Re: Malware database
Jay Scalf <[email protected]> Mon, 17 Jan 2011 10:40:15 -0600
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Organization | James F. Scalf & Associates, Architects, AIA |
| Message-ID | <[email protected]> |
Sandeep, I have spent all morning in chat with Comcast and the only way to=20 block it from going both to my Thunderbird in laptop and Blackberry is=20 to mark as spam individually on-line with Comcast's e-mail. Time=20 consuming but hopefully effective. I'll let you know. Jay On 1/17/2011 10:31 AM, Sandeep Cheema wrote: > I see what you mean. That's very interesting. So a bad guy can eventual= ly sign up on mailing lists and get genuine email addresses for spamming.= Not to mention it's a cakewalk to automate the entire process. Baah. And= that's exactly what's happening. It's true that cached threads mask the = email but what about this communication happening right here? Suggest it = should be taken up in a different thread with the admins being involved. = It's little disturbing. Though the spam cannot be directed to the list si= nce it's moderated but direct spam to email is possible. Thanks for bring= ing it to attention, I certainly dis forget basics :-) > > Regards, Sandeep > Sent from BlackBerry=AE on Airtel > > -----Original Message----- > From: Jay Scalf<[email protected]> > Date: Mon, 17 Jan 2011 16:09:04 > To:<[email protected]> > Cc:<[email protected]>;<[email protected]>;<[email protected]= m> > Subject: Re: Malware database > > This is what I am getting: > > Your request for support has been received. Your service request refe= rence > number is contained in this email. Please note that email should not = be > used for urgent requests. For issues requiring immediate attention, p= lease > contact the Information Security HelpDesk at x26122 to speak with a > representative. > > Please retain this notification until such time as your request is > resolved. Inquiries about this message should include the SRQ# in th= e > subject so all activities and efforts will be tracked and recorded wi= thin > the ticket. > > Service Request Reference Number: SRQ506868 > Date Opened: 2011-01-17 08:51:39 > Service Request Description: > Re: Malware database > > Thank you. > > > > CONFIDENTIALITY NOTICE > This e-mail message and any attachments are only for the use of the > intended recipient and may contain information that is privileged, > confidential or exempt from disclosure under applicable law. If you a= re > not the intended recipient, any disclosure, distribution or other use= of > this e-mail message or attachments is prohibited. If you have receive= d > this e-mail message in error, please delete and notify the sender > immediately. Thank you. > > > On 1/17/2011 9:24 AM, Martin, Kelly J. wrote: > > How do I get off this list? > > > > Sent from my iPhone > > > > On Jan 17, 2011, at 10:24 AM, "Graham Scrowther"<[email protected]= rg> wrote: > > > >> I didn't get anything either. > >> > >> Could you please post the message you got? > >> > >> > >> > >> -----Original Message----- > >> From: [email protected] [mailto:listbounce@securityfoc= us.com] On Behalf Of Sandeep Cheema > >> Sent: 17 January 2011 14:25 > >> To: Jay Scalf ; [email protected] > >> Subject: Re: Malware database > >> > >> That's odd. Seriously. I thought all securityfocus mailing lists = are manually filtered. Strange I didn't receive that. > >> > >> Regards, Sandeep > >> Sent from BlackBerry=AE on Airtel > >> > >> -----Original Message----- > >> From: Jay Scalf<[email protected]> > >> Date: Mon, 17 Jan 2011 14:08:50 > >> To:<[email protected]> > >> Subject: Re: Malware database > >> > >> This is to notify all that I received a message regarding my supp= osed > >> request of Mastercard via this list. I do no have a Mastercard. E= veryone > >> beware. If this happens again I will request to be removed form t= he list > >> even though everyone seems knowledgeable and I appreciate reading= your > >> views. > >> > >> On 1/14/2011 3:23 PM, David H. Lipman wrote: > >>> I agree with this assertion. > >>> > >>> Malware encyclopedias are NOT what they used to be 7~10 years ag= o. > >>> > >>> New variants of malware are created daily and often hourly. So = often that encyclopedias (librariies) just can't be > >>> kept up to date. > >>> > >>> At best we can talk about families such as MEBRoot, TDSS (TDL3, = TDL4, etc), ZBot, Gromozon, FakeAV, > >>> FakeAlert, yada, yada. And in that we can have generalities abo= ut how the malware conducts itself and what > >>> changes it makes to the OS. > >>> > >>> As for ThreatExpert. It is just OK. I use it but, I find that = data colleected is often incomplete. Especially in light > >>> of the AntiVM routines of much of the malware I see. ANUBIS the= same and it can't handle .NET files. COMODO > >>> is limited and supplies very little information. The University= of Manaheim's sandbox is very good but it is > >>> presently down and won't be back up until the third or 4th week = of this month. Stefan B. has an excellent system > >>> but it is underfunded and underpowered and I am afraid if I ment= ion his system you will all use it and it will get > >>> overloaded and it'll take days to get reports returned. > >>> > >>> We return back to the original question about 'srvpool.exe'. > >>> > >>> Google is ONLY good to tell you if it is a known process. Howev= er, any file can be named anything. It isn't > >>> enough to know the name of the file but the fully qualified name= and path to the file. > >>> > >>> We know SVCHOST.EXE is a legitimate process. > >>> Not if it is loaded from %appdata%. > >>> > >>> Malware deliberately hides itsalf in names of legitimate files o= r slight variation thereof. > >>> SVCHOST.EXE is the most prevalent of names forged or use variati= ons like SCVHOST.EXE or LSASS.EXE as > >>> Isass.exe. Here we have 'srvpool.exe' which is a take on 'spool= sv.exe' the Print Spooler Service. The problem is > >>> any file can be called anything and the libraries are just not a= ble to keep up with all the new malware. > >>> > >>> > >>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this. = :-) > >>> > >>> Dave > >>> > >>> > >>> > >>> > >>> Date forwarded: Fri, 14 Jan 2011 09:26:47 -0700 (MST) > >>> Date sent: Fri, 14 Jan 2011 11:24:33 -0500 (EST) > >>> Forwarded by: [email protected] > >>> From: Jose Nazario<[email protected]> > >>> Subject: Re: Malware database > >>> To: Huffen Doback<[email protected]> > >>> Copies to: [email protected], focus-vir= [email protected] > >>> > >>>> virus names used to be unique, but not so much any more. > >>>> > >>>> prevx, for example, lets you search by filename. plenty of site= s have nice > >>>> writeups of "what is file foo.exe and what does it do?" for leg= itimate > >>>> files. prevx mostly handles malicious files, and their writeups= are vague > >>>> or misleading at best in that database. > >>>> > >>>> as for fine grained details sandbox reports are very useful. > >>>> threatexpert.com is one of the more comprehensive and searchabl= e. if you > >>>> have a file hash (md5) that's the best way to get such details. > >>>> > >>>> virustotal.com is also a useful place to get pointers. > >>>> > >>>> i do not trust or respect most AV writeups, they're very inadeq= uate or > >>>> just plain wrong. > >>>> > >>>>________ > >>>> jose nazario, ph.d. http://monkey.org/~jose/ > >>>> > >>>> > >>>> ---------------------------------------------------------------= ------------ > >>>> This list is sponsored by: Black Hat > >>>> > >>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world'= s premier > >>>> technical event for ICT security experts. Featuring 30 hands-on= training > >>>> courses and 90 Briefings presentations with lots of new content= and new > >>>> tools. Network with 4,000 delegates from 70 nations. Visit pr= oduct > >>>> displays by 30 top sponsors in a relaxed setting. > >>>> > >>>> http://www.blackhat.com > >>>> ---------------------------------------------------------------= ------------ > >>>> > >>> > >>> > >>> -- > >>> > >>> Mr. David H. Lipman > >>> [email protected] > >>> Yahoo IM: david_h_lipman > >>> > >>> > >>> > >>> ----------------------------------------------------------------= ----------- > >>> This list is sponsored by: Black Hat > >>> > >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's= premier > >>> technical event for ICT security experts. Featuring 30 hands-on = training > >>> courses and 90 Briefings presentations with lots of new content = and new > >>> tools. Network with 4,000 delegates from 70 nations. Visit pro= duct > >>> displays by 30 top sponsors in a relaxed setting. > >>> > >>> http://www.blackhat.com > >>> ----------------------------------------------------------------= ----------- > >>> > >>> > >> -----------------------------------------------------------------= ---------- > >> This list is sponsored by: Black Hat > >> > >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's = premier > >> technical event for ICT security experts. Featuring 30 hands-on t= raining > >> courses and 90 Briefings presentations with lots of new content a= nd new > >> tools. Network with 4,000 delegates from 70 nations. Visit prod= uct > >> displays by 30 top sponsors in a relaxed setting. > >> > >> http://www.blackhat.com > >> -----------------------------------------------------------------= ---------- > >> > >> -----------------------------------------------------------------= ---------- > >> This list is sponsored by: Black Hat > >> > >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's = premier > >> technical event for ICT security experts. Featuring 30 hands-on t= raining > >> courses and 90 Briefings presentations with lots of new content a= nd new > >> tools. Network with 4,000 delegates from 70 nations. Visit prod= uct > >> displays by 30 top sponsors in a relaxed setting. > >> > >> http://www.blackhat.com > >> -----------------------------------------------------------------= ---------- > >> > >> > >> -----------------------------------------------------------------= ---------- > >> This list is sponsored by: Black Hat > >> > >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's = premier > >> technical event for ICT security experts. Featuring 30 hands-on t= raining > >> courses and 90 Briefings presentations with lots of new content a= nd new > >> tools. Network with 4,000 delegates from 70 nations. Visit prod= uct > >> displays by 30 top sponsors in a relaxed setting. > >> > >> http://www.blackhat.com > >> -----------------------------------------------------------------= ---------- > >> > -------------------------------------------------------------------------= -- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20 technical event for ICT security experts. Featuring 30 hands-on training=20 courses and 90 Briefings presentations with lots of new content and new=20 tools. Network with 4,000 delegates from 70 nations. Visit product=20 displays by 30 top sponsors in a relaxed setting. =20 http://www.blackhat.com -------------------------------------------------------------------------= --