Only 65% of AV software detected hidr.exe as Bagle / Mitglied

Only 65% of AV software detected hidr.exe as Bagle / Mitglied

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Only 65% of AV software detected hidr.exe as Bagle / Mitglied Virus Guy 09-01-2007
Posted by Virus Guy on September 1, 2007, 10:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
This is really sad.

I've got a sample of hidr.exe (06/24/2005) and it's only detected by
21 of the 32 AV packages on VirusTotal.

Here's the results if you want to see them:

http://www.virustotal.com/resultado.html?4ffb71ab220a0c3600b76166b2b2b33f

And for Symantec, this lack of detection is undefensible.

Why doesn't VT show the packing used, or the Norman sandbox details?

Posted by on September 2, 2007, 2:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Looks like I'll be adding a few more MD5s to the next database
update. Thanks for the info.


Posted by Dustin Cook on September 7, 2007, 1:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> This is really sad.
>
> I've got a sample of hidr.exe (06/24/2005) and it's only detected by
> 21 of the 32 AV packages on VirusTotal.

The sample you have, is it just a variant of a something already known?
And how well has it spread? If it hasn't done so well, that may explain
why many of the virus scanners don't bother to detect it.

and of course, you have the often overlooked scenario: they just don't
have a signature for that variant and the hueristics if used aren't
picking it up either.

Since you submitted it to virustotal, they should eventually all get
samples of the file in question. This is why I advocate sending
suspicious files to the vendors directly if at all possible. If you find
something that is missed and you think it shouldn't be, send it to your
favorite antivirus/antimalware company (and send it to myself too! You'll
be contributing to the growing BugHunter userbase). The faster the
samples arrive, the sooner products will have the required information to
identify and possibly remove them.

> Here's the results if you want to see them:
>
> http://www.virustotal.com/resultado.html?
4ffb71ab220a0c3600b76166b2b2b33f

> And for Symantec, this lack of detection is undefensible.

> Why doesn't VT show the packing used, or the Norman sandbox details?

VT may not know the packer used; it could be a known packer but slightly
modified to evade automated detection.

That url expires shortly after being created. :(


--
Dustin Cook, Author of BugHunter - MalWare Removal Tool - v2.2d
Email.: bughunter.dustin@gmail.com
Web...: http://bughunter.it-mate.co.uk
Pad...: http://bughunter.it-mate.co.uk/pad.xml
PGP...: http://bughunter.it-mate.co.uk/bughunter.dustin.txt

Similar ThreadsPosted
Glieder (aka Bagle, version eightysomething) June 2, 2005, 6:14 pm
A squared false positives for bagle? June 15, 2005, 8:59 pm
SYSTEM RESTORE BAGLE WORM November 12, 2005, 8:11 pm
Modern times - nice malware example: Bagle... December 8, 2005, 11:11 am
McAfee DAT v4585 dat files have been released due to mutliple new variants of Bagle September 19, 2005, 10:00 pm
I Have a virus - but it's not being detected March 16, 2006, 2:53 am
How are new viruses detected? June 19, 2006, 5:25 pm
Mitglieder-M Detected by Avast October 19, 2005, 6:40 pm
quicktime integer overflow detected by nav March 21, 2006, 1:42 pm
Java ByteVerify - detected, but is it a problem ? July 23, 2006, 12:25 pm

The site map in XML format XML site map

Contact Us | Privacy Policy