Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 29th, 2005, 08:24 AM
winx5 winx5 is offline
Infrequent Poster
 
Join Date: Jan 2005
Posts: 26
I Say! Looking for heuristics?

http://img483.imageshack.us/img483/5184/heur5rk.th.png

http://img483.imageshack.us/img483/9861/heur22mm.th.png
  #2  
Old October 29th, 2005, 08:49 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Looking for heuristics?

I fear the old AntiVir heuristics rather have a "false positive" here, most likely detecting some exe packer as Win32.Virus.

Just took a look at the sample, seems someone opened an executable with a text editor and saved the result.
The text editor replaced all zero bytes with spaces (0x20), making the executable invalid and non-working.
I wonder if thats the same sample though, got a different MD5 and test5.exe instead of test5.txt.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.

Last edited by Stefan Kurtzhals : October 29th, 2005 at 08:59 AM.
  #3  
Old October 29th, 2005, 09:33 AM
winx5 winx5 is offline
Infrequent Poster
 
Join Date: Jan 2005
Posts: 26
Exclamation Re: Looking for heuristics?

Hi Stefan,

I can confirm that it is a malware, a trojan downloader.
NOD32 blocked it from being downloaded.
By looking in the Threat Log, i found it's URL and downloaded the file Test5.txt with WGET to keep the PE intact.
I also decompressed it with UPX, debbugged it and found out that it contacts a server to download more trojans.

I can PM you the URL if you are interested.
  #4  
Old October 29th, 2005, 09:52 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Looking for heuristics?

For those interested in another example (I ceased taking screenshots after I'd got about 70 images with unique variants):
Attached Images
 
  #5  
Old October 29th, 2005, 11:20 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Looking for heuristics?

winx5, can you send the URL or sample to heuristik@antivir.de?

The test5.exe that was sent to us from VirusTotal was not the same sample you uploaded it seems (different MD5)
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #6  
Old October 29th, 2005, 11:50 AM
Firefighter's Avatar
Firefighter Firefighter is offline
Very Frequent Poster
 
Join Date: Oct 2002
Location: Finland
Posts: 1,641
Default Re: Looking for heuristics?

Quote:
Originally Posted by Marcos
For those interested in another example (I ceased taking screenshots after I'd got about 70 images with unique variants):
Is it so that you just managed to get the top 3 heuristics scanning engines in to the same picture?

Best regards,
Firefighter!
__________________
Some savolax answer to the southern man:
Q. No onko viiruksia näkynyt?
A. No voe tokkiisa. Just äskönnii oes männynnä yks vuan en ehtinnä nähä. Tuolta saanan takkoo se männä jölököttel suorraah järvvee letit hulumuteh!
  #7  
Old October 29th, 2005, 02:18 PM
winx5 winx5 is offline
Infrequent Poster
 
Join Date: Jan 2005
Posts: 26
Thumbs up Re: Looking for heuristics?

Stefan,

It's now sent.

Firefighter,

Count Antivir as the fourth...
  #8  
Old October 29th, 2005, 02:33 PM
Firefighter's Avatar
Firefighter Firefighter is offline
Very Frequent Poster
 
Join Date: Oct 2002
Location: Finland
Posts: 1,641
Default Re: Looking for heuristics?

Quote:
Originally Posted by winx5
Stefan,

It's now sent.

Firefighter,

Count Antivir as the fourth...
Maybe? But none has said anything about the heuristics in Kaspersky 6.0.15.222a (preBeta1 - step 7)!

Best regards,
Firefighter!
__________________
Some savolax answer to the southern man:
Q. No onko viiruksia näkynyt?
A. No voe tokkiisa. Just äskönnii oes männynnä yks vuan en ehtinnä nähä. Tuolta saanan takkoo se männä jölököttel suorraah järvvee letit hulumuteh!
  #9  
Old October 29th, 2005, 02:54 PM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Looking for heuristics?

Firefighter, does that version of KAV6 beta has anything new regarding heuristic detection?
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #10  
Old October 29th, 2005, 03:30 PM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,365
Default Re: Looking for heuristics?

There is Proactive Defense module, that works pretty much the same as TruPrevent. Except it's still very very beta and doesn't exactly function as it should (for now).
__________________
RejZoR's Little Secrets
  #11  
Old October 29th, 2005, 03:48 PM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Looking for heuristics?

I noticed the behaviour blocker, but it's too much work to test an entire collection against it by launching every file. So it's hard to say how good actually its "detection" ratio is.

I thought that KAV6 has a slightly better file heuristic, even though KAV 4.5 and 5 should use the same AVC files, hm.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #12  
Old October 29th, 2005, 04:32 PM
Firefighter's Avatar
Firefighter Firefighter is offline
Very Frequent Poster
 
Join Date: Oct 2002
Location: Finland
Posts: 1,641
Default Re: Looking for heuristics?

Quote:
Originally Posted by Stefan Kurtzhals
Firefighter, does that version of KAV6 beta has anything new regarding heuristic detection?
I have not tested that new Kaspersky Pre-Beta yet. About heuristics, I don't even know how I can test that against large sample collections, because Kaspersky detects almost everything. But there is a simple method with DrWeb 4.33.

If you want to check how good DrWeb's heuristics is, Please, remove all your defs except those today riskware ones, check first by without heuristics, if no detections occured, enable heuristics and scan your all samples collection.

Best regards,
Firefighter!
__________________
Some savolax answer to the southern man:
Q. No onko viiruksia näkynyt?
A. No voe tokkiisa. Just äskönnii oes männynnä yks vuan en ehtinnä nähä. Tuolta saanan takkoo se männä jölököttel suorraah järvvee letit hulumuteh!

Last edited by Firefighter : October 29th, 2005 at 04:40 PM.
  #13  
Old October 29th, 2005, 05:04 PM
Firefighter's Avatar
Firefighter Firefighter is offline
Very Frequent Poster
 
Join Date: Oct 2002
Location: Finland
Posts: 1,641
Default Re: Looking for heuristics?

Can anyone tell which are those av:s that are able to scan with heuristics only except NOD? Also those tricks as DrWeb has are welcome.

Best regards,
Firefighter!
__________________
Some savolax answer to the southern man:
Q. No onko viiruksia näkynyt?
A. No voe tokkiisa. Just äskönnii oes männynnä yks vuan en ehtinnä nähä. Tuolta saanan takkoo se männä jölököttel suorraah järvvee letit hulumuteh!
  #14  
Old October 29th, 2005, 05:52 PM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,672
Default Re: Looking for heuristics?

Quote:
Originally Posted by Stefan Kurtzhals
I thought that KAV6 has a slightly better file heuristic

I remember that on the Kaspersky forum, a developer had stated that KL was considering improving the heuristics engine of KAV 6.x.

BTW, I dont think the AVC files contain the heuristic engine, what they do contain is the generic detection engine.
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

  #15  
Old October 29th, 2005, 06:59 PM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,257
Default Re: Looking for heuristics?

Quote:
Originally Posted by Firecat
BTW, I dont think the AVC files contain the heuristic engine, what they do contain is the generic detection engine.
There is both gen.avc & ca.avc=code analyzer.
__________________
Errare humanum est
  #16  
Old November 1st, 2005, 05:53 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Looking for heuristics?

For those interested, here is how NOD32 provided zero time protection to the latest mass mailing threats without needing to update (the total number of occurences was taken from www.virusradar.com):

Number of a variant of Win32/Bagle worm in 2005-11-01:
2005-11-01 22 : 4137
2005-11-01 21 : 1959
2005-11-01 20 : 3434
2005-11-01 19 : 2354
2005-11-01 18 : 1438
2005-11-01 17 : 407
2005-11-01 16 : 0

Number of a variant of Win32/Mytob worm in 2005-11-01:
2005-11-01 22 : 50
2005-11-01 21 : 23
2005-11-01 20 : 7
2005-11-01 19 : 2
2005-11-01 18 : 0
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:33 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums