VS0605005 Possible new malware [Downloader]
Details on a sample of a suspected new malware being spread via a link
in an e-mail.
This was caught by my Bayesian Filter.
I have included data on a sample for your information and analysis.
1 copy has been trapped so far.
I haven’t had a chance to test it on a goat system yet.
============================================================
Details:
FileName: photoalbum.exe
FileDateTime: 23/05/2006 17:38:18
Filesize: 9472
MD5: 2d081ffa3e7220b02c950809aa7f2f10
CRC32: F3990804
File Type: PE Executable
Packer: FSG
============================================================
Scan report of: photoalbum.exe
@Proventia-VPS -
AntiVir TR/Dldr.Avangt.A.2
Avast! -
AVG -
BitDefender -
ClamAV -
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure -
F-Secure (BETA) -
Fortinet suspicious
Fortinet (BETA) Dloader.U!tr
Ikarus Trojan-Downloader.Win32.Harnig.bl
Kaspersky -
McAfee Generic Downloader.u trojan
McAfee (BETA) Generic Downloader.u trojan
Microsoft -
Nod32 -
Norman -
Panda Suspicious file
Panda (BETA) Suspicious file
QuickHeal Suspicious (warning)
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
VBA32 -
VirusBuster -
YY_Spybot Smitfraud-C.,,Executable
============================================================
Please note that this blog has now moved to my own hosted domain here: http://momusings.com/vsub/.
A full RSS/ATOM feed can be found there.
All the data up to the end of December 2006 will be left here, however all postings from the 1st of January 2007 onwards will only be available at this blogs new home.
ALL future postings will only be available at the new site.
