Re: Malware database
Adrian J Milanoski <[email protected]> Mon, 17 Jan 2011 13:09:17 -0500
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
I wasn't implying to use VirusTotal as a testing solution, but merely suggesting it to gather information on the suspected malware. Alternatively, the information you just provided about virustotal is in fact interesting and I will read your blog for further information. I looked a little further back regarding others posts and found trendmicro DB, threatexpert.com. Thanks for the heads up. - A On Mon, Jan 17, 2011 at 12:38 PM, Jay Scalf <[email protected]> wrote: > From VirusTotal Website: > > "Why using VirusTotal for antivirus testing is a bad idea? > > Hispasec is rather tired of repeating that VirusTotal was not designed as= a > tool to perform AV comparative analyses, but as a tool that checks > suspicious samples with several AV programs and helps AV labs by forwardi= ng > them the malware they failed to detect. Those who use VirusTotal to perfo= rm > AV comparative analyses should know that they are making many implicit > errors in the methodology, the most obvious being: > > VirusTotal AV engines are commandline versions, so depending on the produ= ct, > they will not behave exactly the same as the desktop versions: for instan= ce, > desktop solutions may use techniques based on behavioral analysis and cou= nt > with personal firewalls that may decrease entry points and mitigate > propagation, etc. > In VirusTotal desktop-oriented solutions coexist with perimeter-oriented > solutions; heuristics in this latter group may be more aggressive and > paranoid, since the impact of false positives is less visible in the > perimeter. It is simply not fair to compare both groups. > > These are just two examples illustrating why using VirusTotal for antivir= us > testing is a bad idea, you can read more about this issue in our blog. Th= e > Prevx team also made an entry in its blog discussing the matter." > > Jay > > > On 1/17/2011 10:35 AM, Adrian J Milanoski wrote: > > Take a look at www.virustotal.com you can search hashes, names, etc... > > > - > A > > On Mon, Jan 17, 2011 at 11:09 AM, Jay Scalf <[email protected]> wrote: > > This is what I am getting: > > Your request for support has been received. Your service request referenc= e > number is contained in this email. Please note that email should not be > used for urgent requests. For issues requiring immediate attention, pleas= e > contact the Information Security HelpDesk at x26122 to speak with a > representative. > > Please retain this notification until such time as your request is > resolved. =A0Inquiries about this message should include the SRQ# in the > subject so all activities and efforts will be tracked and recorded within > the ticket. > > Service Request Reference Number: SRQ506868 > Date Opened: 2011-01-17 08:51:39 > Service Request Description: > Re: Malware database > > Thank you. > > > > CONFIDENTIALITY NOTICE > This e-mail message and any attachments are only for the use of the inten= ded > recipient and may contain information that is privileged, confidential or > exempt from disclosure under applicable law. If you are not the intended > recipient, any disclosure, distribution or other use of this e-mail messa= ge > or attachments is prohibited. If you have received this e-mail message in > error, please delete and notify the sender immediately. Thank you. > > > On 1/17/2011 9:24 AM, Martin, Kelly J. wrote: > > How do I get off this list? > > Sent from my iPhone > > On Jan 17, 2011, at 10:24 AM, "Graham Scrowther"<[email protected]> > =A0wrote: > > I didn't get anything either. > > Could you please post the message you got? > > > > -----Original Message----- > From: [email protected] [mailto:[email protected]] > On Behalf Of Sandeep Cheema > Sent: 17 January 2011 14:25 > To: Jay Scalf ; [email protected] > Subject: Re: Malware database > > That's odd. Seriously. I thought all securityfocus mailing lists are > manually filtered. Strange I didn't receive that. > > Regards, Sandeep > Sent from BlackBerry=AE on Airtel > > -----Original Message----- > From: Jay Scalf<[email protected]> > Date: Mon, 17 Jan 2011 14:08:50 > To:<[email protected]> > Subject: Re: Malware database > > This is to notify all that I received a message regarding my supposed > request of Mastercard via this list. I do no have a Mastercard. Everyone > beware. If this happens again I will request to be removed form the list > even though everyone seems knowledgeable and I appreciate reading your > views. > > On 1/14/2011 3:23 PM, David H. Lipman wrote: > > I agree with this assertion. > > Malware encyclopedias are NOT what they used to be 7~10 years ago. > > New variants of malware are created daily and often hourly. =A0So often > that encyclopedias (librariies) just can't be > kept up to date. > > At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, > etc), ZBot, Gromozon, FakeAV, > FakeAlert, yada, yada. =A0And in that we can have generalities about how > the malware conducts itself and what > changes it makes to the OS. > > As for ThreatExpert. =A0It is just OK. =A0I use it but, I find that data > colleected is often incomplete. =A0Especially in light > of the AntiVM routines of much of the malware I see. =A0ANUBIS the same > and it can't handle .NET files. =A0COMODO > is limited and supplies very little information. =A0The University of > Manaheim's sandbox is very good but it is > presently down and won't be back up until the third or 4th week of this > month. =A0Stefan B. has an excellent system > but it is underfunded and underpowered and I am afraid if I mention his > system you will all use it and it will get > overloaded and it'll take days to get reports returned. > > We return back to the original question about 'srvpool.exe'. > > Google is ONLY good to tell you if it is a known process. =A0However, any > file can be named anything. =A0It isn't > enough to know the name of the file but the fully qualified name and > path to the file. > > We know SVCHOST.EXE is a legitimate process. > Not if it is loaded from %appdata%. > > Malware deliberately hides itsalf in names of legitimate files or slight > variation thereof. > SVCHOST.EXE is the most prevalent of names forged or use variations like > SCVHOST.EXE or LSASS.EXE as > Isass.exe. =A0Here we have 'srvpool.exe' which is a take on 'spoolsv.exe' > the Print Spooler Service. =A0The problem is > any file can be called anything and the libraries are just not able to > keep up with all the new malware. > > > Get me a sample of 'spoolsv.exe' and I'll get the 411 on this. =A0:-) > > Dave > > > > > Date forwarded: =A0 =A0 =A0 =A0Fri, 14 Jan 2011 09:26:47 -0700 (MST) > Date sent: =A0 =A0 =A0 =A0 =A0 =A0 Fri, 14 Jan 2011 11:24:33 -0500 (EST) > Forwarded by: =A0 =A0 =A0 =A0 [email protected]= m > From: =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Jose Nazario<[email protected]> > Subject: =A0 =A0 =A0 =A0 =A0 =A0 =A0 Re: Malware database > To: =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Huffen Doback<huffen.doback@gm= ail.com> > Copies to: =A0 =A0 =A0 =A0 =A0 =A0 [email protected], > [email protected] > > virus names used to be unique, but not so much any more. > > prevx, for example, lets you search by filename. plenty of sites have > nice > writeups of "what is file foo.exe and what does it do?" for legitimate > files. prevx mostly handles malicious files, and their writeups are > vague > or misleading at best in that database. > > as for fine grained details sandbox reports are very useful. > threatexpert.com is one of the more comprehensive and searchable. if > you > have a file hash (md5) that's the best way to get such details. > > virustotal.com is also a useful place to get pointers. > > i do not trust or respect most AV writeups, they're very inadequate or > just plain wrong. > > ________ > jose nazario, ph.d. =A0 =A0 =A0 =A0 =A0 =A0 =A0http://monkey.org/~jose/ > > > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's > premier > technical event for ICT security experts. Featuring 30 hands-on > training > courses and 90 Briefings presentations with lots of new content and new > tools. =A0Network with 4,000 delegates from 70 nations. =A0Visit product > displays by 30 top sponsors in a relaxed setting. > > http://www.blackhat.com > > -------------------------------------------------------------------------= -- > > > -- > > =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 Mr. D= avid H. Lipman > =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 DLipm= [email protected] > =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Yahoo IM: = =A0david_h_lipman > > > > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > technical event for ICT security experts. Featuring 30 hands-on training > courses and 90 Briefings presentations with lots of new content and new > tools. =A0Network with 4,000 delegates from 70 nations. =A0Visit product > displays by 30 top sponsors in a relaxed setting. > > http://www.blackhat.com > > -------------------------------------------------------------------------= -- > > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > technical event for ICT security experts. Featuring 30 hands-on training > courses and 90 Briefings presentations with lots of new content and new > tools. =A0Network with 4,000 delegates from 70 nations. =A0Visit product > displays by 30 top sponsors in a relaxed setting. > > http://www.blackhat.com > > -------------------------------------------------------------------------= -- > > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > technical event for ICT security experts. Featuring 30 hands-on training > courses and 90 Briefings presentations with lots of new content and new > tools. =A0Network with 4,000 delegates from 70 nations. =A0Visit product > displays by 30 top sponsors in a relaxed setting. > > http://www.blackhat.com > > -------------------------------------------------------------------------= -- > > > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > technical event for ICT security experts. Featuring 30 hands-on training > courses and 90 Briefings presentations with lots of new content and new > tools. =A0Network with 4,000 delegates from 70 nations. =A0Visit product > displays by 30 top sponsors in a relaxed setting. > > http://www.blackhat.com > > -------------------------------------------------------------------------= -- > > -------------------------------------------------------------------------= -- > This list is sponsored by: Black Hat > > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > technical event for ICT security experts. Featuring 30 hands-on training > courses and 90 Briefings presentations with lots of new content and new > tools. =A0Network with 4,000 delegates from 70 nations. =A0Visit product > displays by 30 top sponsors in a relaxed setting. > http://www.blackhat.com > -------------------------------------------------------------------------= -- > > > --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------