Author Topic: Unbelievable sample missed  (Read 59893 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
The best things in life are free.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Unbelievable sample missed
« Reply #1 on: March 29, 2010, 03:17:06 PM »
wow & oh no... :(
thanx 4 posting! :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Unbelievable sample missed
« Reply #3 on: March 29, 2010, 08:02:07 PM »
Hi Tech,

The infected file was names crack.exe
http://www1.virscan.org/report/4d9b96b5063b02ee2b3387e6b3fa6813.html
Even with a generic flag avast should not miss a term like crack.exe
Should come added:

Trojan.Agent.AOID

Threat Name:Trojan.Agent.AOID

Category:Trojan;Trojan.Agent

First seen:03-03-2010

Spread Level:1

Harmful Index:2

Reported By:Rising;Jiangmin;A-Squared;

Infected Countries:Denmark;Singapore;Ukrainian;

Advice:Uninstall;

Total Report:74737

And yet another missed one for malcode coming for a link in a "scare" mail (alleged copyright case document which is a trojan downloader - re: http://blog.chackraview.net/tag/rtf-embedexe-gen/
Result: 7/42 (16.67%))
http://www.virustotal.com/analisis/9b762ff9d2103022bf1476f2c55db91475f31526522716e827875801f92a0d87-1269486837

polonus
« Last Edit: March 29, 2010, 08:55:29 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

psw

  • Guest
Re: Unbelievable sample missed
« Reply #4 on: March 29, 2010, 10:05:14 PM »
Probably both files are packed with some strong packer. AV give too much FP during analisys of cracks and patches. The reason is obvious - malware and cracks are using the same packers and "detect" is really packer detect only.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unbelievable sample missed
« Reply #5 on: April 07, 2010, 10:53:28 PM »
I can't believe this files aren't recognized yet...
Is there any worth on submitting samples anyway? ::)
The best things in life are free.

Hermite15

  • Guest
Re: Unbelievable sample missed
« Reply #6 on: April 07, 2010, 11:11:52 PM »
yep, that's not good, not good at all... ::) even AVG gets them...but MSE doesn't ??? edit: MSE does catch one of them.
« Last Edit: April 07, 2010, 11:13:53 PM by Logos »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
The best things in life are free.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Unbelievable sample missed
« Reply #8 on: April 13, 2010, 03:24:36 PM »
This first samples AREN'T BEING DETECTED yet!

Didn't anyone send them to avast, yet...???
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Unbelievable sample missed
« Reply #9 on: April 13, 2010, 06:16:06 PM »
i suspect the detections are packer-based, not content based, but i may be wrong (anyway, Milos will try to revisit them)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Unbelievable sample missed
« Reply #10 on: April 13, 2010, 06:20:02 PM »
i suspect the detections are packer-based, not content based, but i may be wrong (anyway, Milos will try to revisit them)

Thanks a lot, Maxx..!! :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Unbelievable sample missed
« Reply #11 on: April 14, 2010, 07:31:37 AM »
Hello,
I didn't find the samples in our database. Can you send us them, please? If they are big you can upload them to ftp.avast.com/incoming and post here the uploaded name(s).

Milos

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unbelievable sample missed
« Reply #12 on: April 17, 2010, 03:59:48 PM »
I'll try to find the samples again... Can't you get them from Virus Total?
I'm very bad surprised how many samples does avast miss...

Here are more two of them:
http://www.virustotal.com/analisis/37aed9fb460d839a19a35489376f7568c874c6e3ae04ec991e67336f0fde267d-1271512515
http://www.virustotal.com/analisis/913d463352eee7bd9f8c4d2e341aeaf1396d22f2e6b90d47c3b8f110c0efdeb7-1271468500
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unbelievable sample missed
« Reply #13 on: April 17, 2010, 04:05:37 PM »
I've submitted 4 files from Chest... Did a manual update...
Are this way of submitting really working? I can't see any information while updating that the files are being uploaded ???
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unbelievable sample missed
« Reply #14 on: April 17, 2010, 04:09:13 PM »
Avast is loosing a lot of samples... C'mon, they're just cracks and keygens... a little P2P digging will find a lot of them... Isn't there anybody that loves to play with fire among you? :'(

http://www.virustotal.com/analisis/6f91aed7f9c68959ac0f2ca1cacb7931712f04bbec2dda6fd60484210a877fda-1271513193
The best things in life are free.