Interesting HIPS leaktests/ malware tests

Discussion in 'other anti-malware software' started by aigle, Jan 18, 2008.

Thread Status:
Not open for further replies.
  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    All the stuff I was playing with has been around awhile, but yes F-Prot blocked them all. I had to disable it to test.
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    By the way, i have got the sample of Robodog. If I had VM I would have tested it against some ISR, HIPS and sandboxes etc!
     
  3. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    that is very impressive and interesting with F-Prot.:)
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Any good scanner will catch them all as these are not new samples. I hardly remember any of them not to be detected by Antivir on my system.
     
  5. zopzop

    zopzop Registered Member

    Joined:
    Apr 6, 2006
    Posts:
    642
    aigle, have you had a chance to email a sample to the comodo guys or brian from geswall? i'm sure they'd test it vs their apps ASAP.
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I sent it to Ilya. he will check it against DW. I might wait for his reults. I have no idea what it tries to do so I don,t even know whether it merits testing against GW and CFP or not?

    See ur PM BTW.
     
  7. Ilya Rabinovich

    Ilya Rabinovich Developer

    Joined:
    Sep 13, 2005
    Posts:
    1,543
    The first action this trojan do is attempt to set up its driver. If it fails, trojan stops its job.
     
  8. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    So nothing serious for a Sandbox. As I know Returnil failed against it but they are working to fix it.
     
  9. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    This leads to another interesting approach. A person I know, who is in the security business, will never install a new exe file for at least 30 days. He will scan it when he gets it, wait 30 days, and then scan it again. The assumption is if it contains a new in the wild virus, in 30 days the AV"s will catch up.
     
  10. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    I have a better idea. Submit the file to Kaspersky, Grisoft, or Avira.

    In all seriousness, though, I don't think any security company employee worth his salt will ever dream of making this assumption.
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Explain Please?
     
  12. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Very simple. Plenty/some threats go undetected even past 30 days, depending on which product you're using.
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Aigle, just to clarify, my questions were not directed at you personally. :)

    Yes I know, I just wondered if someone has got any samples, I would like to test NG. And I wonder what happened to nicM?

    No you didn´t, just wanted to give some extra/general info.

    @ alfa1, thanks for letting me know, I completely missed the thread, so seems like it was a flaw in PS.
     
    Last edited: Jan 26, 2008
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    What a bummer, I´ve tested it, and NG can´t protect against the SSDT Unhooker, eventhough it does try to block direct memory access. Like I said before, NG is quite powerful (will stop most attacks, if you kill the malicious process soon enough) but it needs to become more robust, it simply can´t stop certain stuff, even if it tries to. Would be nice if Arman would start development again, or would make the thing open source. :)
     
  15. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Now I don,t hope NG,s development will ever be satisfactory. I really liked it but it,s stangnant and gives me off and on BSODs. I just removed it from my system.
     
  16. LUSHER

    LUSHER Registered Member

    Joined:
    Feb 28, 2007
    Posts:
    440
    If it were open source are YOU going to develop it further? :D
     
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    You mean you don´t think it will ever become a stable program I assume. And yes I noticed that you removed it from your system, and switched to TF and CFP! Eventhough I also use 2 HIPS, IMO it looks a bit like overkill to me, and not really an option for me since I don´t like those apps. But I might switch to EQS. It´s really a pity that both SSM and NG seem to be pretty dead, they both could be a lot better. But still, they are capable to stop most of the tests mentioned in this thread.

    I wish I could do it! :D No seriously, I still think that HIPS could be a lot easier to use, so I do think that I could improve it when it comes to usability, but when it comes to programming I don´t know a thing.
     
    Last edited: Feb 13, 2008
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.