in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

Last post 09-03-2008 12:08 AM by Blue1978. 20 replies.
Page 2 of 2 (21 items) < Previous 1 2
Sort Posts: Previous Next
  • 08-13-2008 8:58 AM In reply to

    Re: Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

    Spunner:
    Can we get protection from this?  I sold them on using Blink because of its hardened security (I know it's a cat-and-mouse game) but we're pretty smart cats!

    I don't doubt that, there are so many variants of it, it is sickening.  Being able to stop them all is going to be difficult.  I have personally sent eEye like 4 different versions of it now (pretty much same general file name) but with different MD5 hashes.

    Here are two other versions of it that I found and that I have tickets on pending with Norman.  eEye has already sent them in and we are waiting on a signature to be made for them.

    Name: AV2009Install_880174.exe

    MD5: 2f772504e41a9a0a1b55c564f0601818

    Name: AntvrsInstall.exe

    MD5: a114da736592860009233c6ddaab4692

    -------------------------------------------------------------------------------- 

    My personal recommendation is to create two rules:

    1. One IPS signature that blocks any email attachment with the file extension of:  .exe, .dll, .com, .php, and .bat  ... you might go as far as to block .txt also.

    2. One System Protection signature (Under the "Execution Protection" tab) that keeps anything in Outlook (link, file, etc) from opening IE or Firefox (whatever one your using for your browser) that has the following:

    Type of System ResourceExecution

    Specifiy the Executable that this rule will protect against:  "C:\Program Files\Internet Explorer\iexplore.exe"

    - Match the type:  Partial

    - Do not use executable MD5 (in the bottom part)

     Specifiy the Parent Process that this rule will filter against:  (This would be the path to the Outlook executable)

     - Match type: Wildcard

     - Do not use parent process MD5

    ------------------------------------------------------------------------------------

    I have also gone overboard and made individual new rules that were copies of the top rule (for Adobe Acrobat under the "Execution Protection" tab) but are for blocking the following from opening the "cmd.exe":

    Microsoft Word

    Microsoft Excel

    Microsoft Powerpoint

    Windows Word Notepad

    ----------------------------------------------------------------------- 

    Do you know for a fact there was an actual attachment?  If not I will bet on it being imbedded code of some nature: HTML or maybe even scripts imbedded in images (used a lot to bypass Phishing security measures) that ran itself when the pane viewer displayed it.  At that point it probably downloaded the executable to your system from the internet and ran it.

  • 08-13-2008 11:32 AM In reply to

    Re: Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

    Blue1978:
    Name: AV2009Install_880174.exe

    MD5: 2f772504e41a9a0a1b55c564f0601818
     

    Now Detected as:

    Event ID: BLINK-ENG-202
     Severity: Medium
     Description: Blink has disinfected the system after malware was detected
     Quarantine Location: 01C8FD71-E09804D0-0-W32/FakeAV.G
     Action: Quarantined
     Item Found: G:\VMWare\Live Malware (Warning!)\#14\AV2009Install_880174.exe
     Alert: No
     Name:

    W32/FakeAV.G

     

     

    Blue1978:
    Name: AntvrsInstall.exe

    MD5: a114da736592860009233c6ddaab4692

     

    Now Detected as:

     

    Event ID: BLINK-ENG-202
     Severity: Medium
     Description: Blink has disinfected the system after malware was detected
     Quarantine Location: 01C8FD71-ED63E3DC-0-W32/Renos.AEK
     Action: Quarantined
     Item Found: G:\VMWare\Live Malware (Warning!)\#7\AntvrsInstall.exe
     Alert: No
     Name: W32/Renos.AEK

     

     

  • 08-13-2008 7:47 PM In reply to

    Re: Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

    Found yet another variant of this junk tonight!  Waiting on a signature for it now.


    Name:    IAInstall.exe

    MD5:    d93c308f8a4c3e58e6bdace73390d5fb

  • 08-15-2008 11:47 AM In reply to

    Re: Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

    Blue1978:
    Name:    IAInstall.exe

    MD5:    d93c308f8a4c3e58e6bdace73390d5fb
     

     

    Now detected as:

    Event ID: BLINK-MAL-205
     Severity: High
     Description: Blink has found a malware application
     Virus found: W32/DLoader.IXRX
     Item found: G:\VMWare\Live Malware (Warning!)\#7\IAInstall.exe
     Action: Quarantine
     Alert: Yes
     Name: W32/DLoader.IXRX
     Second Action: Log Only
     Category: Trojan
    Filed under:
  • 08-26-2008 1:37 AM In reply to

    Re: Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

    Yeah, the infamous "reading pane". Can you disable it? It's the first and only protection you get in Outlook :D

    Best,

    Art

  • 09-03-2008 12:08 AM In reply to

    Re: Antivirus 2009 malware not detected by Blink 4.04 (with all the patches)

    What version of Outlook are you using?  In Outlook 2003 you would have to do the following for each folder:

    1. Select the folder you want to disable the preview pane on.

    2. Go to View >> Reading Pane, and then mouse over to select "Off"

    Other Items to consider: 

    - Keep in mind Outlook uses the "Internet" zone security settings in IE for its security.  If this zone is set low, a lot will be allowed to happen in Outlook email messages.

    - In Outlook 2003 I recommend also tightening up its security a bit by making the following setting changes:

    1. Under Tools >> Options >> Preferences Tab

        - Select the "E-mail Options" button

           1a. Make sure the "Read all standard email in text" and "Read all digitally signed mail in plain text" have their boxes checked

           1b. At the bottom I would recommend setting "Include original message in text" be set for the "when replying" and "when forwarding" fields.

    2. Under the Mail Format Tab

         - for the "Compose in this message format"  set this to:  Plain Text

    3. Under the Security Tab

         - Make sure the Security Zones section has the "Internet" zone selected in the filed that is visible.

     

    These are my personal recommendations for tightening up security a little bit in Outlook 2003.

    Filed under: ,
Page 2 of 2 (21 items) < Previous 1 2
© 1995 - 2009 eEye Incorporated