HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.


All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: Not detecting Malware
PostPosted: 12 Jan 2009 05:48 
Offline

Joined: 12 Jan 2009 05:41
Posts: 4
I'm not able to block a malware that is downloaded via a php file.
The url is: http://www.oursouthernlakes.com/images/DSC01088.php
The downloaded file is not currently detected by clamav (I have submitted the sample do) but I created an UNOFFICIAL sig for it.
I'm able to detect the malware with clamscan:
clamdscan DSC01010.scr
DSC01010.scr: DSC01010.scr.UNOFFICIAL FOUND

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 0.096 sec (0 m 0 s)


Top
 Profile  
 
PostPosted: 12 Jan 2009 08:05 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
Did you reload HAVP with SIGHUP? Does it help if you restart it completely?


Top
 Profile  
 
PostPosted: 12 Jan 2009 13:33 
Offline

Joined: 12 Jan 2009 05:41
Posts: 4
I restarted clamav and havp. If you have the time you can try to reproduce the situation, the malware is still there.


Top
 Profile  
 
PostPosted: 13 Jan 2009 04:27 
Offline

Joined: 12 Jan 2009 05:41
Posts: 4
This is strange. I'm doing something wrong that I can't figure out.
From the logs:
12/01/2009 09:07:29 10.10.203.4 GET 200 http://www.uniferblog.com/DSC01010.scr 531+205312 VIRUS ClamAV: DSC01010.scr.UNOFFICIAL
12/01/2009 09:07:40 10.10.203.4 GET 200 http://www.uniferblog.com/DSC01010.scr 421+205312 VIRUS ClamAV: DSC01010.scr.UNOFFICIAL
12/01/2009 09:08:12 10.10.203.4 GET 200 http://www.uniferblog.com/DSC01010.scr 421+205312 VIRUS ClamAV: DSC01010.scr.UNOFFICIAL
12/01/2009 09:08:15 10.10.203.4 GET 200 http://www.uniferblog.com/DSC01010.scr 421+205312 VIRUS ClamAV: DSC01010.scr.UNOFFICIAL

These generated by someone in the network (who received an email with links to the malware)

So havp is detecting and blocking, but I can still download it, when other malware that I have for testing is blocked.


Top
 Profile  
 
PostPosted: 14 Jan 2009 10:09 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
Familiarize yourself with how KEEPBACKBUFFER setting works.. :)


Top
 Profile  
 
PostPosted: 14 Jan 2009 15:08 
Offline

Joined: 12 Jan 2009 05:41
Posts: 4
I found the problem. I was creating the signature with
sigtool --md5 DSC01010.scr

They are changing the file over time, the md5 created now is differrent from the original.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group