Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Dismal AV detection on recent "American Airlines" spam payload

23 views
Skip to first unread message

Virus Guy

unread,
Apr 13, 2013, 2:34:59 PM4/13/13
to
I've been getting at least 1 spam a day over the past week with a link
that claims to be an American Airlines e-ticket (or something to that
effect).

The link is to a zip file. After I unzip and submit the .exe to VT, the
detection rate is a consistent 6 or 7 out of 44.

Some of the "big names" in the malware game (Symantec, Microsoft, Trend,
McAffee, AVG, Avira, and sometimes Kaspersky) are failing to detect
these files as a threat, even after re-submitting a few days after the
first scan.

What a joke.

Virus Guy

unread,
Apr 14, 2013, 1:37:23 PM4/14/13
to
Anyone waiting for their American Airlines ticket receipt?

Well, here it is:

hxxp://www.blackgospelvoice.com/components/.tch2em.php?ticket=_

Currently, that link is still working, and blackgospelvoice.com resolves
to 174.121.8.194.

Shoving the .exe file at VirusTotal reveals that the same file had been
scanned 3 hours prior, giving these results:

=================
https://www.virustotal.com/en/file/64b3758168dc6343db18da768850c9bee63e990863e1d0419e9fcab973a07319/analysis/

Detection ratio: 5 / 46
Analysis date: 2013-04-14 13:14:12 UTC ( 2 hours, 51 minutes ago )

ByteHero Trojan.Malware.Obscu.Gen.004
Kaspersky UDS:DangerousObject.Multi.Generic
Malwarebytes Trojan.Agent.TSV
SUPERAntiSpyware Trojan.Agent/Gen-Faker
VBA32 BScope.Trojan-Dropper.8612
===================

A very poor detection rating. Having it perform a re-analysis gives one
extra result:

===================
https://www.virustotal.com/en/file/64b3758168dc6343db18da768850c9bee63e990863e1d0419e9fcab973a07319/analysis/1365955648/

Detection ratio: 6 / 46
Analysis date: 2013-04-14 16:07:28 UTC ( 0 minutes ago )

McAfee Ransom-FBNH!A0B5819A0CF9
====================

RayLopez99

unread,
Apr 15, 2013, 1:49:42 PM4/15/13
to
On Monday, April 15, 2013 1:37:23 AM UTC+8, Virus Guy wrote:
> Anyone waiting for their American Airlines ticket receipt?
> Detection ratio: 6 / 46
>

Damn you're dumb. Do you think anybody would run a file that had *any* detections? You have six, and you think that's not warning enough?

RL

Message has been deleted

FromTheRafters

unread,
Apr 15, 2013, 5:00:27 PM4/15/13
to
RayLopez99 has brought this to us :
The executable drops another executable and a text file and executes
the dropped executable which displays the text file while doing other
maliciousness.

Some malware from two weeks ago is still only 9 of 46 on VT.


Virus Guy

unread,
Apr 15, 2013, 5:28:54 PM4/15/13
to
FromTheRafters wrote:

> Some malware from two weeks ago is still only 9 of 46 on VT.

Try this one:

==================
hxxp://premierplayers.com/components/com_docman/pdf_ftc_consumer_complaint.zip

premierplayers.com = 173.201.185.78
==================

As of about 4 hours ago, VT was reporting a hit-rate of 4/47.

https://www.virustotal.com/en/file/630d583b19acb686453ed2b0e252af887eb04c2fcd60e7725aac1d3da185bc6e/analysis/

ESET-NOD32 a variant of Win32/Kryptik.AYUB
Kaspersky Trojan-Spy.Win32.Zbot.kjkb
Malwarebytes Trojan.Agent.BDAVGen
McAfee-GW-Edition Heuristic.BehavesLike.Win32.ModifiedUPX.C

FromTheRafters

unread,
Apr 15, 2013, 6:04:41 PM4/15/13
to
Virus Guy formulated the question :
Screensaver file with PDFlike icon unpacks into binary files.
Definitely malware - accesses the address book and macromedia history
among other things.


FromTheRafters

unread,
Apr 15, 2013, 6:09:12 PM4/15/13
to
Virus Guy has brought this to us :
A batch file too:
=======================================================================
@echo off
:d
del "C:\Documents and
Settings\user-1\Desktop\pdf_ftc_consumer_complaint\pdf_ftc_consumer_complaint.scr"
if exist "C:\Documents and
Settings\user-1\Desktop\pdf_ftc_consumer_complaint\pdf_ftc_consumer_complaint.scr"
goto d
del /F "C:\DOCUME~1\user-1\LOCALS~1\Temp\tmp68c49d2d.bat"
=======================================================================


mark lewis

unread,
Apr 15, 2013, 10:45:16 AM4/15/13
to
+ User FidoNet address: 1:3634/12.42
VG> From: Virus Guy <Vi...@Guy.com>

VG> Anyone waiting for their American Airlines ticket receipt?

VG> Well, here it is:

VG> hxxp://www.blackgospelvoice.com/components/.tch2em.php?ticket=_

VG> Currently, that link is still working, and blackgospelvoice.com
VG> resolves to 174.121.8.194.

VG> Shoving the .exe file at VirusTotal reveals that the same file had
VG> been scanned 3 hours prior, giving these results:

you know something? you'd get better results if you threw these at the virus
detection engines' maintainers and let them analyze it... virus total can't
tell you anything about it until the virus detection engines know about it...

FWIW: it seems that there are over 2000 web sites hosted on that IP...

project honeypot has it flagged here:
http://www.projecthoneypot.org/ip_174.121.8.194

that sites isn't even fully configured since it carries the default cpanel web
page on the "raw" IP... that's a pretty sad state of affairs since ThePlanet
owns that IP and they should be maintaining the system properly...

)\/(ark
+++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ The FidoNet News Gate (Huntsville, AL - USA) +
+ The views of this user are strictly his or her own. +
+ All data is scanned for malware by Avast! Antivirus +
+++++++++++++++++++++++++++++++++++++++++++++++++++++++

Virus Guy

unread,
Apr 16, 2013, 9:43:51 AM4/16/13
to
mark lewis wrote using an asinine quoting method:

> > Shoving the .exe file at VirusTotal reveals that the same file had
> > been scanned 3 hours prior, giving these results:
>
> you know something? you'd get better results if you threw these at
> the virus detection engines' maintainers and let them analyze it...

No I wouldn't.

What I'm testing here is the compentency of the entire anti-virus
industry.

I'm testing that industry by throwing current malware at them and see
how they respond. I'm throwing files at them that in theory they should
already have a line on. They should already have a response system that
includes a feed for these files to get into their own hands. They can
operate honey-pot e-mail addresses - can't they? It's cheap to do.
Email accounts that are long established and attract spam.

And by the way - those various companies which have their AV scan
engines hosted by VirusTotal - we're under the impression that there is
some sort of real-time feedback from VT to these companies regarding
these files that are submitted. Perhaps that feedback is just urban
legend?

RayLopez99

unread,
Apr 16, 2013, 1:46:19 PM4/16/13
to
On Tuesday, April 16, 2013 2:58:40 AM UTC+8, Dustin wrote:

>
> > Damn you're dumb. Do you think anybody would run a file that had
>
> > *any* detections? You have six, and you think that's not warning
>
> > enough?
>
>
>
> Depends on the detections Ray. Some legit software can cause bad
>
> detections due to internal file structures. I know, years still beyond
>
> what you can technically grasp; but that's how it is.
>

That's not true. The way these detections are done is though a hash signature, not 'internal file structures'.

Keep trying Dustbin, maybe some day you'll guess right.

RL

mark lewis

unread,
Apr 16, 2013, 5:16:49 PM4/16/13
to
+ User FidoNet address: 1:3634/12.42
> > Shoving the .exe file at VirusTotal reveals that the same file had
> > been scanned 3 hours prior, giving these results:
>
> you know something? you'd get better results if you threw these at
> the virus detection engines' maintainers and let them analyze it...

VG> No I wouldn't.

really?

VG> What I'm testing here is the compentency of the entire anti-virus
VG> industry.

no one can test for or protect against that which they know nothing about the
presence of, can they?? can you?

VG> I'm testing that industry by throwing current malware at them and
VG> see how they respond.

virus total is not "the industry"... it is but one company that has installed a
bunch of antivirus and malware detection programs... none of them are any more
reliable than their latest engines and rules... just like a chain is only as
strong as its weakest link...

VG> I'm throwing files at them that in theory they should already have
VG> a line on.

no, you are throwing files are virus total...

VG> They should already have a response system that includes a feed
VG> for these files to get into their own hands.

there is for every one that i've ever seen... you send the files in question
directly to them... not some third party source and expect that third party to
pass it along to everyone else... yo seem to be forgetting about the commercial
aspect of the industry and the "battle to be first" and "be on top as the best"
and such...

VG> They can operate honey-pot e-mail addresses - can't they? It's
VG> cheap to do. Email accounts that are long established and attract
VG> spam.

they do but that doesn't mean that they get sent these files by the those
groups who create them... you are having to access an infested site to acquire
them, aren't you? they, the actual files, aren't being sent to you... a link to
a distribution site is being sent... honey pots don't go and retrieve external
links... they do, however, suck up network data packets and store them for
analysis by humans... it is a long a tedious job...

VG> And by the way - those various companies which have their AV scan
VG> engines hosted by VirusTotal - we're under the impression that
VG> there is some sort of real-time feedback from VT to these companies
VG> regarding these files that are submitted. Perhaps that feedback is
VG> just urban legend?

i don't know what "feedback" you are talking about... when ever i come across
nefarious files, i send them to the companies that i have a business
relationship with... as such, since i do not do norton or mcaffee or m$
schtuff, they do not get anything from me... some of my associates may have
relationships with those companies and may pass the files on to them but no one
can force anyone to do such...

/me thinks your expectations are much too high... turn them down a few notches
and contribute to helping rather than testing and carrying on when your
expectations are not met ;)

mark lewis

unread,
Apr 16, 2013, 5:27:31 PM4/16/13
to
+ User FidoNet address: 1:3634/12.42
> Depends on the detections Ray. Some legit software can cause bad
> detections due to internal file structures. I know, years still
> beyond what you can technically grasp; but that's how it is.

R> That's not true. The way these detections are done is though a
R> hash signature, not 'internal file structures'.

the hashes are built based on the structures of the malware, ray... without
those structures to analyze and build against, there is nothing...

FromTheRafters

unread,
Apr 17, 2013, 7:17:09 AM4/17/13
to
RayLopez99 was thinking very hard :
> On Tuesday, April 16, 2013 2:58:40 AM UTC+8, Dustin wrote:
>
>>
>>> Damn you're dumb. Do you think anybody would run a file that had
>>> *any* detections? You have six, and you think that's not warning
>>> enough?
>>
>>
>>
>> Depends on the detections Ray. Some legit software can cause bad
>>
>> detections due to internal file structures. I know, years still beyond
>>
>> what you can technically grasp; but that's how it is.
>>
>
> That's not true. The way these detections are done is though a hash
> signature, not 'internal file structures'.

Hash based detection is only *one* of the ways these detectors work.
Probably the only detection method you have any chance at
understanding.


FromTheRafters

unread,
Apr 17, 2013, 7:28:34 AM4/17/13
to
Virus Guy used his keyboard to write :
> mark lewis wrote using an asinine quoting method:
>
>>> Shoving the .exe file at VirusTotal reveals that the same file had
>>> been scanned 3 hours prior, giving these results:
>>
>> you know something? you'd get better results if you threw these at
>> the virus detection engines' maintainers and let them analyze it...
>
> No I wouldn't.
>
> What I'm testing here is the compentency of the entire anti-virus
> industry.

No you're not, you only think that you are because you don't understand
things. Many of the samples you send to them may be detected locally by
context where the file submission scanners at VT have no context to go
by.
>
> I'm testing that industry by throwing current malware at them and see
> how they respond. I'm throwing files at them that in theory they should
> already have a line on. They should already have a response system that
> includes a feed for these files to get into their own hands. They can
> operate honey-pot e-mail addresses - can't they? It's cheap to do.
> Email accounts that are long established and attract spam.

You have no idea how many polymorphic forms of a single malware there
are out there and how quickly they are produced.
>
> And by the way - those various companies which have their AV scan
> engines hosted by VirusTotal - we're under the impression that there is
> some sort of real-time feedback from VT to these companies regarding
> these files that are submitted. Perhaps that feedback is just urban
> legend?

I know many of the submission services do indeed share their samples
with the AV/AM community. Those that don't are only helping the 'bad
guys' to hone their skills at evasion. There are *other* sites that
test your newly created malware against various engines and do not
share samples with the "good guys" - these are bad guys themselves
because of that.


Virus Guy

unread,
Apr 17, 2013, 10:15:00 AM4/17/13
to
FromTheRafters wrote:

(why are you quoting / responding to me through Lewis's post?)

> > What I'm testing here is the compentency of the entire anti-virus
> > industry.
>
> No you're not, you only think that you are because you don't
> understand things. Many of the samples you send to them may
> be detected locally by context where the file submission scanners
> at VT have no context to go by.

Are you saying that I would get different results if I had any of those
AV programs on my computer vs submitting the file to VT?

> > I'm testing that industry by throwing current malware at them
> > and see how they respond.
>
> You have no idea how many polymorphic forms of a single malware
> there are out there and how quickly they are produced.

Your statement does not address the point.

I stated that I am testing the entire AV industry (to the extent that
those 47 programs hosted by VT represents the industry).

I am testing them on a valid, "in the wild", currently circulating piece
of malware.

I am testing them to see which of them can, and can't, detect the
example file.

The test is a valid, real-life use-case test. If any one of them can't
detect the file as malicious the instant that it is unzipped on the
victim's computer, then it fails it's intended function as AV
protection. How can it possibly matter if the file is submitted to the
AV program for testing by VT, or if it's running on the victim's
computer?

You don't have to be an apologist for them by explaining what a tough
job it is, etc etc.

FromTheRafters

unread,
Apr 17, 2013, 11:19:25 AM4/17/13
to
Virus Guy explained on 4/17/2013 :
> FromTheRafters wrote:
>
> (why are you quoting / responding to me through Lewis's post?)
>
>>> What I'm testing here is the compentency of the entire anti-virus
>>> industry.
>>
>> No you're not, you only think that you are because you don't
>> understand things. Many of the samples you send to them may
>> be detected locally by context where the file submission scanners
>> at VT have no context to go by.
>
> Are you saying that I would get different results if I had any of those
> AV programs on my computer vs submitting the file to VT?

No, but I'm saying that it is entirely possible.
>
>>> I'm testing that industry by throwing current malware at them
>>> and see how they respond.
>>
>> You have no idea how many polymorphic forms of a single malware
>> there are out there and how quickly they are produced.
>
> Your statement does not address the point.

Yes it does, there will *always* be new samples for them to be exposed
to before their being able to recognize and detect them.
>
> I stated that I am testing the entire AV industry (to the extent that
> those 47 programs hosted by VT represents the industry).
>
> I am testing them on a valid, "in the wild", currently circulating piece
> of malware.
>
> I am testing them to see which of them can, and can't, detect the
> example file.

It is valid inasmuch as you can possibly see how quickly they develop
detection after you or someone else exposed them to it by having
submitted it to them. Especially if they have "Hash not found" when you
first submitted it as opposed to the "submitted two hours ago" that you
might get with a *new*ish sample.
>
> The test is a valid, real-life use-case test. If any one of them can't
> detect the file as malicious the instant that it is unzipped on the
> victim's computer, then it fails it's intended function as AV
> protection.

They will *all* fail this test at one time or another and it means
nothing. What matters is the time it takes for them to detect it after
they have been given a sample. That time is that "zero day" window of
opportunity that must be shortened as much as possible.

> How can it possibly matter if the file is submitted to the
> AV program for testing by VT, or if it's running on the victim's
> computer?

Context scanning as opposed to content scanning.
>
> You don't have to be an apologist for them by explaining what a tough
> job it is, etc etc.

I'm not, I'm just highlighting some aspects you are undoubtedly unaware
of.


Message has been deleted
Message has been deleted

mark lewis

unread,
Apr 17, 2013, 10:45:40 AM4/17/13
to
+ User FidoNet address: 1:3634/12.42
> > What I'm testing here is the compentency of the entire anti-virus
> > industry.
>
> No you're not, you only think that you are because you don't
> understand things. Many of the samples you send to them may be
> detected locally by context where the file submission scanners
> at VT have no context to go by.

VG> Are you saying that I would get different results if I had any of
VG> those AV programs on my computer vs submitting the file to VT?

you might if you have newer rules or engine than VT has... you would also have
a more direct line for the reporting and delivery of the stuff you find that is
bad...

> > I'm testing that industry by throwing current malware at them and
> > see how they respond.
>
> You have no idea how many polymorphic forms of a single malware
> there are out there and how quickly they are produced.

VG> Your statement does not address the point.

granted but you are not testing the industry like you think you are ;)

VG> I stated that I am testing the entire AV industry (to the extent
VG> that those 47 programs hosted by VT represents the industry).

no, you are testing VT and their installed library of those 47 programs...
nothing more...

VG> I am testing them on a valid, "in the wild", currently circulating
VG> piece of malware.

testing VT, yes...

VG> I am testing them to see which of them can, and can't, detect the
VG> example file.

that's given but you still do not know if they have the latest signatures
installed or even the latest engines...

VG> The test is a valid, real-life use-case test.

sorry but no... it is not...

VG> If any one of them can't detect the file as malicious the instant
VG> that it is unzipped on the victim's computer, then it fails it's
VG> intended function as AV protection. How can it possibly matter if
VG> the file is submitted to the AV program for testing by VT, or if
VG> it's running on the victim's computer?

a has been stated many times in many areas, chasing viruses and malware is just
that... chasing... the AV and AM industries will never be able to get ahead of
the folks that create those things... the AV and AM industries have no choice
but to follow and hope they can get examples of everything and that is never
going to happen...

Virus Guy

unread,
Apr 17, 2013, 7:04:52 PM4/17/13
to
Why do you strip the "Re:" from the Subject line in your replies?

You are the only person in the 20-odd years that I've been on usenet to
see do that.

Smart'en up and configure your usenet software to adhear to
well-established conventions.

It's also NOT necessary to include the initials of the person you are
quoting infront of each quoted line.

mark lewis wrote:

> > Are you saying that I would get different results if I had any of
> > those AV programs on my computer vs submitting the file to VT?
>
> you might if you have newer rules or engine than VT has...

I'm sure that most of us here are under the impression that VT is always
using the most recent scan engine(s) and viral def'n files for the AV
software that it runs.

What would be the point of setting up and running such a service for
several years now if they didn't do that?

> you would also have a more direct line for the reporting and
> delivery of the stuff you find that is bad...

Where are you Lipman?

Why don't you speak up and settle the score here regarding Virus Total
(Hispasec Sistemas) and what their connection is to the AV companies
who's products they operate as a form of public portal. Does VT have
the most current scan software / definitions, and do they have any sort
of feedback mechanism to forward suspicious files back to the AV
industry?

Buffalo

unread,
Apr 18, 2013, 2:54:46 PM4/18/13
to
"Virus Guy" wrote in message news:516F2A94...@Guy.com...
In my experience VT does not always have the latest definition updates. How
far behind they may be for their various engine and def updates, I don't
know.
Buffalo

James W. Anderson

unread,
May 3, 2013, 12:03:34 AM5/3/13
to
I've heard some AV vendors don't even report to Virustotal.

Blue Coat often finds many more sites that have a particular virus
spreading package on it than most other AV vendors do or that
Virustotal has as well. Case in point: The recent Sweet Orange
rootkit. Virustotal only found under ten. Blue Coat said in a blog
post they found 263 sites that had that malware.

Virus Guy

unread,
May 3, 2013, 3:55:33 AM5/3/13
to
"James W. Anderson" wrote:

> I've heard some AV vendors don't even report to Virustotal.

What would an AV vendor report to VT?

If anything, as stated by Dave Lipman, VT reports (sends) malware
samples to the AV vendors.

> Blue Coat often finds many more sites that have a particular virus
> spreading package on it than most other AV vendors do or that
> Virustotal has as well.

To my knowledge, VT doesn't scan or analyze websites.

You don't give VT a URL to scan. You give it a file. It then scans the
file on 40-odd AV/AM products that either it runs locally or that it
submits in real time to individual AV vendors.

> Case in point: The recent Sweet Orange rootkit. Virustotal only
> found under ten. Blue Coat said in a blog post they found 263
> sites that had that malware.

I'm not aware that you can submit URL's to VT for analysis, or that VT
somehow performs autonomous discovery of malicious sites. Please
explain.
0 new messages