Author Topic: New Cloud Malware Family Relation scanner simseer  (Read 3250 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
New Cloud Malware Family Relation scanner simseer
« on: May 27, 2013, 07:42:47 PM »
New Cloud- malware family virus scanner, example: http://www.simseer.com/webservices/SimseerSearch/example/SimseerSearch.html
Experimental service to score the similarity between software such as malware... developer Silvio Cesare

http://www.simseer.com/webservices/SimseerSearch/SimseerSearch.html
http://www.simseer.com/webservices/SimseerCluster/SimseerCluster.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: New Cloud Malware Family Relation scanner simseer
« Reply #2 on: May 27, 2013, 09:30:52 PM »
Hi Polonus,

Would you care to provide another example? This scanner looks rather interesting.

~!Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: New Cloud Malware Family Relation scanner simseer
« Reply #3 on: May 27, 2013, 10:15:24 PM »
Hi !Donovan,

Here an example for which there were no matches: http://www.simseer.com/webservices/SimseerSearch/SimseerSearch-print-report.php?h=6016e3252a72c8b57f7181031ad094d9
Another example:
Filename   bdadbaafbcfbccdefdbbcabbcdcfc
Hash   5a00910dc058aae28f4b7741bad97959

In our "virus and worms"section victims could be asked not only to upload to VT but also to this service that will search for subtle patterns that the malware at hand shares with known familiar malware, sort of a "malware DNA scan" as a way to put this... The developer hopes this will enhance detection of so-called polymorphic malware that often goes under the normal av detection radar...

I think it would be great to combine these results, with VT's, anubis analysis results and attack logs found at VirusWatch MX Clean, quttera's  etc. Also IDS alert patterns for particular malware could be taken into considerationm like netquery dot url gives them...

polonus
« Last Edit: May 27, 2013, 10:17:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: New Cloud Malware Family Relation scanner simseer
« Reply #4 on: May 27, 2013, 10:45:00 PM »
Hi !Donovan,

Another interesting resource, stumbled upon these through results by googling for the "best of kin" of this malcode hash: https://www.google.nl/search?q=9fc1648a3188efef3eb29c4afe34f840&oq=9fc1648a3188efef3eb29c4afe34f840&aqs=chrome.0.57&sourceid=chrome&ie=UTF-8

So another interesting resource here: http://christian-rossow.de/files/dataset-sandnet-chapter.txt

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: New Cloud Malware Family Relation scanner simseer
« Reply #6 on: May 28, 2013, 05:14:28 AM »
Hi Polonus,

Although the program itself is legit in this case, it's nice to know that the Simseer scanner did indeed find the suspicious elements present in this validation tool.

~!Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!