Re: Malware database

"Sandeep Cheema " <[email protected]> Mon, 17 Jan 2011 16:31:42 +0000
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
I see what you mean. That's very interesting. So a bad guy can eventually s=
ign up on mailing lists and get genuine email addresses for spamming. Not t=
o mention it's a cakewalk to automate the entire process. Baah. And that's =
exactly what's happening. It's true that cached threads mask the email but =
what about this communication happening right here? Suggest it should be ta=
ken up in a different thread with the admins being involved. It's little di=
sturbing. Though the spam cannot be directed to the list since it's moderat=
ed but direct spam to email is possible. Thanks for bringing it to attentio=
n, I certainly dis forget basics :-)

Regards, Sandeep=20
Sent from BlackBerry=AE on Airtel

-----Original Message-----
From: Jay Scalf <[email protected]>
Date: Mon, 17 Jan 2011 16:09:04=20
To: <[email protected]>
Cc: <[email protected]>; <[email protected]>; <[email protected]=
>
Subject: Re: Malware database

This is what I am getting:=0A=
 =0A=
 Your request for support has been received. Your service request reference=
=0A=
 number is contained in this email. Please note that email should not be=0A=
 used for urgent requests. For issues requiring immediate attention, please=
=0A=
 contact the Information Security HelpDesk at x26122 to speak with a=0A=
 representative.=0A=
 =0A=
 Please retain this notification until such time as your request is=0A=
 resolved.=A0 Inquiries about this message should include the SRQ# in the=
=0A=
 subject so all activities and efforts will be tracked and recorded within=
=0A=
 the ticket.=0A=
 =0A=
 Service Request Reference Number: SRQ506868=0A=
 Date Opened: 2011-01-17 08:51:39=0A=
 Service Request Description:=0A=
 Re: Malware database=0A=
 =0A=
 Thank you.=0A=
 =0A=
 =0A=
 =0A=
 CONFIDENTIALITY NOTICE=0A=
 This e-mail message and any attachments are only for the use of the =0A=
 intended recipient and may contain information that is privileged, =0A=
 confidential or exempt from disclosure under applicable law. If you are =
=0A=
 not the intended recipient, any disclosure, distribution or other use of =
=0A=
 this e-mail message or attachments is prohibited. If you have received =0A=
 this e-mail message in error, please delete and notify the sender =0A=
 immediately. Thank you.=0A=
 =0A=
 =0A=
 On 1/17/2011 9:24 AM, Martin, Kelly J. wrote:=0A=
 > How do I get off this list?=0A=
 >=0A=
 > Sent from my iPhone=0A=
 >=0A=
 > On Jan 17, 2011, at 10:24 AM, "Graham Scrowther"<[email protected]>=A0=
 wrote:=0A=
 >=0A=
 >> I didn't get anything either.=0A=
 >>=0A=
 >> Could you please post the message you got?=0A=
 >>=0A=
 >>=0A=
 >>=0A=
 >> -----Original Message-----=0A=
 >> From: [email protected] [mailto:[email protected]=
] On Behalf Of Sandeep Cheema=0A=
 >> Sent: 17 January 2011 14:25=0A=
 >> To: Jay Scalf ; [email protected]=0A=
 >> Subject: Re: Malware database=0A=
 >>=0A=
 >> That's odd. Seriously. I thought all securityfocus mailing lists are ma=
nually filtered. Strange I didn't receive that.=0A=
 >>=0A=
 >> Regards, Sandeep=0A=
 >> Sent from BlackBerry=AE on Airtel=0A=
 >>=0A=
 >> -----Original Message-----=0A=
 >> From: Jay Scalf<[email protected]>=0A=
 >> Date: Mon, 17 Jan 2011 14:08:50=0A=
 >> To:<[email protected]>=0A=
 >> Subject: Re: Malware database=0A=
 >>=0A=
 >> This is to notify all that I received a message regarding my supposed=
=0A=
 >> request of Mastercard via this list. I do no have a Mastercard. Everyon=
e=0A=
 >> beware. If this happens again I will request to be removed form the lis=
t=0A=
 >> even though everyone seems knowledgeable and I appreciate reading your=
=0A=
 >> views.=0A=
 >>=0A=
 >> On 1/14/2011 3:23 PM, David H. Lipman wrote:=0A=
 >>> I agree with this assertion.=0A=
 >>>=0A=
 >>> Malware encyclopedias are NOT what they used to be 7~10 years ago.=0A=
 >>>=0A=
 >>> New variants of malware are created daily and often hourly.=A0 So ofte=
n that encyclopedias (librariies) just can't be=0A=
 >>> kept up to date.=0A=
 >>>=0A=
 >>> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, =
etc), ZBot, Gromozon, FakeAV,=0A=
 >>> FakeAlert, yada, yada.=A0 And in that we can have generalities about h=
ow the malware conducts itself and what=0A=
 >>> changes it makes to the OS.=0A=
 >>>=0A=
 >>> As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that da=
ta colleected is often incomplete.=A0 Especially in light=0A=
 >>> of the AntiVM routines of much of the malware I see.=A0 ANUBIS the sam=
e and it can't handle .NET files.=A0 COMODO=0A=
 >>> is limited and supplies very little information.=A0 The University of =
Manaheim's sandbox is very good but it is=0A=
 >>> presently down and won't be back up until the third or 4th week of thi=
s month.=A0 Stefan B. has an excellent system=0A=
 >>> but it is underfunded and underpowered and I am afraid if I mention hi=
s system you will all use it and it will get=0A=
 >>> overloaded and it'll take days to get reports returned.=0A=
 >>>=0A=
 >>> We return back to the original question about 'srvpool.exe'.=0A=
 >>>=0A=
 >>> Google is ONLY good to tell you if it is a known process.=A0 However, =
any file can be named anything.=A0 It isn't=0A=
 >>> enough to know the name of the file but the fully qualified name and p=
ath to the file.=0A=
 >>>=0A=
 >>> We know SVCHOST.EXE is a legitimate process.=0A=
 >>> Not if it is loaded from %appdata%.=0A=
 >>>=0A=
 >>> Malware deliberately hides itsalf in names of legitimate files or slig=
ht variation thereof.=0A=
 >>> SVCHOST.EXE is the most prevalent of names forged or use variations li=
ke SCVHOST.EXE or LSASS.EXE as=0A=
 >>> Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on 'spoolsv.e=
xe' the Print Spooler Service.=A0 The problem is=0A=
 >>> any file can be called anything and the libraries are just not able to=
 keep up with all the new malware.=0A=
 >>>=0A=
 >>>=0A=
 >>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 :-)=
=0A=
 >>>=0A=
 >>> Dave=0A=
 >>>=0A=
 >>>=0A=
 >>>=0A=
 >>>=0A=
 >>> Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 -0700 (=
MST)=0A=
 >>> Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 11:24:=
33 -0500 (EST)=0A=
 >>> Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus-return-3806@secur=
ityfocus.com=0A=
 >>> From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose Nazario<=
[email protected]>=0A=
 >>> Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware databas=
e=0A=
 >>> To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen Do=
back<[email protected]>=0A=
 >>> Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 focus-virus@securityfoc=
us.com,=A0 [email protected]=0A=
 >>>=0A=
 >>>> virus names used to be unique, but not so much any more.=0A=
 >>>>=0A=
 >>>> prevx, for example, lets you search by filename. plenty of sites have=
 nice=0A=
 >>>> writeups of "what is file foo.exe and what does it do?" for legitimat=
e=0A=
 >>>> files. prevx mostly handles malicious files, and their writeups are v=
ague=0A=
 >>>> or misleading at best in that database.=0A=
 >>>>=0A=
 >>>> as for fine grained details sandbox reports are very useful.=0A=
 >>>> threatexpert.com is one of the more comprehensive and searchable. if =
you=0A=
 >>>> have a file hash (md5) that's the best way to get such details.=0A=
 >>>>=0A=
 >>>> virustotal.com is also a useful place to get pointers.=0A=
 >>>>=0A=
 >>>> i do not trust or respect most AV writeups, they're very inadequate o=
r=0A=
 >>>> just plain wrong.=0A=
 >>>>=0A=
 >>>>________=0A=
 >>>> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 http://mon=
key.org/~jose/=0A=
 >>>>=0A=
 >>>>=0A=
 >>>> ---------------------------------------------------------------------=
------=0A=
 >>>> This list is sponsored by: Black Hat=0A=
 >>>>=0A=
 >>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's prem=
ier=0A=
 >>>> technical event for ICT security experts. Featuring 30 hands-on train=
ing=0A=
 >>>> courses and 90 Briefings presentations with lots of new content and n=
ew=0A=
 >>>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit prod=
uct=0A=
 >>>> displays by 30 top sponsors in a relaxed setting.=0A=
 >>>>=0A=
 >>>> http://www.blackhat.com=0A=
 >>>> ---------------------------------------------------------------------=
------=0A=
 >>>>=0A=
 >>>=0A=
 >>>=0A=
 >>> --=0A=
 >>>=0A=
 >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman=0A=
 >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected]=0A=
 >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman=0A=
 >>>=0A=
 >>>=0A=
 >>>=0A=
 >>> ----------------------------------------------------------------------=
-----=0A=
 >>> This list is sponsored by: Black Hat=0A=
 >>>=0A=
 >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premi=
er=0A=
 >>> technical event for ICT security experts. Featuring 30 hands-on traini=
ng=0A=
 >>> courses and 90 Briefings presentations with lots of new content and ne=
w=0A=
 >>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produ=
ct=0A=
 >>> displays by 30 top sponsors in a relaxed setting.=0A=
 >>>=0A=
 >>> http://www.blackhat.com=0A=
 >>> ----------------------------------------------------------------------=
-----=0A=
 >>>=0A=
 >>>=0A=
 >> -----------------------------------------------------------------------=
----=0A=
 >> This list is sponsored by: Black Hat=0A=
 >>=0A=
 >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie=
r=0A=
 >> technical event for ICT security experts. Featuring 30 hands-on trainin=
g=0A=
 >> courses and 90 Briefings presentations with lots of new content and new=
=0A=
 >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produc=
t=0A=
 >> displays by 30 top sponsors in a relaxed setting.=0A=
 >>=0A=
 >> http://www.blackhat.com=0A=
 >> -----------------------------------------------------------------------=
----=0A=
 >>=0A=
 >> -----------------------------------------------------------------------=
----=0A=
 >> This list is sponsored by: Black Hat=0A=
 >>=0A=
 >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie=
r=0A=
 >> technical event for ICT security experts. Featuring 30 hands-on trainin=
g=0A=
 >> courses and 90 Briefings presentations with lots of new content and new=
=0A=
 >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produc=
t=0A=
 >> displays by 30 top sponsors in a relaxed setting.=0A=
 >>=0A=
 >> http://www.blackhat.com=0A=
 >> -----------------------------------------------------------------------=
----=0A=
 >>=0A=
 >>=0A=
 >> -----------------------------------------------------------------------=
----=0A=
 >> This list is sponsored by: Black Hat=0A=
 >>=0A=
 >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premie=
r=0A=
 >> technical event for ICT security experts. Featuring 30 hands-on trainin=
g=0A=
 >> courses and 90 Briefings presentations with lots of new content and new=
=0A=
 >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit produc=
t=0A=
 >> displays by 30 top sponsors in a relaxed setting.=0A=
 >>=0A=
 >> http://www.blackhat.com=0A=
 >> -----------------------------------------------------------------------=
----=0A=
 >>

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------