I am a malware researcher and security analyst for a mid-sized global manufacturer. These are some of the incidents I come across frequently.
Friday, July 13, 2012
Follow up for Gataka /Tatanga Submission
Microsoft missed the point of all the files I submitted them.
I knew that all of them were malware, I just wanted them to get the signatures in their definitions to protect others. Out of the last batch of 6 files I sent, 5 of them were samples of the malware as it resides on the system after it was dropped.
The last file, which they firmly placed the words "not malware" next to, IS THE ACTUAL EXECUTABLE THAT CREATED ALL OF THE OTHER FILES I SENT THEM!!!!
So the genius that looked at the files either didn't read the instructions and the cautions that I sent them and proceeded to barrel forward
VirTool:Win32/Obfuscator.ZC is what they come up with... bully for them.
Here is their reply with their results for the files I sent them:
Gataka.zip [Container]
+---2807784521.exe.vir [Not Malware] <========= THIS IS THE DROPPER!!!!
+---AdVantage.exe.vir [VirTool:Win32/Obfuscator.ZC]
+---AdVantage.exe.vir [VirTool:Win32/Obfuscator.ZC]
+---googletalk.exe.vir [VirTool:Win32/Obfuscator.ZC]
+---googletalk.exe.vir [VirTool:Win32/Obfuscator.ZC]
+---Skype.exe.vir [VirTool:Win32/Obfuscator.ZC]
So I have replied back to them trying to, once again, explain that the file they say isn't malware is actually the cause of the whole thing.
Another update if I ever hear back.
P.s. they even had the nerve to tell me that their detection for this was published on June 21. Funny... I submitted these files on July 2 and they didn't detect them.
Just one more piece of proof that the bad guys are ahead. Hell, there's likely better money in it.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment