Re: Malware database

"wt521125" <[email protected]> Tue, 1 Mar 2011 14:43:25 +0800
Newsgroups gmane.comp.security.virus
Message-ID <7E71DCB62BB14451A787494D94AF4A9F@PC2010113008SBG>
I see what you mean. That's very interesting. So a bad guy can =
eventually
sign up on mailing lists and get genuine email addresses for spamming. =
Not
to mention it's a cakewalk to automate the entire process. Baah. And =
that's
exactly what's happening. It's true that cached threads mask the email =
but
what about this communication happening right here? Suggest it should be
taken up in a different thread with the admins being involved. It's =
little
disturbing. Though the spam cannot be directed to the list since it's
moderated but direct spam to email is possible. Thanks for bringing it =
to
attention, I certainly dis forget basics :-)

Regards, Sandeep=20
Sent from BlackBerry=AE on Airtel

-----Original Message-----
From: Jay Scalf <[email protected]>
Date: Mon, 17 Jan 2011 16:09:04=20
To: <[email protected]>
Cc: <[email protected]>; <[email protected]>; =
<[email protected]>
Subject: Re: Malware database

This is what I am getting:
=20
 Your request for support has been received. Your service request =
reference
 number is contained in this email. Please note that email should not be
 used for urgent requests. For issues requiring immediate attention, =
please
 contact the Information Security HelpDesk at x26122 to speak with a
 representative.
=20
 Please retain this notification until such time as your request is
 resolved.=A0 Inquiries about this message should include the SRQ# in =
the
 subject so all activities and efforts will be tracked and recorded =
within
 the ticket.
=20
 Service Request Reference Number: SRQ506868
 Date Opened: 2011-01-17 08:51:39
 Service Request Description:
 Re: Malware database
=20
 Thank you.
=20
=20
=20
 CONFIDENTIALITY NOTICE
 This e-mail message and any attachments are only for the use of the=20
 intended recipient and may contain information that is privileged,=20
 confidential or exempt from disclosure under applicable law. If you are =

 not the intended recipient, any disclosure, distribution or other use =
of=20
 this e-mail message or attachments is prohibited. If you have received=20
 this e-mail message in error, please delete and notify the sender=20
 immediately. Thank you.
=20
=20
 On 1/17/2011 9:24 AM, Martin, Kelly J. wrote:
 > How do I get off this list?
 >
 > Sent from my iPhone
 >
 > On Jan 17, 2011, at 10:24 AM, "Graham =
Scrowther"<[email protected]>=A0
wrote:
 >
 >> I didn't get anything either.
 >>
 >> Could you please post the message you got?
 >>
 >>
 >>
 >> -----Original Message-----
 >> From: [email protected] =
[mailto:[email protected]]
On Behalf Of Sandeep Cheema
 >> Sent: 17 January 2011 14:25
 >> To: Jay Scalf ; [email protected]
 >> Subject: Re: Malware database
 >>
 >> That's odd. Seriously. I thought all securityfocus mailing lists are
manually filtered. Strange I didn't receive that.
 >>
 >> Regards, Sandeep
 >> Sent from BlackBerry=AE on Airtel
 >>
 >> -----Original Message-----
 >> From: Jay Scalf<[email protected]>
 >> Date: Mon, 17 Jan 2011 14:08:50
 >> To:<[email protected]>
 >> Subject: Re: Malware database
 >>
 >> This is to notify all that I received a message regarding my =
supposed
 >> request of Mastercard via this list. I do no have a Mastercard. =
Everyone
 >> beware. If this happens again I will request to be removed form the =
list
 >> even though everyone seems knowledgeable and I appreciate reading =
your
 >> views.
 >>
 >> On 1/14/2011 3:23 PM, David H. Lipman wrote:
 >>> I agree with this assertion.
 >>>
 >>> Malware encyclopedias are NOT what they used to be 7~10 years ago.
 >>>
 >>> New variants of malware are created daily and often hourly.=A0 So =
often
that encyclopedias (librariies) just can't be
 >>> kept up to date.
 >>>
 >>> At best we can talk about families such as MEBRoot, TDSS (TDL3, =
TDL4,
etc), ZBot, Gromozon, FakeAV,
 >>> FakeAlert, yada, yada.=A0 And in that we can have generalities =
about how
the malware conducts itself and what
 >>> changes it makes to the OS.
 >>>
 >>> As for ThreatExpert.=A0 It is just OK.=A0 I use it but, I find that =
data
colleected is often incomplete.=A0 Especially in light
 >>> of the AntiVM routines of much of the malware I see.=A0 ANUBIS the =
same
and it can't handle .NET files.=A0 COMODO
 >>> is limited and supplies very little information.=A0 The University =
of
Manaheim's sandbox is very good but it is
 >>> presently down and won't be back up until the third or 4th week of =
this
month.=A0 Stefan B. has an excellent system
 >>> but it is underfunded and underpowered and I am afraid if I mention =
his
system you will all use it and it will get
 >>> overloaded and it'll take days to get reports returned.
 >>>
 >>> We return back to the original question about 'srvpool.exe'.
 >>>
 >>> Google is ONLY good to tell you if it is a known process.=A0 =
However, any
file can be named anything.=A0 It isn't
 >>> enough to know the name of the file but the fully qualified name =
and
path to the file.
 >>>
 >>> We know SVCHOST.EXE is a legitimate process.
 >>> Not if it is loaded from %appdata%.
 >>>
 >>> Malware deliberately hides itsalf in names of legitimate files or
slight variation thereof.
 >>> SVCHOST.EXE is the most prevalent of names forged or use variations
like SCVHOST.EXE or LSASS.EXE as
 >>> Isass.exe.=A0 Here we have 'srvpool.exe' which is a take on =
'spoolsv.exe'
the Print Spooler Service.=A0 The problem is
 >>> any file can be called anything and the libraries are just not able =
to
keep up with all the new malware.
 >>>
 >>>
 >>> Get me a sample of 'spoolsv.exe' and I'll get the 411 on this.=A0 =
:-)
 >>>
 >>> Dave
 >>>
 >>>
 >>>
 >>>
 >>> Date forwarded:=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 09:26:47 =
-0700 (MST)
 >>> Date sent:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Fri, 14 Jan 2011 =
11:24:33 -0500 (EST)
 >>> Forwarded by:=A0=A0=A0=A0=A0=A0=A0=A0=A0 =
[email protected]
 >>> From:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Jose =
Nazario<[email protected]>
 >>> Subject:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Re: Malware =
database
 >>> To:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Huffen =
Doback<[email protected]>
 >>> Copies to:=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 =
[email protected],=A0
[email protected]
 >>>
 >>>> virus names used to be unique, but not so much any more.
 >>>>
 >>>> prevx, for example, lets you search by filename. plenty of sites =
have
nice
 >>>> writeups of "what is file foo.exe and what does it do?" for =
legitimate
 >>>> files. prevx mostly handles malicious files, and their writeups =
are
vague
 >>>> or misleading at best in that database.
 >>>>
 >>>> as for fine grained details sandbox reports are very useful.
 >>>> threatexpert.com is one of the more comprehensive and searchable. =
if
you
 >>>> have a file hash (md5) that's the best way to get such details.
 >>>>
 >>>> virustotal.com is also a useful place to get pointers.
 >>>>
 >>>> i do not trust or respect most AV writeups, they're very =
inadequate or
 >>>> just plain wrong.
 >>>>
 >>>>________
 >>>> jose nazario, ph.d.=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 =
http://monkey.org/~jose/
 >>>>
 >>>>
 >>>>
-------------------------------------------------------------------------=
--
 >>>> This list is sponsored by: Black Hat
 >>>>
 >>>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's
premier
 >>>> technical event for ICT security experts. Featuring 30 hands-on
training
 >>>> courses and 90 Briefings presentations with lots of new content =
and
new
 >>>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit =
product
 >>>> displays by 30 top sponsors in a relaxed setting.
 >>>>
 >>>> http://www.blackhat.com
 >>>>
-------------------------------------------------------------------------=
--
 >>>>
 >>>
 >>>
 >>> --
 >>>
 =
>>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Mr. David H. Lipman
 =
>>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 [email protected]
 =
>>>=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0 Yahoo IM:=A0 david_h_lipman
 >>>
 >>>
 >>>
 >>>
-------------------------------------------------------------------------=
--
 >>> This list is sponsored by: Black Hat
 >>>
 >>> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's
premier
 >>> technical event for ICT security experts. Featuring 30 hands-on
training
 >>> courses and 90 Briefings presentations with lots of new content and =
new
 >>> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit =
product
 >>> displays by 30 top sponsors in a relaxed setting.
 >>>
 >>> http://www.blackhat.com
 >>>
-------------------------------------------------------------------------=
--
 >>>
 >>>
 >>
-------------------------------------------------------------------------=
--
 >> This list is sponsored by: Black Hat
 >>
 >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's =
premier
 >> technical event for ICT security experts. Featuring 30 hands-on =
training
 >> courses and 90 Briefings presentations with lots of new content and =
new
 >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit =
product
 >> displays by 30 top sponsors in a relaxed setting.
 >>
 >> http://www.blackhat.com
 >>
-------------------------------------------------------------------------=
--
 >>
 >>
-------------------------------------------------------------------------=
--
 >> This list is sponsored by: Black Hat
 >>
 >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's =
premier
 >> technical event for ICT security experts. Featuring 30 hands-on =
training
 >> courses and 90 Briefings presentations with lots of new content and =
new
 >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit =
product
 >> displays by 30 top sponsors in a relaxed setting.
 >>
 >> http://www.blackhat.com
 >>
-------------------------------------------------------------------------=
--
 >>
 >>
 >>
-------------------------------------------------------------------------=
--
 >> This list is sponsored by: Black Hat
 >>
 >> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's =
premier
 >> technical event for ICT security experts. Featuring 30 hands-on =
training
 >> courses and 90 Briefings presentations with lots of new content and =
new
 >> tools.=A0 Network with 4,000 delegates from 70 nations.=A0 Visit =
product
 >> displays by 30 top sponsors in a relaxed setting.
 >>
 >> http://www.blackhat.com
 >>
-------------------------------------------------------------------------=
--
 >>

-------------------------------------------------------------------------=
--
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier =

technical event for ICT security experts. Featuring 30 hands-on training =

courses and 90 Briefings presentations with lots of new content and new=20
tools.  Network with 4,000 delegates from 70 nations.  Visit product=20
displays by 30 top sponsors in a relaxed setting. =20

http://www.blackhat.com
-------------------------------------------------------------------------=
--

__________________________________________________
žÏ¿ì×¢²áÑÅ»¢³¬ŽóÈÝÁ¿Ãâ·ÑÓÊÏä?
http://cn.mail.yahoo.com

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------