Notices
Non Scooby Related Anything Non-Scooby related

New Worm

Thread Tools
 
Search this Thread
 
Old 25 June 2001, 09:18 AM
  #1  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Old 25 June 2001, 10:48 AM
  #2  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

Imagine my surprise when the exchange virus checker caught it before I'd even had a chance to see the thing! Taking all the fun out of things nowadays, I can't even see the rather purile attempts at code obfuscation that the kiddies are thinking is so clever...

Do the heuristics now recognise an obfuscation routine in an attachment? I am starting to suspect that they do.

Keep up the good (if boring for us) work
Old 25 June 2001, 01:57 PM
  #3  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

I won't go into detail but your right. The majority of the samples we recieve nowadays are detected by our Heuristic/Generic routines before they're written. We're having to tread a very fine line between detection and false positive but seen to be winning.
Old 25 June 2001, 04:46 PM
  #4  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Thanks Jack. Enterprise SecureCast has been strangely quiet though...

ChrisB.
Old 25 June 2001, 07:22 PM
  #5  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

I belive we only send to SecureCast immediately if it hits high risk, I was woken with this one at medium risk early... very early... this morning, mainly down to the FBI's interest.


Old 26 June 2001, 09:21 AM
  #6  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Now it all becomes clear - cheers Jack.

ChrisB.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Jeff Wiltshire
Computer & Technology Related
2
25 January 2003 09:53 PM



Quick Reply: New Worm



All times are GMT +1. The time now is 12:12 AM.