RE: Malware database

Graham Scrowther <[email protected]> Mon, 17 Jan 2011 14:58:46 +0000
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
I didn't get anything either.

Could you please post the message you got?



-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of Sandeep Cheema=20
Sent: 17 January 2011 14:25
To: Jay Scalf ; [email protected]=20
Subject: Re: Malware database

That's odd. Seriously. I thought all securityfocus mailing lists are manual=
ly filtered. Strange I didn't receive that.

Regards, Sandeep
Sent from BlackBerry=AE on Airtel

-----Original Message-----
From: Jay Scalf <[email protected]>
Date: Mon, 17 Jan 2011 14:08:50=20
To: <[email protected]>
Subject: Re: Malware database

This is to notify all that I received a message regarding my supposed=20
request of Mastercard via this list. I do no have a Mastercard. Everyone=20
beware. If this happens again I will request to be removed form the list=20
even though everyone seems knowledgeable and I appreciate reading your=20
views.

On 1/14/2011 3:23 PM, David H. Lipman wrote:
> I agree with this assertion.
>
> Malware encyclopedias are NOT what they used to be 7~10 years ago.
>
> New variants of malware are created daily and often hourly.=A0 So often t=
hat encyclopedias (librariies) just can't be
> kept up to date.
>
> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, etc=
), ZBot, Gromozon, FakeAV,
> FakeAlert, yada, yada.=A0 And in that we can have generalities about how =
the malware conducts itself and what
> changes it makes to the OS.
>
> As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that data =
colleected is often incomplete.=A0 Especially in light
> of the AntiVM routines of much of the malware I see.=A0 ANUBIS the same a=
nd it can't handle .NET files.=A0 COMODO
> is limited and supplies very little information.=A0 The University of Man=
aheim's sandbox is very good but it is
> presently down and won't be back up until the third or 4th week of this m=
onth.=A0 Stefan B. has an excellent system
> but it is underfunded and underpowered and I am afraid if I mention his s=
ystem you will all use it and it will get
> overloaded and it'll take days to get reports returned.
>
> We return back to the original question about 'srvpool.exe'.
>
> Google is ONLY good to tell you if it is a known process.=A0 However, any=
 file can be named anything.=A0 It isn't
> enough to know the name of the file but the fully qualified name and path=
 to the file.
>
> We know SVCHOST.EXE is a legitimate process.
> Not if it is loaded from %appdata%.
>
> Malware deliberately hides itsalf in names of legitimate files or slight =
variation thereof.
> SVCHOST.EXE is the most prevalent of names forged or use variations like =
SCVHOST.EXE or LSASS.EXE as
> Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on 'spoolsv.exe'=
 the Print Spooler Service.=A0 The problem is
> any file can be called anything and the libraries are just not able to ke=
ep up with all the new malware.
>
>
> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 :-)
>
> Dave
>
>
>
>
> Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 -0700 (MST=
)
> Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 11:24:33 =
-0500 (EST)
> Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus-return-3806@security=
focus.com
> From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose Nazario<jos=
[email protected]>
> Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware database
> To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen Dobac=
k<[email protected]>
> Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus@securityfocus.=
com,=A0 [email protected]
>
>> virus names used to be unique, but not so much any more.
>>
>> prevx, for example, lets you search by filename. plenty of sites have ni=
ce
>> writeups of "what is file foo.exe and what does it do?" for legitimate
>> files. prevx mostly handles malicious files, and their writeups are vagu=
e
>> or misleading at best in that database.
>>
>> as for fine grained details sandbox reports are very useful.
>> threatexpert.com is one of the more comprehensive and searchable. if you
>> have a file hash (md5) that's the best way to get such details.
>>
>> virustotal.com is also a useful place to get pointers.
>>
>> i do not trust or respect most AV writeups, they're very inadequate or
>> just plain wrong.
>>
>> ________
>> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 http://monkey=
.org/~jose/
>>
>>
>> ------------------------------------------------------------------------=
---
>> This list is sponsored by: Black Hat
>>
>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier
>> technical event for ICT security experts. Featuring 30 hands-on training
>> courses and 90 Briefings presentations with lots of new content and new
>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product
>> displays by 30 top sponsors in a relaxed setting.
>>
>> http://www.blackhat.com
>> ------------------------------------------------------------------------=
---
>>
>
>
>
> --
>
>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman
>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected]
>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman
>
>
>
> -------------------------------------------------------------------------=
--
> This list is sponsored by: Black Hat
>
> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier
> technical event for ICT security experts. Featuring 30 hands-on training
> courses and 90 Briefings presentations with lots of new content and new
> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product
> displays by 30 top sponsors in a relaxed setting.
>
> http://www.blackhat.com
> -------------------------------------------------------------------------=
--
>
>

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20
technical event for ICT security experts. Featuring 30 hands-on training=20
courses and 90 Briefings presentations with lots of new content and new=20
tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit product=20
displays by 30 top sponsors in a relaxed setting.=A0=20

http://www.blackhat.com
---------------------------------------------------------------------------

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20
technical event for ICT security experts. Featuring 30 hands-on training=20
courses and 90 Briefings presentations with lots of new content and new=20
tools.  Network with 4,000 delegates from 70 nations.  Visit product=20
displays by 30 top sponsors in a relaxed setting. =20

http://www.blackhat.com
---------------------------------------------------------------------------


---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------