![]() |
|
#101
|
|||
|
|||
|
Just for the record, isn´t it true that a HIPS like SSM can protect you against all this stuff? Also, it seems that you get alerts about just about everything that tries to install, at least if you´re patched I assume. So not really scary. The only striking thing is that AV scanners can´t detect a lot of these trojans, so another proof why you really need to have a HIPS or sandboxing solution.
![]() |
|
#102
|
||||
|
||||
|
Quote:
However note that malware can be (and has been several times) created so that it won't execute in a "sandboxed" environment, only a real one: fine for "protection" purposes, but faulty to see whether something is really malicous or not. Quote:
Last edited by TNT : August 24th, 2006 at 02:04 PM. |
|
#103
|
|||
|
|||
|
You might also want to test SSM and Neoava Guard against these sites, would be interesting to see how they performed, but I´m sure they will block everything.
Quote:
I mean about the activex controls and the google.com file, they will not load silently, correct? |
|
#104
|
||||
|
||||
|
EraserHW,
Thank you for the great analysis report. One thing that was very surprising to me was that it wouldn't run in a virtual environment. I thought programs couldn't detect if they were run in a virtual environment. Can they break out of a virtual environment? |
|
#105
|
||||
|
||||
|
Quote:
|
|
#106
|
||||
|
||||
|
Quote:
I'm really pleased to have done something interesting ![]() yes, some malware can detect if it's running in a Virtual Machine or not. There are several ways to detect if it's running inside a VM, for example (one stupid example) using some istructions that a VM can't emulate ![]() Regards, Marco
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#107
|
|||
|
|||
|
Excellent document, EraserHW. Well written.
You might want to add this whois to it. Quote:
|
|
#108
|
||||
|
||||
|
http://www.pcalsicuro.com/gromozon.pdf
Anyone tried just putting the gbeb http link referred to in their firewall's (or PerrGuardian's) blocklist? Pete |
|
#109
|
||||
|
||||
|
Quote:
At this point in time, the advice for a 'normal' user might be to format if you get it. |
|
#110
|
|||
|
|||
|
I look forward to seeing updated scan results of this malware :-)
|
|
#111
|
||||
|
||||
|
Quote:
![]() Quote:
|
|
#112
|
||||
|
||||
|
EraserHW
Do I need to allow Acrobat to install service/drive with PG to download the file? Otherwise I am not able to. controler |
|
#113
|
||||
|
||||
|
Quote:
![]() |
|
#114
|
||||
|
||||
|
If you experience problems with that, try http://rapidshare.de/files/30707949/gromozon.pdf.html
|
|
#115
|
||||
|
||||
|
I'll fix speed problem on the server
sorry ![]() @SirMalware: yeah, I've some things to add to the paper in the release 0.3 Thanks for your infos ![]()
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#116
|
|||
|
|||
|
Someone mentioned earlier in this thread that submitting files to virustotal will allow all of the antimalware vendors to get the samples . I have found this not to be case (or they just don't care) . Some work we did here : http://www.castlecops.com/t162898-CMMONSVC32_EXE.html resulted in many new samples being submitted to virustotal , but here : http://www.castlecops.com/t164130-su..._varients.html you can see that most providers had not picked them up 2 weeks later .
I would suggest using virustotal as a testing point for new malware and a benchmarking tool for new threat response time only . If you want the "good guys" to get the samples , upload the samples directly to them . @TNT If it is all right with you I would be interested in having the samples collected so far and/or links to where I can get them myself (you mentioned that they are changing frequently) . There are a few antimalware providers I want to double check with to confirm that they have these . PM me if this is ok with you and I will PM you my email address . Thanks . BTW its cool reading about the use of virtual environments and sandboxes for malware research . I only do it as a hobby and still use the method of intentional infecting my unsecured xp sp1 test machine , pulling out its hard drive , slaving it to my work machine and collecting the samples from there . Super low tech but super effective for crippling rootkits and stubborn malware . I submit malware samples to any providers that both make themselves accessible and provide free versions to home users . Last edited by nosirrah : August 25th, 2006 at 11:07 AM. |
|
#117
|
||||
|
||||
|
ok, fixed download bandwidth problem
now download should be really faster.
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#118
|
||||
|
||||
|
http://www.symantec.com/enterprise/s...803-99&tabid=2
Symantec released an analysis of the threat! ![]() quite similar to mine. Even if the one from Symantec will be more official than mine, I'm proud about my paper and because I've pointed out a dangerous threat that otherwise was infecting a lot of people. ![]()
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute Last edited by EraserHW : August 25th, 2006 at 02:26 PM. |
|
#119
|
||||
|
||||
|
Quote:
![]() |
|
#120
|
||||
|
||||
|
Quote:
![]()
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#121
|
|||
|
|||
|
Quote:
Apparently, this stuff is now targeting all the specialty rootkit/removal tools out there, I was just at another forum where it was stated that IceSword or Avenger don't even work anymore. ![]() |
|
#122
|
||||
|
||||
|
yep but if you edit some editable byte into the sw with an hex editor, then the software will work again. It's a checksum scanner.
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#123
|
||||
|
||||
|
I was looking more deeply at Symantec writeup.
Imho there are some things that are wrong/inaccurate Quote:
For Trojan DLL here I hope/believe they want to say "rootkit". Here is the most important (and only) key of rootkit. Quote:
List isn't complete as far as I know, this is only a really small number Quote:
Here there's an error, because the second line isn't the 'System' subdir but 'Microsoft Shared' afaik. Regards, Marco ![]()
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#124
|
||||
|
||||
|
Quote:
![]() |
|
#125
|
|||
|
|||
|
Quote:
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|