Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 98 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Analysis assistance requested
EH-Net
May 26, 2012, 09:03:42 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Analysis assistance requested  (Read 6916 times)
0 Members and 1 Guest are viewing this topic.
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« on: January 10, 2012, 03:19:37 PM »

Hi all,

I am currently trying out Amahi Home server as a home server (obviously) included is a vpn server, and they suggest their own, easy to use client software for windows.

download HERE: http://dl.amahi.org/HDAConnect3.exe

Now, when I downloaded the software I scanned it with MSE (clean) and submitted it to Virus total. The file had last been submitted in 2010 with 2 alerts. I reanalyzed the file and the report came back clean 100%. On a whim, i threw the MD5 into google and received one result

http://xml.ssdsandbox.net/index.php/4a7fbb2eee1efb0cad809bb78f1180ca

It looks like an analysis of the file with a different exe name. IAC, the review  indicated what to my untrained eyes appears to be suspicious and concerning.

http://xml.ssdsandbox.net/index.php/files424 shows trojan files I suppose in the exe. In addition the exe appears to add some flags to itself, "Security anonymous" I havent looked this up yet but it seems suspicious. I was wondering if anyone wanted to take a look before I present this to the Amahi community.

In the meantime, i'll likely look elsewhere for a free vpn client.
Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 650


aka dynamik


View Profile WWW
« Reply #1 on: January 10, 2012, 05:41:34 PM »

It's probably a false positive. From what I've seen, it's relatively common to see remote access software identified as generic trojans. Also, someone could have repackaged it with malware and gotten it associated with something malicious at some point. I'm not familiar with the company, but if the vendor's reputable, it's probably a false positive.

Also, SECURITY_ANONYMOUS appears to be preferred since it doesn't attempt to impersonate anything and uses the anonymous impersonation level:
http://msdn.microsoft.com/en-us/library/windows/desktop/aa363858%28v=vs.85%29.aspx

http://msdn.microsoft.com/en-us/library/windows/desktop/aa378832%28v=vs.85%29.aspx
Logged

WIP: OSCP | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #2 on: January 11, 2012, 09:45:15 AM »

Check out OpenVPN, if all you need is a single VPN license, this works well and supports multiple platforms.  For Mac you need TunnelBlick.  The server end comes as pre-packed ISO for VM installation or CD/DVD install.  I think they may have instructions on installing it to a current system.
Logged

Certs: GCWN
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« Reply #3 on: January 11, 2012, 05:38:28 PM »

The server includes OpenVPN, but i need a client to connect with. Thanks dynamik, Those are possibilities I considered, i'll wait a few days, see if anyone is interested.
Logged

3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #4 on: January 12, 2012, 09:35:13 AM »

Ah, I am using Tunnelblick on my Mac, works pretty well.  I think the Windows and linux clients you can download directly from the OpenVPN Server site on the box.  I think you can see it if you visit the 443 site on your server.  Or whatever https port you are using.  OpenVPN has two service ports it uses, the https and the management port.
Logged

Certs: GCWN
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.103 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.