Author Topic: Scanning to analyze executables.....at novirusthanks.org  (Read 3265 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Scanning to analyze executables.....at novirusthanks.org
« on: April 09, 2009, 02:40:43 PM »
Hi malware fighters,

Why should we do this? Because a large amount of malware have protection against AV detection and cannot therefore be easily traced, but you yourself may establish it to be malware. Online here:
http://scanner.novirusthanks.org  there is an option to analyze the ASCII code of the .exe you scanned,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

CharleyO

  • Guest
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #1 on: April 09, 2009, 07:12:54 PM »
***

Nice find, Polonus.

I tried it out, liked the way the results were presented, and the extra information given.


***

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #2 on: April 09, 2009, 08:56:12 PM »
Can you make this scan locally?
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #3 on: April 09, 2009, 09:02:00 PM »
Hi Tech,

From your question and reaction  I see you haven't been there yet, because it says there in their disclaimer:
Quote
NoVirusThanks.org (NoVirusThanks Virus & Malware Scan Service) is not substitute for any antivirus software installed in a PC, as it only scans individual files on demand. These results DO NOT guarantee the harmlessness of a file. Currently, there isn't any solution that offers a 100% effectiveness rate for detecting malware. You may be a victim of misleading advertising, if you buy such a product under those premises. This website DOES NOT compare Anti-Virus.
(Bold text by me, Polonus)

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #4 on: April 09, 2009, 09:07:49 PM »
I see you haven't been there yet
Got me... yeah, I did not go there ;D
Well, it requires upload the file and does not allow local scanning... I thought I'll have an option and I realize I don't have one.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #5 on: April 09, 2009, 09:17:06 PM »
Well Anubis: Analyzing Unknown Binaries, could be another though some try to avoid this too.

http://anubis.iseclab.org/?action=home

But it is a single detailed analysis of a file not a multiple engine scan.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #6 on: April 09, 2009, 09:20:41 PM »
Hi DavidR,

Can you give the reason why some want to avoid this?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Scanning to analyze executables.....at novirusthanks.org
« Reply #7 on: April 09, 2009, 09:34:59 PM »
There are some malware variants that try to avoid detection by blocking certain detection AVs and methods. I really don't know how they would go about it something I read today in this topic, http://www.wilderssecurity.com/showthread.php?t=238372#post1440149.

I don't know if having managed to identify and upload the file since it wouldn't be running I really don't know how it might hide its intent/purpose from Anubis.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security