CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Submitting samples .

 
Post new topic   Reply to topic       All -> FavForums -> Malware Listserv [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Fri Dec 01, 2006 12:50 pm    Post subject: Submitting samples .
Reply with quote

Submit all malware samples here with MD5 and file name as the subject . If your collection methods rename the malware just post the MD5 as the subject . Post a single piece of malware per malware thread . Zip each sample with the password "infected" before attaching . Also post a complete virustotal log with each sample so we can all get a rough idea of how well your sample is detected .

If your file is an installer of some kind also post the file in the unknown files forum so we can collect additional samples and information .

Back to top
View users profile Send private message Send email
Maagiz

MIRT Hunter


Joined: Nov 04, 2006
Posts: 4
Location: Finland

PostPosted: Wed Feb 21, 2007 9:24 am    Post subject: Re: Submitting samples .
Reply with quote

nosirrah wrote:
Submit all malware samples here with MD5 and file name as the subject . If your collection methods rename the malware just post the MD5 as the subject . Post a single piece of malware per malware thread . Zip each sample with the password "infected" before attaching . Also post a complete virustotal log with each sample so we can all get a rough idea of how well your sample is detected .

If your file is an installer of some kind also post the file in the unknown files forum so we can collect additional samples and information .


Is there any good softaware to rename lots of files with them MD5?

Back to top
View users profile Send private message Yahoo Messenger MSN Messenger
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Mon Apr 02, 2007 7:20 pm    Post subject:
Reply with quote

From this point forward I am going to insist that all samples submitted here are detected by virustotal by no more than 50% of vendors .

Exceptions will be made for highly detected but only through heuristics (behaves like , possible variant of , DNA scan , suspicious ...) .

Back to top
View users profile Send private message Send email
pykko

MIRT Hunter


Joined: Jan 18, 2007
Posts: 736

MIRT

PostPosted: Mon Apr 16, 2007 1:09 pm    Post subject:
Reply with quote

one question: are these samples submitted by someone also to every AV company by e-mail or not ?


_________________
I want to know God's thoughts. The rest are details. - Albert Einstein
Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5865

MIRT Premium

PostPosted: Mon Apr 16, 2007 7:55 pm    Post subject:
Reply with quote

How often are the samples sent out? As soon as they are posted (1 sample per e-mail) or once a day (lots of samples per e-mail)?


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Apr 17, 2007 10:04 pm    Post subject:
Reply with quote

Quote:
are these samples submitted by someone also to every AV company by e-mail or not


Software grabs the samples and sends them to every email on the listserv .

Quote:
How often are the samples sent out?


Its twice a day for now but as we get more hunters and the volume increases we may change that to 4 or 8 times a day .

Back to top
View users profile Send private message Send email
pykko

MIRT Hunter


Joined: Jan 18, 2007
Posts: 736

MIRT

PostPosted: Thu Apr 19, 2007 9:50 am    Post subject:
Reply with quote

nosirrah wrote:
Quote:
are these samples submitted by someone also to every AV company by e-mail or not


Software grabs the samples and sends them to every email on the listserv .

Quote:
How often are the samples sent out?


Its twice a day for now but as we get more hunters and the volume increases we may change that to 4 or 8 times a day .

thank you for the answer.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Malware Listserv All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer