Re: Malware database

Jay Scalf <[email protected]> Mon, 17 Jan 2011 10:09:04 -0600
Newsgroups gmane.comp.security.virus
Organization James F. Scalf & Associates, Architects, AIA
Message-ID <[email protected]>
This is what I am getting:

Your request for support has been received. Your service request referenc=
e
number is contained in this email. Please note that email should not be
used for urgent requests. For issues requiring immediate attention, pleas=
e
contact the Information Security HelpDesk at x26122 to speak with a
representative.

Please retain this notification until such time as your request is
resolved.  Inquiries about this message should include the SRQ# in the
subject so all activities and efforts will be tracked and recorded within
the ticket.

Service Request Reference Number: SRQ506868
Date Opened: 2011-01-17 08:51:39
Service Request Description:
Re: Malware database

Thank you.



CONFIDENTIALITY NOTICE
This e-mail message and any attachments are only for the use of the=20
intended recipient and may contain information that is privileged,=20
confidential or exempt from disclosure under applicable law. If you are=20
not the intended recipient, any disclosure, distribution or other use of=20
this e-mail message or attachments is prohibited. If you have received=20
this e-mail message in error, please delete and notify the sender=20
immediately. Thank you.


On 1/17/2011 9:24 AM, Martin, Kelly J. wrote:
> How do I get off this list?
>
> Sent from my iPhone
>
> On Jan 17, 2011, at 10:24 AM, "Graham Scrowther"<[email protected]>  =
wrote:
>
>> I didn't get anything either.
>>
>> Could you please post the message you got?
>>
>>
>>
>> -----Original Message-----
>> From: [email protected] [mailto:[email protected]=
m] On Behalf Of Sandeep Cheema
>> Sent: 17 January 2011 14:25
>> To: Jay Scalf ; [email protected]
>> Subject: Re: Malware database
>>
>> That's odd. Seriously. I thought all securityfocus mailing lists are m=
anually filtered. Strange I didn't receive that.
>>
>> Regards, Sandeep
>> Sent from BlackBerry=C2=AE on Airtel
>>
>> -----Original Message-----
>> From: Jay Scalf<[email protected]>
>> Date: Mon, 17 Jan 2011 14:08:50
>> To:<[email protected]>
>> Subject: Re: Malware database
>>
>> This is to notify all that I received a message regarding my supposed
>> request of Mastercard via this list. I do no have a Mastercard. Everyo=
ne
>> beware. If this happens again I will request to be removed form the li=
st
>> even though everyone seems knowledgeable and I appreciate reading your
>> views.
>>
>> On 1/14/2011 3:23 PM, David H. Lipman wrote:
>>> I agree with this assertion.
>>>
>>> Malware encyclopedias are NOT what they used to be 7~10 years ago.
>>>
>>> New variants of malware are created daily and often hourly.  So often=
 that encyclopedias (librariies) just can't be
>>> kept up to date.
>>>
>>> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4,=
 etc), ZBot, Gromozon, FakeAV,
>>> FakeAlert, yada, yada.  And in that we can have generalities about ho=
w the malware conducts itself and what
>>> changes it makes to the OS.
>>>
>>> As for ThreatExpert.  It is just OK.  I use it but, I find that data =
colleected is often incomplete.  Especially in light
>>> of the AntiVM routines of much of the malware I see.  ANUBIS the same=
 and it can't handle .NET files.  COMODO
>>> is limited and supplies very little information.  The University of M=
anaheim's sandbox is very good but it is
>>> presently down and won't be back up until the third or 4th week of th=
is month.  Stefan B. has an excellent system
>>> but it is underfunded and underpowered and I am afraid if I mention h=
is system you will all use it and it will get
>>> overloaded and it'll take days to get reports returned.
>>>
>>> We return back to the original question about 'srvpool.exe'.
>>>
>>> Google is ONLY good to tell you if it is a known process.  However, a=
ny file can be named anything.  It isn't
>>> enough to know the name of the file but the fully qualified name and =
path to the file.
>>>
>>> We know SVCHOST.EXE is a legitimate process.
>>> Not if it is loaded from %appdata%.
>>>
>>> Malware deliberately hides itsalf in names of legitimate files or sli=
ght variation thereof.
>>> SVCHOST.EXE is the most prevalent of names forged or use variations l=
ike SCVHOST.EXE or LSASS.EXE as
>>> Isass.exe.  Here we have 'srvpool.exe' which is a take on 'spoolsv.ex=
e' the Print Spooler Service.  The problem is
>>> any file can be called anything and the libraries are just not able t=
o keep up with all the new malware.
>>>
>>>
>>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.  :-)
>>>
>>> Dave
>>>
>>>
>>>
>>>
>>> Date forwarded:        Fri, 14 Jan 2011 09:26:47 -0700 (MST)
>>> Date sent:             Fri, 14 Jan 2011 11:24:33 -0500 (EST)
>>> Forwarded by:          [email protected]
>>> From:                  Jose Nazario<[email protected]>
>>> Subject:               Re: Malware database
>>> To:                    Huffen Doback<[email protected]>
>>> Copies to:             [email protected],  focus-virus-re=
[email protected]
>>>
>>>> virus names used to be unique, but not so much any more.
>>>>
>>>> prevx, for example, lets you search by filename. plenty of sites hav=
e nice
>>>> writeups of "what is file foo.exe and what does it do?" for legitima=
te
>>>> files. prevx mostly handles malicious files, and their writeups are =
vague
>>>> or misleading at best in that database.
>>>>
>>>> as for fine grained details sandbox reports are very useful.
>>>> threatexpert.com is one of the more comprehensive and searchable. if=
 you
>>>> have a file hash (md5) that's the best way to get such details.
>>>>
>>>> virustotal.com is also a useful place to get pointers.
>>>>
>>>> i do not trust or respect most AV writeups, they're very inadequate =
or
>>>> just plain wrong.
>>>>
>>>> ________
>>>> jose nazario, ph.d.              http://monkey.org/~jose/
>>>>
>>>>
>>>> --------------------------------------------------------------------=
-------
>>>> This list is sponsored by: Black Hat
>>>>
>>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's pre=
mier
>>>> technical event for ICT security experts. Featuring 30 hands-on trai=
ning
>>>> courses and 90 Briefings presentations with lots of new content and =
new
>>>> tools.  Network with 4,000 delegates from 70 nations.  Visit product
>>>> displays by 30 top sponsors in a relaxed setting.
>>>>
>>>> http://www.blackhat.com
>>>> --------------------------------------------------------------------=
-------
>>>>
>>>
>>>
>>> --
>>>
>>>                                    Mr. David H. Lipman
>>>                                    [email protected]
>>>                                 Yahoo IM:  david_h_lipman
>>>
>>>
>>>
>>> ---------------------------------------------------------------------=
------
>>> This list is sponsored by: Black Hat
>>>
>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's prem=
ier
>>> technical event for ICT security experts. Featuring 30 hands-on train=
ing
>>> courses and 90 Briefings presentations with lots of new content and n=
ew
>>> tools.  Network with 4,000 delegates from 70 nations.  Visit product
>>> displays by 30 top sponsors in a relaxed setting.
>>>
>>> http://www.blackhat.com
>>> ---------------------------------------------------------------------=
------
>>>
>>>
>> ----------------------------------------------------------------------=
-----
>> This list is sponsored by: Black Hat
>>
>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premi=
er
>> technical event for ICT security experts. Featuring 30 hands-on traini=
ng
>> courses and 90 Briefings presentations with lots of new content and ne=
w
>> tools.  Network with 4,000 delegates from 70 nations.  Visit product
>> displays by 30 top sponsors in a relaxed setting.
>>
>> http://www.blackhat.com
>> ----------------------------------------------------------------------=
-----
>>
>> ----------------------------------------------------------------------=
-----
>> This list is sponsored by: Black Hat
>>
>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premi=
er
>> technical event for ICT security experts. Featuring 30 hands-on traini=
ng
>> courses and 90 Briefings presentations with lots of new content and ne=
w
>> tools.  Network with 4,000 delegates from 70 nations.  Visit product
>> displays by 30 top sponsors in a relaxed setting.
>>
>> http://www.blackhat.com
>> ----------------------------------------------------------------------=
-----
>>
>>
>> ----------------------------------------------------------------------=
-----
>> This list is sponsored by: Black Hat
>>
>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premi=
er
>> technical event for ICT security experts. Featuring 30 hands-on traini=
ng
>> courses and 90 Briefings presentations with lots of new content and ne=
w
>> tools.  Network with 4,000 delegates from 70 nations.  Visit product
>> displays by 30 top sponsors in a relaxed setting.
>>
>> http://www.blackhat.com
>> ----------------------------------------------------------------------=
-----
>>

-------------------------------------------------------------------------=
--
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20
technical event for ICT security experts. Featuring 30 hands-on training=20
courses and 90 Briefings presentations with lots of new content and new=20
tools.  Network with 4,000 delegates from 70 nations.  Visit product=20
displays by 30 top sponsors in a relaxed setting. =20

http://www.blackhat.com
-------------------------------------------------------------------------=
--