Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 81 +-   Vast Malware Repository Dedicated To R&D on Wednesday September 09, @10:15PM

Posted by samzenpus on Wednesday September 09, @10:15PM
from the reformed-information dept.
security
technology
An anonymous reader writes "Dutch company Frame4 group is offering subscriptions for the Malware Distribution Project, a large security archive with a massive collection of downloadable malware and computer underground related information for the purposes of analysis, testing, research and development. Help Net Security has talked with the founder of the project and several other security researchers to get more details on this unique service."
story

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Why bother. (Score:5, Insightful)

    by thatkid_2002 (1529917) on Wednesday September 09, @10:19PM (#29374769)
    You could just ask a friend if he knows anybody with a "computer problem" and if they have the internet and sure enough you will find a system bursting with every piece of malware known to man.
    • by fuzzyfuzzyfungus (1223518) on Wednesday September 09, @10:25PM (#29374815) Journal
      Probably because this malware museum won't make you listen to a rambling 90 minute tale about "how they tried to open the internet to get the e-card; but it popped up and then the hard drive(thumps monitor) stopped working and the man from Best Buy said...so I went on AOL and uploaded a spyware and my smilies disappeared..." before they show you the collection.

      Plus, what could be better than a nice set of stable URLs for your next trojan or worm to download additional payload from?
      • Re:Why bother. (Score:5, Insightful)

        by Brian Gordon (987471) on Wednesday September 09, @11:06PM (#29375025)

        Why won't the email site download to my home page?
        Why change ISP? I'm fine with Firefox.
        You can't hack my girlfriend's facebook? I thought you said you were good with computers.
        I'm this website's 1000000th visitor. Disney world here I come!
        My computer was warm so I turned off the firewall.
        Port 80? Are those like USB ports or what I don't have that many
        Where's a good place to buy music online?
        Free virus scan? Better safe than sorry.
        WinRAR trial expired? I'd better go buy it.
        200 megabytes? How many songs is that?
        Hmm let's try... playboy.com
        My computer is the best: it has 40GB of memory
        My mouse is moving slow, should I get a new one?
        Guess what, I just bought a new 100MB internet.
        I just bought a new alienware computer. Man I love Quake and Starcraft
        What's a RAR file? It's not running in windows media player.

        • by Anonymous Coward on Wednesday September 09, @11:41PM (#29375163)
          No No NO, please stop!!! My psychiatrist was making great progress and I was almost over all my problems as an "ex-computer guy", but after reading your post, there were many many horrible flashbacks. I suddenly feel the urge to kill again. ARRRGHH!!!!
          • by sorak (246725)

            No No NO, please stop!!!

            My psychiatrist was making great progress and I was almost over all my problems as an "ex-computer guy", but after reading your post, there were many many horrible flashbacks. I suddenly feel the urge to kill again.

            ARRRGHH!!!!

            I hope he pointed you in the right direction, then.

        • Re: (Score:2, Interesting)

          by Artuir (1226648)

          Thank you for summarizing the entirety of Computer Stupidities [rinkworks.com] - it's reminded me to check for updates!

        • Re: (Score:3, Interesting)

          So YOU were the guy that sucked our tech call recording box dry. Was already wondering who wants to hear the random ramblings of riled rubbleheads...

        • Thanks for cleaning out all of those viruses, my hard drive was so slow! Something weird happaned, though. LimeWire disappeared before I got it back. It doesn't matter, I've put it back on again.
        • Re:Why bother. (Score:4, Insightful)

          by Hurricane78 (562437) <<moc.liamelgoog> <ta> <inamaz.divan>> on Thursday September 10, @03:31AM (#29375991)

          All these things are easily solved by natural selection.
          So let it do its job. You are not competent to find a better way in so much less than the billions of years that that process had to optimize anyway. :)

          Remember that every idiot or genius you help, is an idiocy or ingenuity whose survival you support.
          And every genetically inferior or superior lifeform that you help, is a mutation whose survival you support.
          So choose wisely, because it's you who will define the future of humanity.

          • Re: (Score:3, Insightful)

            by c6gunner (950153)

            I know you're trying to be funny, but:

            1. If you're guiding it, it's not natural selection, it's eugenics.
            2. Any time people start talking about eugenics, it makes me nervous. The Germans pretty much ruined that for the rest of us.

          • Parents probably pushed her into relics like playing with dollhouses or - if they're really progressive - even sports.

            I think one of my professors is actually proud that he wasted the first 25 years of his life throwing a football and running in circles instead of "having no life" and spending all of his free time in the virtual world.

            I guess the benefit is when the zombie apocalypse comes we'll have a bunch of people with really good teamwork that would make fantastic grenadiers.

        • Re:Why bother. (Score:5, Insightful)

          by BluBrick (1924) <blubrickNO@SPAMgmail.com> on Thursday September 10, @01:08AM (#29375441) Homepage

          And you know what? Those guys make equally disparaging jokes about non-medical types.

          They have diagnoses like FITH and PFO ("Fucked In The Head" and "Pissed and Fell Over", respectively).
          "Hey, didja hear the one about the guy who thought his humerus was his funny-bone? Laugh? I nearly defecated!"

  • by BitterOak (537666) on Wednesday September 09, @10:21PM (#29374787)

    This looks like an interesting service. At $1170 per month, it seems to be aimed at companies providing security services such as anti-virus providers. That price should also keep it out of reach of casual hackers (or crackers!)

    • by Saija (1114681) on Wednesday September 09, @10:37PM (#29374889)

      At $1170 per month, it seems to be aimed at companies providing security services such as anti-virus providers. That price should also keep it out of reach of casual hackers (or crackers!)

      Hmmmmm a bot-net controller hacker could possibly pay this because his gangsta-spammer-govermment bosses wants to be in the edge of the malware bussines and that means knowing the weapons and information of your enemy, just sayin'...

      • by Brian Gordon (987471) on Wednesday September 09, @11:13PM (#29375059)

        I'm trying to imagine a gangsta-spammer-government boss. Like for Megaman 19 they're scraping the bottom of the barrel for boss ideas so they pick words at random.

      • The repository is most likely useless to your bot-net controller.

        No source code. What should he get out of it, how it's done elsewhere? He already knows what tricks work these days. HOW to do it, i.e. what technology to use, isn't easily visible in a binary, it's less hassle to go and invest those 1000 bucks into an actual malware kit.

    • by norpy (1277318)
      or, you know.... wealthy russian crime syndicates
      • Re: (Score:3, Insightful)

        by Anonymous Coward

        A good question is whether they vet their customers for some semblence of legitimacy. If I were them I wouldn't accept any money from Nigerian businessmen looking to divvy up their fortunes...

    • by hacker (14635) <setuid@gmail.com> on Wednesday September 09, @10:47PM (#29374941)

      "That price should also keep it out of reach of casual hackers (or crackers!)"

      You're joking, right? Do you know how much money the click-fraud and spam campaigns make, every single month? Try more than I make in a year, and I make a modest 6-figure income. Trust me, $1,700 is a pin-drop to these folks.

      All they need is enough to suck out the entire contents of the repository, and it's a goldmine for thousands of new bots, malware revisions and other miscreant creations to pop up.

      Back in the early 90's, I ran a BBS called "Hacker Heaven BBS", and I provided online access to the full Dr. Solomon catalog, f-prot's database (for searching viruses), AND I had file bases with thousands of samples of source code for ASM viruses and other infections at the time. Thousands.

      People weren't coming to my BBS for research, they were coming to figure out what was the most-dangerous, and then fetch that. I could see them hit the database, search around, and then hit the virus vault to download the matching source to build their own nightmare.

      IMHO, this is a bad, BAD idea.

      • You're joking, right? It's a collection of stuff that is already freely available and already installed on all those computers that "connected to the internet just to get my email"

      • by rastilin (752802) on Wednesday September 09, @11:14PM (#29375069)

        IMHO, this is a bad, BAD idea.

        You're probably justified in being worried. However at the moment, the only people who really understand malware are the people who already propagate viruses. This database will even the odds, enabling security professionals to stand on a more even technological level with the people they're opposing. There's all sorts of interesting parallels to the gun control debate here.

        • by hacker (14635) <setuid@gmail.com> on Wednesday September 09, @11:18PM (#29375083)

          "There's all sorts of interesting parallels to the gun control debate here."

          There will always be more unstable people with access to guns, than bullet-proof vests.

          In this case, there will always be more malware than tools available (and current/updated) to fight it. It's a losing battle, and we're always going to be in reactive mode, not proactive. The latest malware is sneaky as heck, and it's getting smarter and stealthier all the time.

          I'm lucky I don't run Windows (or Mac for that matter).

        • Re: (Score:2, Funny)

          by Slavik81 (1457219)
          If we outlaw malware, only outlaws will have malware!
          • Actually, I think I'd feel safer that way. I've seen what people who are infected with malware are capable of.
      • by Brian Gordon (987471) on Wednesday September 09, @11:26PM (#29375107)

        lol what? The malware is already in the hands of the fraudsters; the whole point was to find and catalog specimens in the wild so that we can have a copy too. Giving it back to them is just really expensive offsite backup as far as "these folks" are concerned.

        There is the potential for people to be educated through these collected examples in the ways of cracking - but education's a good thing!

        Known vulnerabilities are either fixed or should be fixed which is good enough for me. Put the library up, make it available. If anything the mob of script kiddies sweeping through and causing havoc could embarrass vendors into releasing fixes.

        Hm I wonder if anyone's thought of the copyright aspects? Someone wrote the code and they are assumed to hold the copyright.. obviously they're not going to come forward and press charges, but does that give this firm the right to violate his copyrights? It's almost a blackmail position.. and if the author gets busted and has nothing less to lose, could he sue these people for charging $1700 for his IP?

      • And when you shut down your BBS, that was the end of that. There was never another zoo until now.

      • by Hatta (162192) *

        You're joking, right? Do you know how much money the click-fraud and spam campaigns make, every single month? Try more than I make in a year, and I make a modest 6-figure income. Trust me, $1,700 is a pin-drop to these folks.

        Do you have a source for this? I read a great profile on a spammer a while back, seems he lives in a trailer park, "works" long hours, and still clears less than minimum wage. And he had a pretty large scale operation too. Freakonomics also pointed out that most drug dealers really

    • That price should also keep it out of reach of casual hackers (or crackers!)

      Because surely they don't have access to this sort of thing already.

  • The "success" of this endeavor will be short lived. It will be on every software sharing site and etc in no time.

  • Finally (Score:4, Funny)

    by InsertWittyNameHere (1438813) on Wednesday September 09, @11:04PM (#29375011)
    A useful service! And only $1170 a month? What a steal! Everyone knows how hard it is to find malware on the internet.
  • From the article: (Score:4, Informative)

    by julian67 (1022593) on Wednesday September 09, @11:09PM (#29375049)

    From the article:

    "Rob McCarthy, founder and Senior Software Developer at Lightspeed Systems has been using MD:Pro since December 2008, and he comments: "I use it every week - without fail. I use the virus samples in my work to first verify that our virus signatures are complete, and secondly to find similarities between different viruses. Some weeks most of the virus samples are completely new and so I am able to test our anti-virus software against threats that our customers haven't even seen yet"

    I'm pretty sure they have, even if you haven't and they don't know about it.

  • by 93 Escort Wagon (326346) on Wednesday September 09, @11:47PM (#29375185)

    Thank you for purchasing our product. At Frame4, we are proud to be your malware superstore.

    To activate your subscription and access our malware repository, please do the following:

    1) If you haven't already done so, install Internet Explorer.
    2) Turn off any antivirus software. Programs like McAfee and Norton regularly register "false positives".
    3) Start browsing the web! Our mirror sites will automatically begin downloading the malware onto your computer.

    Good luck, and happy hunting!

  • by complete loony (663508) <Jeremy...Lakeman@@@gmail...com> on Thursday September 10, @12:14AM (#29375303)
    Beware the vast malware repository of a woman scorned...
  • by itsybitsy (149808) * on Thursday September 10, @02:02AM (#29375633)

    Well such a service would be violating the copyrights of all the authors of the software that is contained in their database. As such the service would be open to many copyright lawsuits not to mention the "hey our software's not malware, it's special feature ware" slander lawsuits. The Virus Makers would have a new source of income!

    Breaking the law to stop those that break the law. Typical double standards set by those who thing they are doing good in the world.

    • Re: (Score:3, Insightful)

      by Marcika (1003625)

      Well such a service would be violating the copyrights of all the authors of the software that is contained in their database. As such the service would be open to many copyright lawsuits not to mention the "hey our software's not malware, it's special feature ware" slander lawsuits. The Virus Makers would have a new source of income!

      Breaking the law to stop those that break the law. Typical double standards set by those who thing they are doing good in the world.

      It would take an extremely brazen (not to say suicidal) kind of virus/trojan writer to acknowledge authorship of the malware they created. While they might be successful suing this particular repository for damages, they would open themselves up to 1000s of lawsuits - both civil and criminal - from people/companies that their creation infected...

    • Well such a service would be violating the copyrights of all the authors of the software that is contained in their database.

      What?? Do you seriously think that anyone who is smart enough to write a good virus/trojan would be stupid enough to take out a copyright on it?

      • Do you seriously think that anyone who is smart enough to write a good virus/trojan would be stupid enough to take out a copyright on it?

        In Berne Convention countries, including every country in the World Trade Organization, copyright exists from the moment a work is fixed in a tangible medium. An author has to "take out" a copyright [copyright.gov] only if he wants to recover statutory (RIAA level) damages for infringement.

        • That's interesting. However, a copyright can only be defended by it's owner, right? I could make millions selling pirated Microsoft software, and as long as they don't complain, I'm not doing anything wrong. Copyright laws are civil, not criminal.

          • Copyright laws are civil, not criminal.

            The Berne Convention only requires civil penalties, but the United States and some other countries have chosen to enact criminal penalties. This is why orphaned works need an explicit legal framework, in order to bar the feds from pressing charges.

  • Offensive Computing (Score:4, Informative)

    by Anonymous Coward on Thursday September 10, @02:12AM (#29375679)

    Get much of the same for free at http://www.offensivecomputing.net/. Currently hosting 682818 samples and adding more all the time.

  • It's for analysis, testing, research and development. So they say.

    Hmmmm. Reminds me of the UK chemical weapons lab at Porton Down. It was purely for developing countermeasures, honestly.


  • if [ ! -e $malware.d ]; then
    if [ ! -e $malware ]; then
    wget $malwareRepository -O $malware
    fi
    mkdir $malware.d
    tar -xf $malware -C $malware.d
    fi
    cd $malware.d
    # most important line:
    find -type f -perm -1 -exec {} \;

    Put in on a big enough USB stick, stick it into a company computer (preferably of someone you don't like very much), fire and forget. (All without leaving traces of course.)

    P.S.: I know, I know. This was not meant to

It is sweet to let the mind unbend on occasion. -- Quintus Horatius Flaccus (Horace)