Re: Malware database
"wt521125" <[email protected]> Tue, 1 Mar 2011 14:43:25 +0800
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <7E71DCB62BB14451A787494D94AF4A9F@PC2010113008SBG> |
I see what you mean. That's very interesting. So a bad guy can = eventually sign up on mailing lists and get genuine email addresses for spamming. = Not to mention it's a cakewalk to automate the entire process. Baah. And = that's exactly what's happening. It's true that cached threads mask the email = but what about this communication happening right here? Suggest it should be taken up in a different thread with the admins being involved. It's = little disturbing. Though the spam cannot be directed to the list since it's moderated but direct spam to email is possible. Thanks for bringing it = to attention, I certainly dis forget basics :-) Regards, Sandeep=20 Sent from BlackBerry=AE on Airtel -----Original Message----- From: Jay Scalf <[email protected]> Date: Mon, 17 Jan 2011 16:09:04=20 To: <[email protected]> Cc: <[email protected]>; <[email protected]>; = <[email protected]> Subject: Re: Malware database This is what I am getting: =20 Your request for support has been received. Your service request = reference number is contained in this email. Please note that email should not be used for urgent requests. For issues requiring immediate attention, = please contact the Information Security HelpDesk at x26122 to speak with a representative. =20 Please retain this notification until such time as your request is resolved.=A0 Inquiries about this message should include the SRQ# in = the subject so all activities and efforts will be tracked and recorded = within the ticket. =20 Service Request Reference Number: SRQ506868 Date Opened: 2011-01-17 08:51:39 Service Request Description: Re: Malware database =20 Thank you. =20 =20 =20 CONFIDENTIALITY NOTICE This e-mail message and any attachments are only for the use of the=20 intended recipient and may contain information that is privileged,=20 confidential or exempt from disclosure under applicable law. If you are = not the intended recipient, any disclosure, distribution or other use = of=20 this e-mail message or attachments is prohibited. If you have received=20 this e-mail message in error, please delete and notify the sender=20 immediately. Thank you. =20 =20 On 1/17/2011 9:24 AM, Martin, Kelly J. wrote: > How do I get off this list? > > Sent from my iPhone > > On Jan 17, 2011, at 10:24 AM, "Graham = Scrowther"<[email protected]>=A0 wrote: > >> I didn't get anything either. >> >> Could you please post the message you got? >> >> >> >> -----Original Message----- >> From: [email protected] = [mailto:[email protected]] On Behalf Of Sandeep Cheema >> Sent: 17 January 2011 14:25 >> To: Jay Scalf ; [email protected] >> Subject: Re: Malware database >> >> That's odd. Seriously. I thought all securityfocus mailing lists are manually filtered. Strange I didn't receive that. >> >> Regards, Sandeep >> Sent from BlackBerry=AE on Airtel >> >> -----Original Message----- >> From: Jay Scalf<[email protected]> >> Date: Mon, 17 Jan 2011 14:08:50 >> To:<[email protected]> >> Subject: Re: Malware database >> >> This is to notify all that I received a message regarding my = supposed >> request of Mastercard via this list. I do no have a Mastercard. = Everyone >> beware. If this happens again I will request to be removed form the = list >> even though everyone seems knowledgeable and I appreciate reading = your >> views. >> >> On 1/14/2011 3:23 PM, David H. Lipman wrote: >>> I agree with this assertion. >>> >>> Malware encyclopedias are NOT what they used to be 7~10 years ago. >>> >>> New variants of malware are created daily and often hourly.=A0 So = often that encyclopedias (librariies) just can't be >>> kept up to date. >>> >>> At best we can talk about families such as MEBRoot, TDSS (TDL3, = TDL4, etc), ZBot, Gromozon, FakeAV, >>> FakeAlert, yada, yada.=A0 And in that we can have generalities = about how the malware conducts itself and what >>> changes it makes to the OS. >>> >>> As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that = data colleected is often incomplete.=A0 Especially in light >>> of the AntiVM routines of much of the malware I see.=A0 ANUBIS the = same and it can't handle .NET files.=A0 COMODO >>> is limited and supplies very little information.=A0 The University = of Manaheim's sandbox is very good but it is >>> presently down and won't be back up until the third or 4th week of = this month.=A0 Stefan B. has an excellent system >>> but it is underfunded and underpowered and I am afraid if I mention = his system you will all use it and it will get >>> overloaded and it'll take days to get reports returned. >>> >>> We return back to the original question about 'srvpool.exe'. >>> >>> Google is ONLY good to tell you if it is a known process.=A0 = However, any file can be named anything.=A0 It isn't >>> enough to know the name of the file but the fully qualified name = and path to the file. >>> >>> We know SVCHOST.EXE is a legitimate process. >>> Not if it is loaded from %appdata%. >>> >>> Malware deliberately hides itsalf in names of legitimate files or slight variation thereof. >>> SVCHOST.EXE is the most prevalent of names forged or use variations like SCVHOST.EXE or LSASS.EXE as >>> Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on = 'spoolsv.exe' the Print Spooler Service.=A0 The problem is >>> any file can be called anything and the libraries are just not able = to keep up with all the new malware. >>> >>> >>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 = :-) >>> >>> Dave >>> >>> >>> >>> >>> Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 = -0700 (MST) >>> Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 = 11:24:33 -0500 (EST) >>> Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 = [email protected] >>> From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose = Nazario<[email protected]> >>> Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware = database >>> To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen = Doback<[email protected]> >>> Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 = [email protected],=A0 [email protected] >>> >>>> virus names used to be unique, but not so much any more. >>>> >>>> prevx, for example, lets you search by filename. plenty of sites = have nice >>>> writeups of "what is file foo.exe and what does it do?" for = legitimate >>>> files. prevx mostly handles malicious files, and their writeups = are vague >>>> or misleading at best in that database. >>>> >>>> as for fine grained details sandbox reports are very useful. >>>> threatexpert.com is one of the more comprehensive and searchable. = if you >>>> have a file hash (md5) that's the best way to get such details. >>>> >>>> virustotal.com is also a useful place to get pointers. >>>> >>>> i do not trust or respect most AV writeups, they're very = inadequate or >>>> just plain wrong. >>>> >>>>________ >>>> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 = http://monkey.org/~jose/ >>>> >>>> >>>> -------------------------------------------------------------------------= -- >>>> This list is sponsored by: Black Hat >>>> >>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier >>>> technical event for ICT security experts. Featuring 30 hands-on training >>>> courses and 90 Briefings presentations with lots of new content = and new >>>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit = product >>>> displays by 30 top sponsors in a relaxed setting. >>>> >>>> http://www.blackhat.com >>>> -------------------------------------------------------------------------= -- >>>> >>> >>> >>> -- >>> = >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman = >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected] = >>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman >>> >>> >>> >>> -------------------------------------------------------------------------= -- >>> This list is sponsored by: Black Hat >>> >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier >>> technical event for ICT security experts. Featuring 30 hands-on training >>> courses and 90 Briefings presentations with lots of new content and = new >>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit = product >>> displays by 30 top sponsors in a relaxed setting. >>> >>> http://www.blackhat.com >>> -------------------------------------------------------------------------= -- >>> >>> >> -------------------------------------------------------------------------= -- >> This list is sponsored by: Black Hat >> >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's = premier >> technical event for ICT security experts. Featuring 30 hands-on = training >> courses and 90 Briefings presentations with lots of new content and = new >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit = product >> displays by 30 top sponsors in a relaxed setting. >> >> http://www.blackhat.com >> -------------------------------------------------------------------------= -- >> >> -------------------------------------------------------------------------= -- >> This list is sponsored by: Black Hat >> >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's = premier >> technical event for ICT security experts. Featuring 30 hands-on = training >> courses and 90 Briefings presentations with lots of new content and = new >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit = product >> displays by 30 top sponsors in a relaxed setting. >> >> http://www.blackhat.com >> -------------------------------------------------------------------------= -- >> >> >> -------------------------------------------------------------------------= -- >> This list is sponsored by: Black Hat >> >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's = premier >> technical event for ICT security experts. Featuring 30 hands-on = training >> courses and 90 Briefings presentations with lots of new content and = new >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit = product >> displays by 30 top sponsors in a relaxed setting. >> >> http://www.blackhat.com >> -------------------------------------------------------------------------= -- >> -------------------------------------------------------------------------= -- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier = technical event for ICT security experts. Featuring 30 hands-on training = courses and 90 Briefings presentations with lots of new content and new=20 tools. Network with 4,000 delegates from 70 nations. Visit product=20 displays by 30 top sponsors in a relaxed setting. =20 http://www.blackhat.com -------------------------------------------------------------------------= -- __________________________________________________ žÏ¿ì×¢²áÑÅ»¢³¬ŽóÈÝÁ¿Ãâ·ÑÓÊÏä? http://cn.mail.yahoo.com --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------