Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 8th, 2008, 02:37 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Malware Defender Hips-Testing with trojans and Rogue AV

This test is what a user could expect from a Hips when it encounters execution of a unwanted.The site I am tesing is a real threat that contains trojans,Rogues AV and anyones guess what else.It requires a Active X download that appears to execute with out the users intervention from the active x pop.I will try to post all screens for example.This is also when the trojans and rogue would normally be dropped on a users machine providing they had no blocking as hips or un detected by a Antivirus or a behavior blocker.Also perhaps No Active X would be a big plus here on this site anyways.
Attached Images
 
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/

Last edited by Dark Shadow : December 8th, 2008 at 03:33 AM.
  #2  
Old December 8th, 2008, 02:41 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Screen shot 2
Attached Images
 
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #3  
Old December 8th, 2008, 02:46 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

screen shot 3
Attached Images
 
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #4  
Old December 8th, 2008, 02:52 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Screen shot 4
Attached Images
 
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #5  
Old December 8th, 2008, 03:11 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Ok appreantly there is about 10 different pop warnings here to deal with and some freezing between snipping images making it difficult for screen shots.Some findings, Malware Defender effectively Blocks providing users make the correct choice.The user should come out clean,No files where dropped on my machine, So it is very good at blocking, However Malware Defender struggles with Deny and termination, the pop ups to run the exe kept poping up makeing it difficult to close the common pops that come with adult sites.It did terminate but seem to be a few minute or so delay.I am No expert here but these are my finding.All and All great program light stable didn't crash even while waiting for longer periods while waiting user reply of deny or allow or Deny and terminate processes.IMO deny and terminate would be the obvious choice unless the user would like to answer nearly a dozen pop ups in this case.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/

Last edited by Dark Shadow : December 8th, 2008 at 03:28 AM.
  #6  
Old December 8th, 2008, 03:33 AM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Interesting, Dave. Thanks!
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #7  
Old December 8th, 2008, 03:39 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Your welcome it was fun fun fun.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #8  
Old December 8th, 2008, 04:19 AM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Dave, could you pm me a link to that site? I'd like to do some testing of my own.
  #9  
Old December 8th, 2008, 07:41 AM
chris1341's Avatar
chris1341 chris1341 is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Scotland
Posts: 632
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

After the initial Learnimg Mode period I've got used to placing MD in Silent Mode when surfing, particularly unknown sites. I'm assuming if you did that then these threats would be blocked/denied without the need for multiple pop-ups/decisions.

Is that correct?

Cheers
__________________
Chris
  #10  
Old December 8th, 2008, 09:31 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Quote:
Originally Posted by chrome_sturmen
Dave, could you pm me a link to that site? I'd like to do some testing of my own.


Check you PM
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #11  
Old December 8th, 2008, 09:40 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Quote:
Originally Posted by chris1341
After the initial Learnimg Mode period I've got used to placing MD in Silent Mode when surfing, particularly unknown sites. I'm assuming if you did that then these threats would be blocked/denied without the need for multiple pop-ups/decisions.

Is that correct?

Cheers
Hi chris1341,That would be the best choice IMO,However my test is with Normal mode and this little buger is persistent you will still get popups even in silent mode minus not decision making one from the soft but from the site it self.Keep in mind this is IE7 X active enable,java script.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #12  
Old December 8th, 2008, 10:07 AM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

I know this post relates to malware defender's ability to handle drive-by malware, but I couldn't help but want to try a small test against the site using my own protections, so forgive the brief impertinence, here were my findings:

Dave, I checked out the site you sent me, I find this odd, because after visiting it, I looked in agnitum firewall's content filtering log, expecting to see blocked activex scripting, blocked embedded spyware, blocked referers, pop-ups ect ect - but I saw nothing, not one blocked element. Then again I use ad-muncher to complement outpost firewall's ad-blocking and content filtering modules, so I then took a look at ad-muncher's log, again expecting to see something wild- all I got was this, which is nothing major:

Default filter match - No filtering on URL: /jquery.js [http:**/jquery.js]
Removed suspected web bug [htt:**]
Default filter match - No filtering on URL: /jquery.js [http:**/]
Prevented site from changing the browser status bar [[url]http://**]

I just don't get it,all I got was a clean web page. Of course I use sandboxie, which removed any element of fear in testing the siteno matter how badly infected it may've been, but sandboxie wouldn'tve affected the elements in the web pages themselves.

thoughts?
  #13  
Old December 8th, 2008, 10:17 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Did you get the second link with porn tube that require new active X for Video.the first link was wrong.I tested this with NOD32 4 beta another post.My testing files was also sent to VT which only a few scanners detected at first and more at a latter the link is not clean.I will recheck it again.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #14  
Old December 8th, 2008, 10:29 AM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Ahhhh, I see now, the web page itself was clean, but when you click to watch a video,you're prompted to install a "video activex object". I downloaded and ran the executable, at which point it tried to access the internet and evoke a command prompt -I allowed the calling of the command prompt through outpost's h.i.p.s. module, but sandboxie denied any access to the internet, and that's as far as anything went, nothing else tried to happen and I could test no further.

But back on topic, this kind of thing is easily handled by h.i.p.s. apps like malware defender, I imagine it could knock it out blindfolded

Excuse me now while I go empty the sandbox
  #15  
Old December 8th, 2008, 10:31 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Here ya go
Attached Thumbnails
Click image for larger version

Name:	Capture.JPG
Views:	2
Size:	95.3 KB
ID:	204729  

__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #16  
Old December 8th, 2008, 10:32 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

and here.
Attached Images
 
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #17  
Old December 8th, 2008, 10:51 AM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Yep, I see it there in the flesh. I am thinking that whatever that activex setup object wants to do, it has to download from the internet in order to do it, because I allowed it to evoke a command prompt, and i'd think that at that point it would install it's malicious code if it was gonna, but when it couldn't access the internet it gave up, so it relys on downloading the rogue code from the net, it's not included in the setup itself (unless you count it wanting to download crapware to begin with). Then again, as your screenshot points out, they're all trojan downloaders, so it's fairly obvious Any rate, I grabbed a handful of the buggers and dumped the sandbox on top of 'em, whereupon they scurried away crying and squealing
  #18  
Old December 8th, 2008, 10:56 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Quote:
Originally Posted by djohn
Hi chris1341,That would be the best choice IMO,However my test is with Normal mode and this little buger is persistent you will still get popups even in silent mode minus not decision making one from the soft but from the site it self.Keep in mind this is IE7 X active enable,java script.
very impresive john good test
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #19  
Old December 8th, 2008, 10:57 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Quote:
Originally Posted by chrome_sturmen
Yep, I see it there in the flesh. I am thinking that whatever that activex setup object wants to do, it has to download from the internet in order to do it, because I allowed it to evoke a command prompt, and i'd think that at that point it would install it's malicious code if it was gonna, but when it couldn't access the internet it gave up, so it relys on downloading the rogue code from the net, it's not included in the setup itself (unless you count it wanting to download crapware to begin with). Then again, as your screenshot points out, they're all trojan downloaders, so it's fairly obvious
thanks Chrome Sturmen for testing,lots of fun perhaps not for some folks that explore these areas not knowing what lurks behind the seens.Somebody worst nightmare waiting to happen.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #20  
Old December 8th, 2008, 11:01 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Quote:
Originally Posted by jmonge
very impresive john good test
Thank you jmonge I am know expert here just a amateur but thank you for the compliment.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #21  
Old December 8th, 2008, 11:05 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Quote:
Originally Posted by djohn
Thank you jmonge I am know expert here just a amateur but thank you for the compliment.
you did very good man and you have a big wepon in your hands
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #22  
Old December 8th, 2008, 12:15 PM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

I decided to have some fun with the malicious code that the activex video object downloads and installs on the system

it starts out like so, when you click on a video to watch:


Name:  Snap1.jpg
Views: 433
Size:  38.0 KB

once you run the setup, it connects to this site to download the malware, i assume:

Name:  Snap2.jpg
Views: 430
Size:  64.9 KB

upon being allowed to do so,it downloads and runs these exes:

Name:  Snap3.jpg
Views: 431
Size:  58.0 KB
Name:  Snap4.jpg
Views: 431
Size:  57.9 KB
Name:  Snap5.jpg
Views: 429
Size:  57.6 KB

continued...
  #23  
Old December 8th, 2008, 12:22 PM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Name:  Snap6.jpg
Views: 425
Size:  56.2 KB

one of the exes launches a command prompt
Name:  Snap7.jpg
Views: 429
Size:  56.9 KB

evokes rundll32.exe
Name:  Snap9.jpg
Views: 431
Size:  57.4 KB

br41.exe? oh my
Name:  Snap10.jpg
Views: 428
Size:  70.3 KB

all of which culminates in the lovely virus response lab 2009, a definite security addition for any antimalware aficinadio
Name:  Snap11.jpg
Views: 432
Size:  184.2 KB

seems clicking "watch video" can be a dangerous affair these days of late
  #24  
Old December 8th, 2008, 12:25 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

Nice,rather more informative details of the variants
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #25  
Old December 8th, 2008, 10:22 PM
chrome_sturmen's Avatar
chrome_sturmen chrome_sturmen is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Sverige
Posts: 612
Default Re: Malware Defender Hips-Testing with trojans and Rogue AV

enjoyed it, we should do it again sometime (you buy the beer?)
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:14 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums