Re: Malware database
"wt521125" <[email protected]> Tue, 1 Mar 2011 14:43:25 +0800
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Organization | James F. Scalf & Associates, Architects, AIA |
| Message-ID | <E3D09F43481943109C8BC4393B263DD0@PC2010113008SBG> |
Sandeep, I have spent all morning in chat with Comcast and the only way to=20 block it from going both to my Thunderbird in laptop and Blackberry is=20 to mark as spam individually on-line with Comcast's e-mail. Time=20 consuming but hopefully effective. I'll let you know. Jay On 1/17/2011 10:31 AM, Sandeep Cheema wrote: > I see what you mean. That's very interesting. So a bad guy can = eventually sign up on mailing lists and get genuine email addresses for spamming. = Not to mention it's a cakewalk to automate the entire process. Baah. And = that's exactly what's happening. It's true that cached threads mask the email = but what about this communication happening right here? Suggest it should be taken up in a different thread with the admins being involved. It's = little disturbing. Though the spam cannot be directed to the list since it's moderated but direct spam to email is possible. Thanks for bringing it = to attention, I certainly dis forget basics :-) > > Regards, Sandeep > Sent from BlackBerry=AE on Airtel > > -----Original Message----- > From: Jay Scalf<[email protected]> > Date: Mon, 17 Jan 2011 16:09:04 > To:<[email protected]> > = Cc:<[email protected]>;<[email protected]>;<[email protected]>= > Subject: Re: Malware database > > This is what I am getting: > > Your request for support has been received. Your service request reference > number is contained in this email. Please note that email should not = be > used for urgent requests. For issues requiring immediate attention, please > contact the Information Security HelpDesk at x26122 to speak with a > representative. > > Please retain this notification until such time as your request is > resolved. Inquiries about this message should include the SRQ# in = the > subject so all activities and efforts will be tracked and recorded within > the ticket. > > Service Request Reference Number: SRQ506868 > Date Opened: 2011-01-17 08:51:39 > Service Request Description: > Re: Malware database > > Thank you. > > > > CONFIDENTIALITY NOTICE > This e-mail message and any attachments are only for the use of the > intended recipient and may contain information that is privileged, > confidential or exempt from disclosure under applicable law. If you = are > not the intended recipient, any disclosure, distribution or other = use of > this e-mail message or attachments is prohibited. If you have = received > this e-mail message in error, please delete and notify the sender > immediately. Thank you. > > > On 1/17/2011 9:24 AM, Martin, Kelly J. wrote: > > How do I get off this list? > > > > Sent from my iPhone > > > > On Jan 17, 2011, at 10:24 AM, "Graham = Scrowther"<[email protected]> wrote: > > > >> I didn't get anything either. > >> > >> Could you please post the message you got? > >> > >> > >> > >> -----Original Message----- > >> From: [email protected] [mailto:[email protected]] On Behalf Of Sandeep Cheema > >> Sent: 17 January 2011 14:25 > >> To: Jay Scalf ; [email protected] > >> Subject: Re: Malware database > >> > >> That's odd. Seriously. I thought all securityfocus mailing lists = are manually filtered. Strange I didn't receive that. > >> > >> Regards, Sandeep > >> Sent from BlackBerry=AE on Airtel > >> > >> -----Original Message----- > >> From: Jay Scalf<[email protected]> > >> Date: Mon, 17 Jan 2011 14:08:50 > >> To:<[email protected]> > >> Subject: Re: Malware database > >> > >> This is to notify all that I received a message regarding my supposed > >> request of Mastercard via this list. I do no have a Mastercard. Everyone > >> beware. If this happens again I will request to be removed form = the list > >> even though everyone seems knowledgeable and I appreciate = reading your > >> views. > >> > >> On 1/14/2011 3:23 PM, David H. Lipman wrote: > >>> I agree with this assertion. > >>> > >>> Malware encyclopedias are NOT what they used to be 7~10 years = ago. > >>> > >>> New variants of malware are created daily and often hourly. So often that encyclopedias (librariies) just can't be > >>> kept up to date. > >>> > >>> At best we can talk about families such as MEBRoot, TDSS (TDL3, TDL4, etc), ZBot, Gromozon, FakeAV, > >>> FakeAlert, yada, yada. And in that we can have generalities = about how the malware conducts itself and what > >>> changes it makes to the OS. > >>> > >>> As for ThreatExpert. It is just OK. I use it but, I find that data colleected is often incomplete. Especially in light > >>> of the AntiVM routines of much of the malware I see. ANUBIS = the same and it can't handle .NET files. COMODO > >>> is limited and supplies very little information. The = University of Manaheim's sandbox is very good but it is > >>> presently down and won't be back up until the third or 4th week = of this month. Stefan B. has an excellent system > >>> but it is underfunded and underpowered and I am afraid if I = mention his system you will all use it and it will get > >>> overloaded and it'll take days to get reports returned. > >>> > >>> We return back to the original question about 'srvpool.exe'. > >>> > >>> Google is ONLY good to tell you if it is a known process. = However, any file can be named anything. It isn't > >>> enough to know the name of the file but the fully qualified = name and path to the file. > >>> > >>> We know SVCHOST.EXE is a legitimate process. > >>> Not if it is loaded from %appdata%. > >>> > >>> Malware deliberately hides itsalf in names of legitimate files = or slight variation thereof. > >>> SVCHOST.EXE is the most prevalent of names forged or use = variations like SCVHOST.EXE or LSASS.EXE as > >>> Isass.exe. Here we have 'srvpool.exe' which is a take on 'spoolsv.exe' the Print Spooler Service. The problem is > >>> any file can be called anything and the libraries are just not = able to keep up with all the new malware. > >>> > >>> > >>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this. = :-) > >>> > >>> Dave > >>> > >>> > >>> > >>> > >>> Date forwarded: Fri, 14 Jan 2011 09:26:47 -0700 (MST) > >>> Date sent: Fri, 14 Jan 2011 11:24:33 -0500 (EST) > >>> Forwarded by: = [email protected] > >>> From: Jose Nazario<[email protected]> > >>> Subject: Re: Malware database > >>> To: Huffen Doback<[email protected]> > >>> Copies to: [email protected], [email protected] > >>> > >>>> virus names used to be unique, but not so much any more. > >>>> > >>>> prevx, for example, lets you search by filename. plenty of = sites have nice > >>>> writeups of "what is file foo.exe and what does it do?" for legitimate > >>>> files. prevx mostly handles malicious files, and their = writeups are vague > >>>> or misleading at best in that database. > >>>> > >>>> as for fine grained details sandbox reports are very useful. > >>>> threatexpert.com is one of the more comprehensive and = searchable. if you > >>>> have a file hash (md5) that's the best way to get such = details. > >>>> > >>>> virustotal.com is also a useful place to get pointers. > >>>> > >>>> i do not trust or respect most AV writeups, they're very inadequate or > >>>> just plain wrong. > >>>> > >>>>________ > >>>> jose nazario, ph.d. http://monkey.org/~jose/ > >>>> > >>>> > >>>> -------------------------------------------------------------------------= -- > >>>> This list is sponsored by: Black Hat > >>>> > >>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the = world's premier > >>>> technical event for ICT security experts. Featuring 30 = hands-on training > >>>> courses and 90 Briefings presentations with lots of new = content and new > >>>> tools. Network with 4,000 delegates from 70 nations. Visit product > >>>> displays by 30 top sponsors in a relaxed setting. > >>>> > >>>> http://www.blackhat.com > >>>> -------------------------------------------------------------------------= -- > >>>> > >>> > >>> > >>> -- > >>> > >>> Mr. David H. Lipman > >>> [email protected] > >>> Yahoo IM: david_h_lipman > >>> > >>> > >>> > >>> -------------------------------------------------------------------------= -- > >>> This list is sponsored by: Black Hat > >>> > >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the = world's premier > >>> technical event for ICT security experts. Featuring 30 hands-on training > >>> courses and 90 Briefings presentations with lots of new content = and new > >>> tools. Network with 4,000 delegates from 70 nations. Visit product > >>> displays by 30 top sponsors in a relaxed setting. > >>> > >>> http://www.blackhat.com > >>> -------------------------------------------------------------------------= -- > >>> > >>> > >> -------------------------------------------------------------------------= -- > >> This list is sponsored by: Black Hat > >> > >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > >> technical event for ICT security experts. Featuring 30 hands-on training > >> courses and 90 Briefings presentations with lots of new content = and new > >> tools. Network with 4,000 delegates from 70 nations. Visit = product > >> displays by 30 top sponsors in a relaxed setting. > >> > >> http://www.blackhat.com > >> -------------------------------------------------------------------------= -- > >> > >> -------------------------------------------------------------------------= -- > >> This list is sponsored by: Black Hat > >> > >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > >> technical event for ICT security experts. Featuring 30 hands-on training > >> courses and 90 Briefings presentations with lots of new content = and new > >> tools. Network with 4,000 delegates from 70 nations. Visit = product > >> displays by 30 top sponsors in a relaxed setting. > >> > >> http://www.blackhat.com > >> -------------------------------------------------------------------------= -- > >> > >> > >> -------------------------------------------------------------------------= -- > >> This list is sponsored by: Black Hat > >> > >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier > >> technical event for ICT security experts. Featuring 30 hands-on training > >> courses and 90 Briefings presentations with lots of new content = and new > >> tools. Network with 4,000 delegates from 70 nations. Visit = product > >> displays by 30 top sponsors in a relaxed setting. > >> > >> http://www.blackhat.com > >> -------------------------------------------------------------------------= -- > >> > -------------------------------------------------------------------------= -- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier = technical event for ICT security experts. Featuring 30 hands-on training = courses and 90 Briefings presentations with lots of new content and new=20 tools. Network with 4,000 delegates from 70 nations. Visit product=20 displays by 30 top sponsors in a relaxed setting. =20 http://www.blackhat.com -------------------------------------------------------------------------= -- __________________________________________________ žÏ¿ì×¢²áÑÅ»¢³¬ŽóÈÝÁ¿Ãâ·ÑÓÊÏä? http://cn.mail.yahoo.com --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------