Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Security & Privacy
Tech-Savvy Business
Weekly Brief
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: UtilitiesGoogleViruses & Worms

New Tool Searches Google for Malware

Researcher releases code that can be used to mine Google's database for malicious software.

Robert McMillan, IDG News Service

Tuesday, July 18, 2006 6:00 AM PDT
Recommend this story?

A well-known security researcher has released code that can be used to mine Google's database for malicious software.

The tool is similar to one developed by Web filtering vendor Websense last week, but which was not released to the general public. Websense said that making this software public could lead to its being misused by attackers.

Using a database of digital fingerprints of known malware--called "signatures"--the Malware Search tool uses the popular search engine to find a number of known worms and viruses. It was developed by HD Moore, the researcher best known as the developer of the widely used Metasploit hacking tool. Moore's tool, which was posted early Monday, can be found here.

Though Google is widely used to search the Internet for Web pages and office documents, the search engine also can peek through the binary information stored in the normally unreadable executable files that are run by Windows computers. Google won't say when it added this feature, but it has gained the attention of security researchers over the past three months.

Moore built his tool to help shed some light on how much malware was actually being indexed by Google, he said. His findings: not much.

When the security researcher examined a sample of about 4GB of executable code, he found that very few of the programs were malicious. "You can search for malware, but it's not a big risk," he said.

Of the approximately 2400 samples he examined, 125 contained malware. More than 90 of these popped up as part of malicious e-mail messages stored in online e-mail archives. The rest of the samples came from Web sites that were actively distributing malware.

Attackers Disappointed?

So any attacker that might be looking to find new sources of malware using Moore's tool will probably be disappointed.

"Attackers have much better sources of malware and the items in the Google index are not recent or useful," he said. "If anything, the Google index is a great tool for determining who distributes malware--the actual malware in question is not that interesting."

Though some have speculated that Google's ability to search through executable files might allow it to create its own shareware and freeware search service, Moore said that Google has not yet indexed enough files for this to be useful.

Three months ago, Google had indexed about 30,000 executable files. That number has now risen to about 112,000 samples, he said.

"Considering that they're Google, you'd expect better results," Moore said. "If they could grow their index of executables to some sort of useful amount, then this would be really useful," he said.

However, without some way of weeding out malicious software, this kind of service could be misused by attackers to trick users into downloading worms or viruses masquerading as legitimate downloads, Moore said.

Google declined to comment for this article except to say that it is aware that users can find malicious executables via its search engine, and is making an effort to shield users from this code.


Recommend this story?

Comments
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
A strong showing in April means Nintendo's console will likely surpass Xbox 360 sales sooner than expected. 17-May-2008
Hewlett-Packard's acquisition of Electronic Data Systems won't hurt Dell in the next few years, but it could affect Dell's... 16-May-2008
Microsoft confirms that it has yanked parts of a backup feature from a major upgrade to its Windows Home Server. 16-May-2008
HP confirms that some users of its AMD-based desktops have had problems after installing Windows XP Service Pack 3. 16-May-2008
The days of imagining Wi-Fi blanketing a city are over with the exit of the last major municipally focused Wi-Fi service provider. 16-May-2008
In its continued attempt to convince business customers to adopt Vista, Microsoft has outlined and tried to explain some of... 16-May-2008
Sony Friday revealed a list of 15 upcoming games for the PlayStation 3, PS2 and PSP. 16-May-2008
This was a big IT news week, with the massive earthquake in China on Monday showing once again the role that the Internet... 16-May-2008
FastMac on Friday announced its new U-Charge. It's a universal battery charger for Apple laptops and it costs US$69.95; it... 16-May-2008
The June 2008 issue of Macworld includes a feature article on running Windows on your Mac--and how to do it in the most... 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)