Author Topic: Subject: Encrypted Mail System - New Worm  (Read 15893 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: Subject: Encrypted Mail System - New Worm
« Reply #15 on: April 29, 2006, 11:19:27 PM »
Yes very interesting.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #16 on: April 30, 2006, 08:22:30 PM »
Got a new variant in my mailbox today. Symantec missed it again. Antivir and AVG's generic definitions picked it up but avast! missed it.

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Subject: Encrypted Mail System - New Worm
« Reply #17 on: May 01, 2006, 04:33:34 AM »
Got a new variant in my mailbox today. Symantec missed it again. Antivir and AVG's generic definitions picked it up but avast! missed it.
Will I see the day that NOD32 and Kaspersky do not detect a malware?  ;D
The best things in life are free.

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: Subject: Encrypted Mail System - New Worm
« Reply #18 on: May 01, 2006, 01:42:46 PM »
well i yesterday got another new variant (not subvariant) ... oh well :)
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #19 on: May 01, 2006, 04:35:00 PM »
I think I was wrong to call the file I got a new variant: rather each HTML file sent out is different because this is a polymorphic worm.

In another thread we read that avast! has successfully identified the polymorphic virus Polipos: a generic detection of this worm (which Antivir and AVG manage) is needed.

No rest for the virus analyst!!
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #20 on: May 01, 2006, 10:25:00 PM »
Well, Ewido added this sample after 24 hours. If it is a polymorphic worm and every sample is different, then adding a definition for every sample submitted rather than developing a generic definition may not be particularly effective in preventing infection, but it is impressive that they can respond so quickly...
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: Subject: Encrypted Mail System - New Worm
« Reply #21 on: May 07, 2006, 01:35:16 AM »
and another two variants EG and GM ...

and You know what sux,  Antivir with last database update 20.4.2006 is able detect most of them

yes Avast! not , oh well :(
« Last Edit: May 07, 2006, 01:39:26 AM by Dwarden »
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #22 on: May 07, 2006, 09:18:57 AM »
Igor did some good work in detecting the polymorphic virus Polipos:

http://forum.avast.com/index.php?topic=20859.0

But at the moment both Antivir and AVG's generic detections are managing to catch Feebs, and avast! is not doing so well.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: Subject: Encrypted Mail System - New Worm
« Reply #23 on: May 11, 2006, 04:06:06 PM »
todays 0619-2 added some Feeb variants and was able detect 3 from my list ...

yet there are still 4 variants (28 different files) undetected  ...
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #24 on: May 18, 2006, 11:36:37 PM »
avast! is now on a par with CAT-QuickHeal, F-Prot and UNA:



What happened guys?  ???  :'(
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #25 on: December 04, 2006, 12:41:51 AM »
Still undetected.  :-[

Should I send this again?  ???



     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Subject: Encrypted Mail System - New Worm
« Reply #26 on: December 04, 2006, 12:56:51 AM »
Still undetected.  :-[
Should I send this again?  ???
Frank... you know this won't be necessary.
I wish they take your sample in account and improve detection  :-X
The best things in life are free.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #27 on: December 04, 2006, 10:06:55 AM »
Well, I've just sent the original Feebs plus the later variant (which also remains undetected) again. I hope avast! can add them, or preferably improve its generic detection, because it seems to be way behind almost every other AV. 
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #28 on: March 03, 2007, 04:14:14 PM »
Well, 10 months now, and still not detected. Is this a record?

The only change is that AntiVur no longer detects this file. Weird!

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Subject: Encrypted Mail System - New Worm
« Reply #29 on: March 20, 2007, 11:34:21 AM »
Finally got a detection today for one of these files:



However, the other file is still missed.

I'll try submitting it through the chest and see if we can better 10 months before detection this way.  :P
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog