Re: Malware database
"wt521125" <[email protected]> Tue, 1 Mar 2011 14:43:25 +0800
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <3BA5FAA9F70146FB81A5A9C0AABE4AEF@PC2010113008SBG> |
virus names used to be unique, but not so much any more. prevx, for example, lets you search by filename. plenty of sites have nice writeups of "what is file foo.exe and what does it do?" for legitimate files. prevx mostly handles malicious files, and their writeups are vague or misleading at best in that database. as for fine grained details sandbox reports are very useful. threatexpert.com is one of the more comprehensive and searchable. if you have a file hash (md5) that's the best way to get such details. virustotal.com is also a useful place to get pointers. i do not trust or respect most AV writeups, they're very inadequate or just plain wrong. ________ jose nazario, ph.d. http://monkey.org/~jose/ --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com --------------------------------------------------------------------------- __________________________________________________ ¸Ï¿ì×¢²áÑÅ»¢³¬´óÈÝÁ¿Ãâ·ÑÓÊÏä? http://cn.mail.yahoo.com --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------