VSUB - Malware Submissions

Wednesday 26th July, 2006

VS0607004 Possible new malware [IRCFlooder?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via a link
in an e-mail.

This was caught by an end user.

I have included data on the excutable downloaded from the link in the e-mail, and the files
extracted from the RAR-SFX for your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: update.exe
FileDateTime: 26/07/2006 11:22:18
Filesize: 717558
MD5: 69406abece50099bb54143528eb7adfd
CRC32: 4CCC2BF7
File Type: PE Executable RAR
Packer: UPX

Contains:-

FileName: control.ini
FileDateTime: 10/03/2006 14:16:28
Filesize: 61
MD5: f5d1a3af67f05f5af2b0fca009887a97
CRC32: 885F5848
File Type: INI File

FileName: id.exe
FileDateTime: 09/07/2006 22:53:00
Filesize: 141260
MD5: 429ca729bd5c2707443965f6998883ce
CRC32: 7ABF7113
File Type: Unknown text file

FileName: mirc.ini
FileDateTime: 11/07/2006 20:56:38
Filesize: 2643
MD5: 527d999707095fdb32eb331989ecf6cf
CRC32: 2C38AC77
File Type: INI File

FileName: reg.dll
FileDateTime: 19/04/2003 11:43:12
Filesize: 81621
MD5: f2803769872afd580dbcf4dd5569296e
CRC32: A1A5BB75
File Type: PE Executable

FileName: remote.ini
FileDateTime: 26/07/2006 03:15:36
Filesize: 285
MD5: 2acee5f13b4ee0993744c29f2836ff7f
CRC32: 7D2BFAA5
File Type: INI File

FileName: rundll.exe
FileDateTime: 11/07/2006 20:57:48
Filesize: 326
MD5: 72217eb69692459541d90f7beb137dd4
CRC32: 2FC75B8F
File Type: Unknown text file

FileName: rundll32.exe
FileDateTime: 25/04/1999 23:48:20
Filesize: 40960
MD5: 6a7d2cbd8111bc7080c832f8a3442256
CRC32: 4E7C8819
File Type: PE Executable

FileName: script1.ini
FileDateTime: 12/05/2005 06:42:42
Filesize: 221
MD5: 86f27715c17b963a520384c14bc45bf4
CRC32: 583A9AFC
File Type: INI File

FileName: svchost.exe
FileDateTime: 12/04/2005 04:29:24
Filesize: 500224
MD5: c54c4adc3ebec0c4642912dad8e39318
CRC32: 73963C36
File Type: PE Executable

FileName: users.exe
FileDateTime: 11/07/2006 20:58:59
Filesize: 856
MD5: 2f9cd96bc38c2c46c3e3396776fa9fde
CRC32: D22462F
File Type: Unknown binary file
Packer: PECompact

FileName: vir.exe
FileDateTime: 11/07/2006 20:59:35
Filesize: 19933
MD5: 21b5b1a3164160b7b7b9744ed25e5d02
CRC32: BB907970
File Type: Unknown text file

FileName: win.com
FileDateTime: 11/07/2006 21:00:42
Filesize: 93
MD5: 440e042868e03d830dd71dd229b49d09
CRC32: 37413A6B
File Type: Unknown text file

FileName: win.ini
FileDateTime: 26/07/2006 02:34:20
Filesize: 12303
MD5: bb69660f07cb4125ebc7b2f4da8fdd73
CRC32: 67FD2F46
File Type: INI File

============================================================

Scan report of: update.exe

@Proventia-VPS -
AntiVir -
Avast! Win32:Hidewnd [Trj]
AVG HideWindow (Trojan horse)
BitDefender Spyware.Adspace.DLL
ClamAV Trojan.IRC.Flood.AQ
Command -
Dr Web Trojan.Flood.22016
eSafe Win32.Polipos.sus
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure Backdoor.IRC.Zapchast
F-Secure (BETA) Backdoor.IRC.Zapchast
Fortinet Misc/MIRC
Fortinet (BETA) Misc/MIRC
Ikarus -
Kaspersky not-a-virus:RiskTool.Win32.HideWindows
McAfee HideWindow (potentially unwanted program)
McAfee (BETA) HideWindow (potentially unwanted program)
Microsoft Tool:Win32/HideWindows
Nod32 -
Norman -
Panda Suspicious file
Panda (BETA) Suspicious file
QuickHeal -
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 BackDoor.IRC.based
VirusBuster -
WebWasher Win32.Malware.gen#Upack!94 (suspicious)
YY_Spybot -

============================================================

Thursday 20th July, 2006

VS0607003 Possible new malware [Downloader?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via e-mail.

This was caught by my Bayesian Filter.

I have included data on the zip extracted from the e-mail, and the executable extracted from the zip for
your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: DD269901.zip
FileDateTime: 20/07/2006 10:49:40
Filesize: 4308
MD5: c1aa725f9b6eedd79b99491e014e258c
CRC32: 90F66E21
File Type: ZIP Archive File

Contains:-

FileName: DD269901.exe
FileDateTime: 19/07/2006 17:09:00
Filesize: 5244
MD5: eb6aa621d168bf53a204141d0ace119e
CRC32: 1CDC43AE
File Type: PE Executable
Packer: FSG

============================================================

Scan report of: DD269901.exe

@Proventia-VPS -
AntiVir HEUR/Trojan.Downloader
Avast! -
AVG -
BitDefender -
ClamAV -
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure W32/Small.DGR
F-Secure (BETA) W32/Small.DGR
Fortinet suspicious
Fortinet (BETA) suspicious
Ikarus suspicious
Kaspersky -
McAfee -
McAfee (BETA) -
Microsoft -
Nod32 -
Norman -
Panda Suspicious file
Panda (BETA) Suspicious file
QuickHeal Suspicious (warning)
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 -
VirusBuster -
WebWasher Heuristic.Trojan.Downloader
YY_Spybot Smitfraud-C.,,Executable

============================================================

VS0607002 Possible new malware [Downloader?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via a link
in an e-mail.

This was caught by my Bayesian Filter.

I have included data on a sample of the executable downloaded from the link in
the e-mail for your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: fotos.cmd
FileDateTime: 19/07/2006 08:52:53
Filesize: 147988
MD5: bd958c2d06fc9a7456bfa6c8c67218d1
CRC32: E042FADB
File Type: PE Executable

============================================================

Scan report of: fotos.cmd

@Proventia-VPS -
AntiVir HEUR/Crypted.Layered.B
Avast! -
AVG Downloader.Generic2.FEW (Trojan horse)
BitDefender BehavesLike:Trojan.Downloader (suspected)
ClamAV -
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido Downloader.Delf.apx
F-Prot -
F-Secure Trojan-Downloader.Win32.Delf.apx
F-Secure (BETA) Trojan-Downloader.Win32.Delf.apx
Fortinet W32/Delf.APX!tr.dldr
Fortinet (BETA) W32/Delf.APX!tr.dldr
Ikarus -
Kaspersky Trojan-Downloader.Win32.Delf.apx
McAfee -
McAfee (BETA) -
Microsoft -
Nod32 -
Norman W32/Suspicious_U.gen
Panda Suspicious file
Panda (BETA) Suspicious file
QuickHeal Suspicious (warning)
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 -
VirusBuster -
WebWasher Heuristic.Crypted.Layered.B
YY_Spybot -

============================================================

Wednesday 12th July, 2006

VS0607001 Possible new malware [Downloader/Banker?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via e-mail.

This was caught by my Bayesian Filter.

I have included data on the zip extracted from the e-mail, and the executable
extracted from the zip for your information and analysis.

12 copies have been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: ID 0220712.zip
FileDateTime: 11/07/2006 19:09:40
Filesize: 4230
MD5: 1ad4a6cdc799d7ac112bf749d3339924
CRC32: 74DD4E84
File Type: ZIP Archive File

Contains:-

FileName: ID 0220712.exe
FileDateTime: 11/07/2006 06:47:10
Filesize: 5172
MD5: 73da3beb4b2d09db14d9881a18fd7535
CRC32: 883E01A9
File Type: PE Executable
Packer: FSG

============================================================

Scan report of: ID 0220712.exe

@Proventia-VPS -
AntiVir HEUR/Trojan.Downloader
Avast! Win32:Small-TI [Trj]
AVG -
BitDefender -
ClamAV -
Command -
Dr Web Trojan.DownLoader.10885
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure W32/Small.DEO
F-Secure (BETA) W32/Small.DEO
Fortinet suspicious
Fortinet (BETA) W32/ATM!tr.dldr
Ikarus Trojan-Downloader.Win32.Agent.gen
Kaspersky Trojan-Downloader.Win32.Small.dep
McAfee -
McAfee (BETA) Downloader-ATM trojan
Microsoft -
Nod32 Win32/TrojanDownloader.Small.NIH trojan (variant)
Norman -
Panda Suspicious file
Panda (BETA) Trj/Banker.CZI
QuickHeal Suspicious (warning)
Sophos Troj/Clagger-W
Symantec -
Symantec (BETA) Downloader
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 -
VirusBuster -
WebWasher Heuristic.Trojan.Downloader
YY_Spybot Smitfraud-C.,,Executable

============================================================

Get free blog up and running in minutes with Blogsome | Theme designs available here