![]() |
|
#1
|
||||
|
||||
|
It,s discussed partly here.
http://www.wilderssecurity.com/showp...0&postcount=29 http://www.wilderssecurity.com/showt...=212092&page=5 For obvious resons I am making a new thread. Here are the snapshots provided by Meriadoc. Thanks for his kindness, permission and the sample etc. Plese note that it,s still not 100% confirmed that the malware has really bypassed SBIE or it was an isolated phenomenon. So don,t crticize if later proven othersise... SBIE lover espoecialy. 255MB video file download: http://rapidshare.de/files/39916359/malware23.avi.html
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by LowWaterMark : July 8th, 2008 at 01:02 PM. Reason: added label to download link so people will know it's a 255MB video file and not a malware file |
|
#2
|
||||
|
||||
|
I tested CFP Defnce plus and GesWall against it. I mainly tested GW and allowed all popups by CFP, a lot of pop ups really.
GW denied any dll/ file creation in System32 folder. All other files were isolated and tagged untrusted by GW. I deleted these files via GW isolated files explorer and run a full scan of C drive by MBAM. No infected file was detected. Snapshots are self explanatory I think. Sample aws run sandboxed but it was able to create a dll, jfiehayd.dll in system32 folder, out of sandbox. Some reg entries escaped the sandbox too and desktop was changed but as I said clearly findings are not confirmed by anotehr person though same findings were obtained twice by same person.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 8th, 2008 at 06:24 PM. |
|
#3
|
||||
|
||||
|
Still more!
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#4
|
||||
|
||||
|
GesWall, log is here.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#5
|
||||
|
||||
|
Quote:
And then you go on about every other app except Sandboxie. Not nice aigle! ![]()
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#6
|
|||
|
|||
|
Quote:
Hi Doesn't the thread title say: Malware that possible ?bypassed SBIE. That seems alright to me. And anyway, you can just read the thread and Aigle clearly says that it is not certain. |
|
#7
|
||||
|
||||
|
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#8
|
||||
|
||||
|
Undoubtedly a reminder needs to be given periodically for even long time members that Wilders does not allow the trading of malware or the posting of malware links. Discussion is cool folks but let's do keep it within our Terms of Service
![]()
__________________
Wilders - Terms of Service · Site FAQ · Searching the forum easier · The Art of Quoting in Posts |
|
#9
|
||||
|
||||
|
The topic of this thread does not seem to fit the content of this thread. (If it doesn't fit, you must acquit.)
Maybe I am dense, but I could NOT find the SBIE connection. All I found was tests of various security apps. Although I appreciate aigle doing these tests, I feel that the topic of this thread SEEMS inapplicable and unnecessarily negative. It is dangerously close to a false alarm (a la chicken little).
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#10
|
||||
|
||||
|
Agree with Franklin & Bellgamin that the title is arbitrary, interesting read though
|
|
#11
|
||||
|
||||
|
that thing is that wasnt clear enough but you know something that makes me
wake up an smell the coffee and think that nothing is perfect so what i mean bypassed or not we need a second layer at least.whay i said this cause heard people at sandboxie forum that sandboxie is all they need or run. ![]()
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#12
|
||||
|
||||
|
@Bellgamin and Kees
The connection with SBIE is that apparently this malware was able to escape sandboxie. But it hasn't been tested again. Other security software results are shown. ~removed off topic comment....Bubba~ , hopefully I'll be able to test it tonight.
__________________
I ♥ SandboxIE
Last edited by Bubba : July 8th, 2008 at 04:01 PM. Reason: removed off topic comment |
|
#13
|
||||
|
||||
|
Not only is comments concerning malware trading via PM off topic to any discussion here at Wilders, the actual act of malware trading or the posting of malware links is against our policy. Let's take the malware trading comments and the actual act to another site Please.
__________________
Wilders - Terms of Service · Site FAQ · Searching the forum easier · The Art of Quoting in Posts |
|
#14
|
||||
|
||||
|
@bellgamin
@Kees Title of the thread is OK. You need to look at screenshots carefuly in my first post. I did not make this thread for a stunt. I only had no time to write a detailed description. I will try to write it in first post. Or may be somebody will post his findings. BTW Hurst got this point.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 8th, 2008 at 06:18 PM. |
|
#15
|
||||
|
||||
|
Quote:
I looked again at the screenshots in post#1 but saw no connection to SBIE. Saw no evidence that malware evaded SBIE.What am I looking for? What am I missing?
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#16
|
||||
|
||||
|
yeah, title may be a tad bit confusing, but the facts of Geswall are right on. Sorry folks, but this is one software that wont die away. It can do it all and continues to prove it time and time again. I can use whatever I want, I have bought quite a few, but the bottom line is, the lack of intrusion of my daily web habits along with its great ability to nab malware, make it number 1 in my book. And the paid version is worth every penny, and in the future there,,,,,,,,,ooops, cant go there.
![]()
__________________
Eset |
|
#17
|
||||
|
||||
|
OK
test is done! I'm glad to say that SBIE has contained it. LOTS of processes launched inside the sandbox, and lots of activity. Some error popups (not from sandboxie). Deleted sandbox, and MBAM scan came out clean. I will post the screenshots later tonight.
__________________
I ♥ SandboxIE
Last edited by HURST : July 8th, 2008 at 06:40 PM. |
|
#18
|
||||
|
||||
|
Strangely I am not able to edit my post no.1.
Sample was run sandboxed but it was able to create a dll, jfiehayd.dll in system32 folder, out of sandbox. See first screenshot. Some reg entries escaped the sandbox too and desktop was changed but as I said clearly findings are not confirmed by anotehr person though same findings were obtained twice by same person.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#19
|
||||
|
||||
|
Quote:
OK, I will test it also myself later. BTW malware does not seem to have any special ability to bypass a sandbox.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#20
|
||||
|
||||
|
No sign of jfiehayd.dll on system32.
Desktop hasn't changed.
__________________
I ♥ SandboxIE
|
|
#21
|
||||
|
||||
|
Did u check for jfiehayd.dll inside sandbox before emptying it?
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#22
|
||||
|
||||
|
No.
But I'll retest to provide screenshots and will check for that file then.
__________________
I ♥ SandboxIE
|
|
#23
|
||||
|
||||
|
The only dll inside system32 in the sandbox is qoMEuSJY.dll
__________________
I ♥ SandboxIE
|
|
#24
|
||||
|
||||
|
Surprisingly also I don,t find any jfiehayd.dll. I will try to run it out of sandbox n see what happens.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#25
|
|||
|
|||
|
Quote:
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|