Re: Malware database
"Sandeep Cheema " <[email protected]> Mon, 17 Jan 2011 16:31:42 +0000
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
I see what you mean. That's very interesting. So a bad guy can eventually s= ign up on mailing lists and get genuine email addresses for spamming. Not t= o mention it's a cakewalk to automate the entire process. Baah. And that's = exactly what's happening. It's true that cached threads mask the email but = what about this communication happening right here? Suggest it should be ta= ken up in a different thread with the admins being involved. It's little di= sturbing. Though the spam cannot be directed to the list since it's moderat= ed but direct spam to email is possible. Thanks for bringing it to attentio= n, I certainly dis forget basics :-) Regards, Sandeep=20 Sent from BlackBerry=AE on Airtel -----Original Message----- From: Jay Scalf <[email protected]> Date: Mon, 17 Jan 2011 16:09:04=20 To: <[email protected]> Cc: <[email protected]>; <[email protected]>; <[email protected]= > Subject: Re: Malware database This is what I am getting:=0A= =0A= Your request for support has been received. Your service request reference= =0A= number is contained in this email. Please note that email should not be=0A= used for urgent requests. For issues requiring immediate attention, please= =0A= contact the Information Security HelpDesk at x26122 to speak with a=0A= representative.=0A= =0A= Please retain this notification until such time as your request is=0A= resolved.=A0 Inquiries about this message should include the SRQ# in the= =0A= subject so all activities and efforts will be tracked and recorded within= =0A= the ticket.=0A= =0A= Service Request Reference Number: SRQ506868=0A= Date Opened: 2011-01-17 08:51:39=0A= Service Request Description:=0A= Re: Malware database=0A= =0A= Thank you.=0A= =0A= =0A= =0A= CONFIDENTIALITY NOTICE=0A= This e-mail message and any attachments are only for the use of the =0A= intended recipient and may contain information that is privileged, =0A= confidential or exempt from disclosure under applicable law. If you are = =0A= not the intended recipient, any disclosure, distribution or other use of = =0A= this e-mail message or attachments is prohibited. If you have received =0A= this e-mail message in error, please delete and notify the sender =0A= immediately. Thank you.=0A= =0A= =0A= On 1/17/2011 9:24 AM, Martin, Kelly J. wrote:=0A= > How do I get off this list?=0A= >=0A= > Sent from my iPhone=0A= >=0A= > On Jan 17, 2011, at 10:24 AM, "Graham Scrowther"<[email protected]>=A0= wrote:=0A= >=0A= >> I didn't get anything either.=0A= >>=0A= >> Could you please post the message you got?=0A= >>=0A= >>=0A= >>=0A= >> -----Original Message-----=0A= >> From: [email protected] [mailto:[email protected]= ] On Behalf Of Sandeep Cheema=0A= >> Sent: 17 January 2011 14:25=0A= >> To: Jay Scalf ; [email protected]=0A= >> Subject: Re: Malware database=0A= >>=0A= >> That's odd. Seriously. I thought all securityfocus mailing lists are ma= nually filtered. Strange I didn't receive that.=0A= >>=0A= >> Regards, Sandeep=0A= >> Sent from BlackBerry=AE on Airtel=0A= >>=0A= >> -----Original Message-----=0A= >> From: Jay Scalf<[email protected]>=0A= >> Date: Mon, 17 Jan 2011 14:08:50=0A= >> To:<[email protected]>=0A= >> Subject: Re: Malware database=0A= >>=0A= >> This is to notify all that I received a message regarding my supposed= =0A= >> request of Mastercard via this list. I do no have a Mastercard. Everyon= e=0A= >> beware. If this happens again I will request to be removed form the lis= t=0A= >> even though everyone seems knowledgeable and I appreciate reading your= =0A= >> views.=0A= >>=0A= >> On 1/14/2011 3:23 PM, David H. Lipman wrote:=0A= >>> I agree with this assertion.=0A= >>>=0A= >>> Malware encyclopedias are NOT what they used to be 7~10 years ago.=0A= >>>=0A= >>> New variants of malware are created daily and often hourly.=A0 So ofte= n that encyclopedias (librariies) just can't be=0A= >>> kept up to date.=0A= >>>=0A= >>> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, = etc), ZBot, Gromozon, FakeAV,=0A= >>> FakeAlert, yada, yada.=A0 And in that we can have generalities about h= ow the malware conducts itself and what=0A= >>> changes it makes to the OS.=0A= >>>=0A= >>> As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that da= ta colleected is often incomplete.=A0 Especially in light=0A= >>> of the AntiVM routines of much of the malware I see.=A0 ANUBIS the sam= e and it can't handle .NET files.=A0 COMODO=0A= >>> is limited and supplies very little information.=A0 The University of = Manaheim's sandbox is very good but it is=0A= >>> presently down and won't be back up until the third or 4th week of thi= s month.=A0 Stefan B. has an excellent system=0A= >>> but it is underfunded and underpowered and I am afraid if I mention hi= s system you will all use it and it will get=0A= >>> overloaded and it'll take days to get reports returned.=0A= >>>=0A= >>> We return back to the original question about 'srvpool.exe'.=0A= >>>=0A= >>> Google is ONLY good to tell you if it is a known process.=A0 However, = any file can be named anything.=A0 It isn't=0A= >>> enough to know the name of the file but the fully qualified name and p= ath to the file.=0A= >>>=0A= >>> We know SVCHOST.EXE is a legitimate process.=0A= >>> Not if it is loaded from %appdata%.=0A= >>>=0A= >>> Malware deliberately hides itsalf in names of legitimate files or slig= ht variation thereof.=0A= >>> SVCHOST.EXE is the most prevalent of names forged or use variations li= ke SCVHOST.EXE or LSASS.EXE as=0A= >>> Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on 'spoolsv.e= xe' the Print Spooler Service.=A0 The problem is=0A= >>> any file can be called anything and the libraries are just not able to= keep up with all the new malware.=0A= >>>=0A= >>>=0A= >>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 :-)= =0A= >>>=0A= >>> Dave=0A= >>>=0A= >>>=0A= >>>=0A= >>>=0A= >>> Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 -0700 (= MST)=0A= >>> Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 11:24:= 33 -0500 (EST)=0A= >>> Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus-return-3806@secur= ityfocus.com=0A= >>> From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose Nazario<= [email protected]>=0A= >>> Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware databas= e=0A= >>> To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen Do= back<[email protected]>=0A= >>> Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus@securityfoc= us.com,=A0 [email protected]=0A= >>>=0A= >>>> virus names used to be unique, but not so much any more.=0A= >>>>=0A= >>>> prevx, for example, lets you search by filename. plenty of sites have= nice=0A= >>>> writeups of "what is file foo.exe and what does it do?" for legitimat= e=0A= >>>> files. prevx mostly handles malicious files, and their writeups are v= ague=0A= >>>> or misleading at best in that database.=0A= >>>>=0A= >>>> as for fine grained details sandbox reports are very useful.=0A= >>>> threatexpert.com is one of the more comprehensive and searchable. if = you=0A= >>>> have a file hash (md5) that's the best way to get such details.=0A= >>>>=0A= >>>> virustotal.com is also a useful place to get pointers.=0A= >>>>=0A= >>>> i do not trust or respect most AV writeups, they're very inadequate o= r=0A= >>>> just plain wrong.=0A= >>>>=0A= >>>>________=0A= >>>> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 http://mon= key.org/~jose/=0A= >>>>=0A= >>>>=0A= >>>> ---------------------------------------------------------------------= ------=0A= >>>> This list is sponsored by: Black Hat=0A= >>>>=0A= >>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's prem= ier=0A= >>>> technical event for ICT security experts. Featuring 30 hands-on train= ing=0A= >>>> courses and 90 Briefings presentations with lots of new content and n= ew=0A= >>>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit prod= uct=0A= >>>> displays by 30 top sponsors in a relaxed setting.=0A= >>>>=0A= >>>> http://www.blackhat.com=0A= >>>> ---------------------------------------------------------------------= ------=0A= >>>>=0A= >>>=0A= >>>=0A= >>> --=0A= >>>=0A= >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman=0A= >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected]=0A= >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman=0A= >>>=0A= >>>=0A= >>>=0A= >>> ----------------------------------------------------------------------= -----=0A= >>> This list is sponsored by: Black Hat=0A= >>>=0A= >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premi= er=0A= >>> technical event for ICT security experts. Featuring 30 hands-on traini= ng=0A= >>> courses and 90 Briefings presentations with lots of new content and ne= w=0A= >>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produ= ct=0A= >>> displays by 30 top sponsors in a relaxed setting.=0A= >>>=0A= >>> http://www.blackhat.com=0A= >>> ----------------------------------------------------------------------= -----=0A= >>>=0A= >>>=0A= >> -----------------------------------------------------------------------= ----=0A= >> This list is sponsored by: Black Hat=0A= >>=0A= >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie= r=0A= >> technical event for ICT security experts. Featuring 30 hands-on trainin= g=0A= >> courses and 90 Briefings presentations with lots of new content and new= =0A= >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produc= t=0A= >> displays by 30 top sponsors in a relaxed setting.=0A= >>=0A= >> http://www.blackhat.com=0A= >> -----------------------------------------------------------------------= ----=0A= >>=0A= >> -----------------------------------------------------------------------= ----=0A= >> This list is sponsored by: Black Hat=0A= >>=0A= >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie= r=0A= >> technical event for ICT security experts. Featuring 30 hands-on trainin= g=0A= >> courses and 90 Briefings presentations with lots of new content and new= =0A= >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produc= t=0A= >> displays by 30 top sponsors in a relaxed setting.=0A= >>=0A= >> http://www.blackhat.com=0A= >> -----------------------------------------------------------------------= ----=0A= >>=0A= >>=0A= >> -----------------------------------------------------------------------= ----=0A= >> This list is sponsored by: Black Hat=0A= >>=0A= >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie= r=0A= >> technical event for ICT security experts. Featuring 30 hands-on trainin= g=0A= >> courses and 90 Briefings presentations with lots of new content and new= =0A= >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produc= t=0A= >> displays by 30 top sponsors in a relaxed setting.=0A= >>=0A= >> http://www.blackhat.com=0A= >> -----------------------------------------------------------------------= ----=0A= >> --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------