3 ms·
The infosec community at large is well aware of how unreliable just using md5 checksums to identify malware is. If anything it is the absolute first line of def
by blakejustblake 6y ago
The infosec community at large is well aware of how unreliable just using md5 checksums to identify malware is. If anything it is the absolute first line of defense for identifying malware, in that it is easy to implement quickly and has a decent enough chance of filtering out low hanging fruit. The biggest use for the checksums between malware researchers is for identifying if they have the same strain of malware as someone else. Identification is mostly not based on checksums, but rather things like YARA rules where different identifying factors of malware are outlined to be compared against binaries. This isn't foolproof either, but there is a rather large ecosystem of malware researchers out there constantly taking samples and releasing rules. I follow a lot of these folks on Twitter and the majority of what they post are their findings on the bajillionth strain of whatever malware is in vogue at the moment. This sort of stuff is going to catch the majority of what will be coming at most people and anything that slips by the first lines of detection usually gets picked up somewhere along the way and passed on to researchers who do an exceptional job of reversing and identifying new malware or strains of old ones. But of course the reliability of that whole ecosystem depends on sensible organization security policy to start with.
In short, md5 sums and signatures are there to protect against the low hanging fruit, spray and pray type malware that's pretty common. If someone wants to target you with uniquely signatured malware they can. Identifying it isn't going to be what stops it, but proper opsec can.
- johnmaguire2013 6y ago> I follow a lot of these folks on Twitter and the majority of what they post are their findings on the bajillionth strain of whatever malware is in vogue at the moment. Anyone in particular you recommend following?
- wyxuan 6y agokrebsonsecurity, notdan, donk_enby are all good cybsec follows. you can probably find others from people that they follow/rt
- blakejustblake 6y ago@malwaremustd1e @malwrhunterteam @0xrb @capesandbox @malware_traffic
- theamk 6y agoAnd that's what I don't understand! You say it "has a decent enough chance of filtering", and I believe you -- but this just seems so strange. It seems to me like it trivial to create a webserver which says "serve the same binary, but put a random ASCII string in bytes 40-48". Or make malware installer which says, "write out the executable file to disk, but put a random value in bytes 80-88". Sure, it won't help against good YARA rule, but it seems really easy to do, and it will frustrate researchers, and even defeat some endpoint protection software, like [0] and [1]. [0] https://help.symantec.com/cs/ATP_3.2/ATP/v106632175_v127300344/Creating-a-Blacklist-policy?locale=EN_US https://help.symantec.com/cs/ATP_3.2/ATP/v106632175_v1273003... [1] https://docs.mcafee.com/bundle/network-security-platform-9.2.x-integration-guide-unmanaged/page/GUID-E7355943-6033-43FE-B17C-35A54A0593C7.html https://docs.mcafee.com/bundle/network-security-platform-9.2...
- Leherenn 6y agoI think, like with many things, basic steps are not taken, through laziness, carelessness or ignorance.
- jjeaff 6y agoLucky for us, most criminals are lazy.
- thaumasiotes 6y agoI don't think this comes from them being lazy. I think this comes from them not being aware of (1) the defense; and (2) the mitigation. It's an example of security through obscurity.
- monocasa 6y agoOr even if they know about the defense and the mitigation, it is additional work. In my work in the formal economy I rarely get to ship the technically best and most complete solution but instead a compromise 'MVP' that'll receive more work only if the problem proves to demand it. I expect the same holds true in the informal economy.