Slashdot Mirror


Old Malware Tricks Still Defeat Most AV Scanners

SkiifGeek writes "A year ago Didier Stevens discovered that padding IE malware with 0x00 bytes would happily slip past most of the scanners in use at VirusTotal.com. Revisiting his earlier discovery, Didier found that detection on his initial samples had improved, but not by much. For all the talk of AV companies moving away from signature based detection to heuristics, it is painfully obvious that not many of the tested engines can successfully handle such a simple and well known obfuscation method and the best of those that can detect the obfuscation can only detect it as a generic malware type. At least the scanning engines that can detect the presence of malware with the obfuscation aren't trying to claim each differential as a new variant."

13 of 122 comments (clear)

  1. Fir0x00st! by fph+il+quozientatore · · Score: 5, Funny

    Fir0x00st!

    --
    My first program:

    Hell Segmentation fault

    1. Re:Fir0x00st! by Zencyde · · Score: 4, Funny

      Strangely, the 0x00 exploit even works on Slashdot... you've somehow gotten a "first post" to +5 Funny. If that's not hacker-worthy, I don't know what is.

      --
      What day is it? Could you please tell me?
  2. Padding with 0x00 bytes? by glindsey · · Score: 5, Funny

    So padding it with nothing makes it undetectable? I never thought of that!

    1. Re:Padding with 0x00 bytes? by floorpirate · · Score: 2, Funny

      If someone ever figures out how to translate 0x00 bytes into something that can affect human senses, they'll have developed the Somebody Else's Problem field!

      --
      For every action there is a completely absurd lawsuit.
    2. Re:Padding with 0x00 bytes? by Zencyde · · Score: 2, Funny

      Wow.. that analogy made sense. I propose Slashdot move from car analogies to Superman analogies. All in favor?

      --
      What day is it? Could you please tell me?
  3. uh oh by gEvil+(beta) · · Score: 4, Funny

    At least the scanning engines that can detect the presence of malware with the obfuscation aren't trying to claim each differential as a new variant.

    Don't give the guys in marketing any ideas. "New and Improved! FoobarAV now detects an infinite number of viruses! Compare that with Norton's piddly 30,000."

    --
    This guy's the limit!
    1. Re:uh oh by sexconker · · Score: 4, Funny

      Detects 70%* of viruses, 60%** of malware, 20% of trojans***, and 1% of rootkits****!

      *Includes false positives
      **Includes tracking cookies
      ***Any generic threat found is counted as a virus and a trojan
      ****Removal of rootkits is not supported in AV Total Security Home 2008 + Firewall. To remove rootkits, you must purchase the value-add Anti-Rootkit Pro module.

    2. Re:uh oh by zappepcs · · Score: 4, Funny

      Pardon me young man. You do work here, don't you?

      Well, yes, you can help me. I was just wondering if you can explain the differences between the Value-add Anti-Rootkit Pro module and the Value-add Anti-Rootkit Amateur module.

      You see, my wife doesn't think I should be messing with anything for professionals, so I need to know the differences.

    3. Re:uh oh by jgtg32a · · Score: 2, Funny

      Not so much anymore most virus's these days just want to leach your bandwidth and DOS someone else, there is less of a performance loss when compared to most AV software

  4. IDW by Anonymous Coward · · Score: 2, Funny

    This is the dirty secret of desktop / on-access antivirus scanners; they don't work.

    F.D., I work in the industry, and the sole exception from this rule is my own employer's product, xxxxxxxxxxxx, of course.

  5. Old Jedi Malware Tricks by whitehatlurker · · Score: 4, Funny

    These0x00are0x00not0x00the0x00softwares0x00you0x00are0x00scanning0x00for.

    --
    .. paranoid crackpot leftover from the days of Amiga.
  6. Re:Antivirus/Antispyware 2009 by kv9 · · Score: 2, Funny

    ultimately running any AV software is a joke if you know how to use your computer correctly and don't download goat pr0n and warez

    I've been downloading goat pr0n and warez for years, and I'm OK. well, my computers are.

  7. Virus scanners don't stop malware? really... by crossmr · · Score: 2, Funny

    That's like saying bug repellent is no good against tigers. News at 11!