Author Topic: Samples missed by avast  (Read 30303 times)

0 Members and 1 Guest are viewing this topic.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89063
  • No support PMs thanks
Re: Samples missed by avast
« Reply #15 on: September 13, 2010, 12:16:14 AM »
Well I'm talking about the VT results link that you posted in reply #7 as that is effectively showing only bitdefender detecting anything. If that came from MDL then I would say that their 100% claim is dubious.

Your first VT results is entirely different to the second they aren't the same file which I was responding to.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security


WhiteZero

  • Guest
Re: Samples missed by avast
« Reply #17 on: September 13, 2010, 05:46:49 AM »
http://www.virustotal.com/file-scan/report.html?id=f1e384d3bc63a07b1bdfb4effd170e9745af1ae19dfb568d6984225dd436262f-1284349326
Submitted via Virus Chest.

Llanziel, I see you are a fan of the MalwareDomainList too.  ;)
« Last Edit: September 13, 2010, 05:49:02 AM by WhiteZero »

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Samples missed by avast
« Reply #18 on: September 13, 2010, 08:41:30 AM »
Well, its certainly a good source of FakeAV's. And some exploits, bots and other junk.
Visit my webpage Angry Sheep Blog

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Samples missed by avast
« Reply #19 on: September 13, 2010, 10:12:17 AM »
If you want, you can add MalwareDomainlist auto-update to yr Hosts file through HostMan Editor

edit - no idea why i have so many hphosts as update Sources, just happened that way.
« Last Edit: September 13, 2010, 10:18:27 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Samples missed by avast
« Reply #20 on: September 13, 2010, 10:23:37 AM »
Tech: Kazy and Zbot variants will be detected generically (we have some samples with a wider context available), other samples will be probably detected with some "regular" detections..

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
The best things in life are free.

iRonzel

  • Guest
Re: Samples missed by avast
« Reply #22 on: September 13, 2010, 03:54:47 PM »

Llanziel, I see you are a fan of the MalwareDomainList too.  ;)

That is correct! ;)

edit: also with Malware Patrol, http://www.malware.com.br/
« Last Edit: September 13, 2010, 03:58:07 PM by Llanziel »

iRonzel

  • Guest
Re: Samples missed by avast
« Reply #23 on: September 13, 2010, 04:00:36 PM »
What about: Trojan.Win32.Workir.agf

Is avast! detecting it???

http://www.threatexpert.com/report.aspx?md5=93c98cfc407afe3c3b3cd557643a160e

Burkoff

  • Guest
Re: Samples missed by avast
« Reply #24 on: September 13, 2010, 04:59:42 PM »
Hi, people.

hxxp://rapidshare.com/files/418820320/MONMVR32.7z

http://www.virustotal.com/file-scan/report.html?id=a3e0c19979eae982d6f8e084283423cda036488121d7ffc03024ace41f89e30c-1284313816

Please add in the virus database.
   And

hxxp://rapidshare.com/files/418826287/Trojan-SMS_for_Android_FakePlayer_RUapk.zip

http://www.virustotal.com/file-scan/report.html?id=25ca122c12a44e52a1d1971cd1ef8fe89be66e930e25f16732d273d6be2a7f53-1284134992





« Last Edit: September 20, 2010, 11:51:49 AM by igor »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89063
  • No support PMs thanks
Re: Samples missed by avast
« Reply #25 on: September 13, 2010, 05:32:45 PM »
Please modify your post and remove the link to the malware download. The samples should be sent directly to avast and not use the forums as some sudo malware distribution site. These forums are publicly available so you never know who might download it or what use they might put it to. Not to mention if it is an undetected sample then you put avast users at risk.

Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Samples missed by avast
« Reply #26 on: September 13, 2010, 05:42:02 PM »
@Maxx
Any chance to ever expect more of aggressive heuristics? Maybe as Ultra High/Aggressive sensitivity option (disabled by default) and with direct uploading of anything detected to your servers and tagged as [AdvHeur]?
Even though some may like very passive avast! response, i'd like to see a more aggressive approach, at least as optional thing. Wouldn't it be possible to use these aggressive detections to fine tune heuristics for lower levels so everyone can benefit. Casual users with strong but accurate heuristics and those security freaks (us) to have very strong heuristics with few more false positives. But it's easier to deal with false positive than real threat imo.
Visit my webpage Angry Sheep Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Samples missed by avast
« Reply #27 on: September 13, 2010, 05:53:11 PM »
Please modify your post and remove the link to the malware download.
Not necessary. Better change http for hxxp in the link. Then avast team has the information of the source of the file in my opinion.
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Samples missed by avast
« Reply #28 on: September 13, 2010, 06:00:44 PM »
direct uploading
Seems cloud technology... Are they prepared for that? Both on technology and servers side?
Besides this, I fully agree with you :)
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89063
  • No support PMs thanks
Re: Samples missed by avast
« Reply #29 on: September 13, 2010, 06:19:14 PM »
Please modify your post and remove the link to the malware download.
Not necessary. Better change http for hxxp in the link. Then avast team has the information of the source of the file in my opinion.

It is necessary as just changing the http to hxxp won't stop people downloading it they aren't stupid and we have no idea what they might do with samples that are undetected by avast.

This forum has to act responsibly when other avast users could be put at risk if some idiot decided to download and distribute these samples for malicious purposes.

I'm totally unconcerned with the link being active to rapidshare, I'm concerned with what people might do with the samples. If you want the virus labs team to get the samples then send them directly.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security