 2011 14:58:46 +0000
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
I didn't get anything either. Could you please post the message you got? -----Original Message----- From: [email protected] [mailto:[email protected]] On= Behalf Of Sandeep Cheema=20 Sent: 17 January 2011 14:25 To: Jay Scalf ; [email protected]=20 Subject: Re: Malware database That's odd. Seriously. I thought all securityfocus mailing lists are manual= ly filtered. Strange I didn't receive that. Regards, Sandeep Sent from BlackBerry=AE on Airtel -----Original Message----- From: Jay Scalf <[email protected]> Date: Mon, 17 Jan 2011 14:08:50=20 To: <[email protected]> Subject: Re: Malware database This is to notify all that I received a message regarding my supposed=20 request of Mastercard via this list. I do no have a Mastercard. Everyone=20 beware. If this happens again I will request to be removed form the list=20 even though everyone seems knowledgeable and I appreciate reading your=20 views. On 1/14/2011 3:23 PM, David H. Lipman wrote: > I agree with this assertion. > > Malware encyclopedias are NOT what they used to be 7~10 years ago. > > New variants of malware are created daily and often hourly.=A0 So often t= hat encyclopedias (librariies) just can't be > kept up to date. > > At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, etc= ), ZBot, Gromozon, FakeAV, > FakeAlert, yada, yada.=A0 And in that we can have generalities about how = the malware conducts itself and what > changes it makes to the OS. > > As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that data = colleected is often incomplete.=A0 Especially in light > of the AntiVM routines of much of the malware I see.=A0 ANUBIS the same a= nd it can't handle .NET files.=A0 COMODO > is limited and supplies very little information.=A0 The University of Man= aheim's sandbox is very good but it is > presently down and won't be back up until the third or 4th week of this m= onth.=A0 Stefan B. has an excellent system > but it is underfunded and underpowered and I am afraid if I mention his s= ystem you will all use it and it will get > overloaded and it'll take days to get reports returned. > > We return back to the original question about 'srvpool.exe'. > > Google is ONLY good to tell you if it is a known process.=A0 However, any= file can be named anything.=A0 It isn't > enough to know the name of the file but the fully qualified name and path= to the file. > > We know SVCHOST.EXE is a legitimate process. > Not if it is loaded from %appdata%. > > Malware deliberately hides itsalf in names of legitimate files or slight = variation thereof. > SVCHOST.EXE is the most prevalent of names forged or use variations like = SCVHOST.EXE or LSASS.EXE as > Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on 'spoolsv.exe'= the Print Spooler Service.=A0 The problem is > any file can be called anything and the libraries are just not able to ke= ep up with all the new malware. > > > Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 :-) > > Dave > > > > > Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 -0700 (MST= ) > Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 11:24:33 = -0500 (EST) > Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus-return-3806@security= focus.com > From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose Nazario<jos= [email protected]> > Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware database > To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen Dobac= k<[email protected]> > Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus@securityfocus.= com,=A0 [email protected] > >> virus names used to be unique, but not so much any more. >> >> prevx, for example, lets you search by filename. plenty of sites have ni= ce >> writeups of "what is file foo.exe and what does it do?" for legitimate >> files. prevx mostly handles malicious files, and their writeups are vagu= e >> or misleading at best in that database. >> >> as for fine grained details sandbox reports are very useful. >> threatexpert.com is one of the more comprehensive and searchable. if you >> have a file hash (md5) that's the best way to get such details. >> >> virustotal.com is also a useful place to get pointers. >> >> i do not trust or respect most AV writeups, they're very inadequate or >> just plain wrong. >> >> ________ >> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 http://monkey= .org/~jose/ >> >> >> ------------------------------------------------------------------------= --- >> This list is sponsored by: Black Hat >> >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier >> technical event for ICT security experts. Featuring 30 hands-on training >> courses and 90 Briefings presentations with lots of new content and new >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product >> displays by 30 top sponsors in a relaxed setting. >> >> http://www.blackhat.com >> ------------------------------------------------------------------------= --- >> > > > > -- > >=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman >=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected] >=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman > > > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > technical event for ICT security experts. Featuring 30 hands-on training > courses and 90 Briefings presentations with lots of new content and new > tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product > displays by 30 top sponsors in a relaxed setting. > > http://www.blackhat.com > -------------------------------------------------------------------------= -- > > --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20 technical event for ICT security experts. Featuring 30 hands-on training=20 courses and 90 Briefings presentations with lots of new content and new=20 tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product=20 displays by 30 top sponsors in a relaxed setting.=A0=20 http://www.blackhat.com --------------------------------------------------------------------------- --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20 technical event for ICT security experts. Featuring 30 hands-on training=20 courses and 90 Briefings presentations with lots of new content and new=20 tools. Network with 4,000 delegates from 70 nations. Visit product=20 displays by 30 top sponsors in a relaxed setting. =20 http://www.blackhat.com --------------------------------------------------------------------------- --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------