Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 8th, 2008, 08:13 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Malware that possible ?bypassed SBIE

It,s discussed partly here.

http://www.wilderssecurity.com/showp...0&postcount=29
http://www.wilderssecurity.com/showt...=212092&page=5

For obvious resons I am making a new thread. Here are the snapshots provided by Meriadoc. Thanks for his kindness, permission and the sample etc.

Plese note that it,s still not 100% confirmed that the malware has really bypassed SBIE or it was an isolated phenomenon. So don,t crticize if later proven othersise... SBIE lover espoecialy.

255MB video file download: http://rapidshare.de/files/39916359/malware23.avi.html
Attached Images
    
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?

Last edited by LowWaterMark : July 8th, 2008 at 01:02 PM. Reason: added label to download link so people will know it's a 255MB video file and not a malware file
  #2  
Old July 8th, 2008, 08:15 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

I tested CFP Defnce plus and GesWall against it. I mainly tested GW and allowed all popups by CFP, a lot of pop ups really.

GW denied any dll/ file creation in System32 folder. All other files were isolated and tagged untrusted by GW. I deleted these files via GW isolated files explorer and run a full scan of C drive by MBAM. No infected file was detected.

Snapshots are self explanatory I think.

Sample aws run sandboxed but it was able to create a dll, jfiehayd.dll in system32 folder, out of sandbox. Some reg entries escaped the sandbox too and desktop was changed but as I said clearly findings are not confirmed by anotehr person though same findings were obtained twice by same person.

Name:  2.jpg
Views: 588
Size:  27.5 KB
Name:  3.jpg
Views: 598
Size:  79.0 KB
Name:  4.jpg
Views: 587
Size:  77.1 KB
Name:  5.jpg
Views: 597
Size:  44.1 KB
Click image for larger version

Name:	1.jpg
Views:	5
Size:	89.4 KB
ID:	201281
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?

Last edited by aigle : July 8th, 2008 at 06:24 PM.
  #3  
Old July 8th, 2008, 08:16 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

Still more!
Attached Images
 
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #4  
Old July 8th, 2008, 08:16 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

GesWall, log is here.
Attached Files
File Type: txt GW log.txt (11.8 KB, 27 views)
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #5  
Old July 8th, 2008, 08:27 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Malware that possible ?bypassed SBIE

Quote:
Originally Posted by aigle
Plese note that it,s still not 100% confirmed that the malware has really bypassed SBIE or it was an isolated phenomenon. So don,t crticize if later proven othersise... SBIE lover espoecialy.
Not a 100% sure but it was OK to use "bypassed SBIE" in the title thread, eh?

And then you go on about every other app except Sandboxie.

Not nice aigle!
  #6  
Old July 8th, 2008, 08:31 AM
Someone Someone is offline
Very Frequent Poster
 
Join Date: Jan 2008
Posts: 1,106
Default Re: Malware that possible ?bypassed SBIE

Quote:
Originally Posted by Franklin
Not a 100% sure but it was OK to use "bypassed SBIE" in the title thread, eh?

And then you go on about every other app except Sandboxie.

Not nice aigle!

Hi

Doesn't the thread title say: Malware that possible ?bypassed SBIE. That seems alright to me.

And anyway, you can just read the thread and Aigle clearly says that it is not certain.
  #7  
Old July 8th, 2008, 09:04 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Malware that possible ?bypassed SBIE

I'm still shirty about it so gimme a sample of this malware. (please)
install3051.exe
  #8  
Old July 8th, 2008, 12:11 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Malware that possible ?bypassed SBIE

Undoubtedly a reminder needs to be given periodically for even long time members that Wilders does not allow the trading of malware or the posting of malware links. Discussion is cool folks but let's do keep it within our Terms of Service
  #9  
Old July 8th, 2008, 03:27 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: Malware that possible ?bypassed SBIE

The topic of this thread does not seem to fit the content of this thread. (If it doesn't fit, you must acquit.)

Maybe I am dense, but I could NOT find the SBIE connection. All I found was tests of various security apps.

Although I appreciate aigle doing these tests, I feel that the topic of this thread SEEMS inapplicable and unnecessarily negative. It is dangerously close to a false alarm (a la chicken little).
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #10  
Old July 8th, 2008, 03:35 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Malware that possible ?bypassed SBIE

Agree with Franklin & Bellgamin that the title is arbitrary, interesting read though
  #11  
Old July 8th, 2008, 03:54 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: Malware that possible ?bypassed SBIE

that thing is that wasnt clear enough but you know something that makes me
wake up an smell the coffee and think that nothing is perfect so what i mean bypassed or not we need a second layer at least.whay i said this cause
heard people at sandboxie forum that sandboxie is all they need or run.
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #12  
Old July 8th, 2008, 03:55 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware that possible ?bypassed SBIE

@Bellgamin and Kees

The connection with SBIE is that apparently this malware was able to escape sandboxie. But it hasn't been tested again.
Other security software results are shown.
~removed off topic comment....Bubba~ , hopefully I'll be able to test it tonight.
__________________
I SandboxIE

Last edited by Bubba : July 8th, 2008 at 04:01 PM. Reason: removed off topic comment
  #13  
Old July 8th, 2008, 04:07 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Malware that possible ?bypassed SBIE

Not only is comments concerning malware trading via PM off topic to any discussion here at Wilders, the actual act of malware trading or the posting of malware links is against our policy. Let's take the malware trading comments and the actual act to another site Please.
  #14  
Old July 8th, 2008, 05:50 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

@bellgamin
@Kees

Title of the thread is OK. You need to look at screenshots carefuly in my first post. I did not make this thread for a stunt. I only had no time to write a detailed description. I will try to write it in first post. Or may be somebody will post his findings.

BTW Hurst got this point.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?

Last edited by aigle : July 8th, 2008 at 06:18 PM.
  #15  
Old July 8th, 2008, 06:19 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: Malware that possible ?bypassed SBIE

Quote:
Originally Posted by aigle
@bellgamin
@Kees

Title of the thread is OK. You need to look at screenshots carefuly in my first post. I did not make this thread for a stunt. I only had no time to write a detailed description. I will try to write it in first post. Or may be somebody will post his findings.
I believe you aigle BUT...

I looked again at the screenshots in post#1 but saw no connection to SBIE. Saw no evidence that malware evaded SBIE.What am I looking for? What am I missing?
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #16  
Old July 8th, 2008, 06:24 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,637
Default Re: Malware that possible ?bypassed SBIE

yeah, title may be a tad bit confusing, but the facts of Geswall are right on. Sorry folks, but this is one software that wont die away. It can do it all and continues to prove it time and time again. I can use whatever I want, I have bought quite a few, but the bottom line is, the lack of intrusion of my daily web habits along with its great ability to nab malware, make it number 1 in my book. And the paid version is worth every penny, and in the future there,,,,,,,,,ooops, cant go there.
__________________
Eset
  #17  
Old July 8th, 2008, 06:32 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware that possible ?bypassed SBIE

OK
test is done!
I'm glad to say that SBIE has contained it.

LOTS of processes launched inside the sandbox, and lots of activity.
Some error popups (not from sandboxie).

Deleted sandbox, and MBAM scan came out clean.

I will post the screenshots later tonight.
__________________
I SandboxIE

Last edited by HURST : July 8th, 2008 at 06:40 PM.
  #18  
Old July 8th, 2008, 06:35 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

Strangely I am not able to edit my post no.1.

Sample was run sandboxed but it was able to create a dll, jfiehayd.dll in system32 folder, out of sandbox. See first screenshot. Some reg entries escaped the sandbox too and desktop was changed but as I said clearly findings are not confirmed by anotehr person though same findings were obtained twice by same person.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #19  
Old July 8th, 2008, 06:38 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

Quote:
Originally Posted by HURST
OK
test is done!
I'm glad to say that SBIE has contained it.

LOTS of processes launched inside the sandbox, and lots of activity.
Some error popups (not from sandboxie).

Deleted files, and MBAM scan came out clean.

I will post the screenshots later tonight.
Thanks for testing. That,s good news. So there is something weired on first test system as it was tested twice with same results.

OK, I will test it also myself later. BTW malware does not seem to have any special ability to bypass a sandbox.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #20  
Old July 8th, 2008, 06:39 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware that possible ?bypassed SBIE

No sign of jfiehayd.dll on system32.
Desktop hasn't changed.
__________________
I SandboxIE
  #21  
Old July 8th, 2008, 06:49 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

Did u check for jfiehayd.dll inside sandbox before emptying it?
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #22  
Old July 8th, 2008, 07:23 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware that possible ?bypassed SBIE

No.
But I'll retest to provide screenshots and will check for that file then.
__________________
I SandboxIE
  #23  
Old July 8th, 2008, 07:26 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware that possible ?bypassed SBIE

The only dll inside system32 in the sandbox is qoMEuSJY.dll
__________________
I SandboxIE
  #24  
Old July 8th, 2008, 07:49 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malware that possible ?bypassed SBIE

Surprisingly also I don,t find any jfiehayd.dll. I will try to run it out of sandbox n see what happens.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #25  
Old July 8th, 2008, 08:02 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Malware that possible ?bypassed SBIE

Quote:
Originally Posted by aigle
Surprisingly also I don,t find any jfiehayd.dll. I will try to run it out of sandbox n see what happens.
Maybe the malware renames its components automatically.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:28 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums