VSUB - Malware Submissions

Thursday 20th July, 2006

VS0607003 Possible new malware [Downloader?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via e-mail.

This was caught by my Bayesian Filter.

I have included data on the zip extracted from the e-mail, and the executable extracted from the zip for
your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: DD269901.zip
FileDateTime: 20/07/2006 10:49:40
Filesize: 4308
MD5: c1aa725f9b6eedd79b99491e014e258c
CRC32: 90F66E21
File Type: ZIP Archive File

Contains:-

FileName: DD269901.exe
FileDateTime: 19/07/2006 17:09:00
Filesize: 5244
MD5: eb6aa621d168bf53a204141d0ace119e
CRC32: 1CDC43AE
File Type: PE Executable
Packer: FSG

============================================================

Scan report of: DD269901.exe

@Proventia-VPS -
AntiVir HEUR/Trojan.Downloader
Avast! -
AVG -
BitDefender -
ClamAV -
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure W32/Small.DGR
F-Secure (BETA) W32/Small.DGR
Fortinet suspicious
Fortinet (BETA) suspicious
Ikarus suspicious
Kaspersky -
McAfee -
McAfee (BETA) -
Microsoft -
Nod32 -
Norman -
Panda Suspicious file
Panda (BETA) Suspicious file
QuickHeal Suspicious (warning)
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 -
VirusBuster -
WebWasher Heuristic.Trojan.Downloader
YY_Spybot Smitfraud-C.,,Executable

============================================================

VS0607002 Possible new malware [Downloader?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via a link
in an e-mail.

This was caught by my Bayesian Filter.

I have included data on a sample of the executable downloaded from the link in
the e-mail for your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: fotos.cmd
FileDateTime: 19/07/2006 08:52:53
Filesize: 147988
MD5: bd958c2d06fc9a7456bfa6c8c67218d1
CRC32: E042FADB
File Type: PE Executable

============================================================

Scan report of: fotos.cmd

@Proventia-VPS -
AntiVir HEUR/Crypted.Layered.B
Avast! -
AVG Downloader.Generic2.FEW (Trojan horse)
BitDefender BehavesLike:Trojan.Downloader (suspected)
ClamAV -
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido Downloader.Delf.apx
F-Prot -
F-Secure Trojan-Downloader.Win32.Delf.apx
F-Secure (BETA) Trojan-Downloader.Win32.Delf.apx
Fortinet W32/Delf.APX!tr.dldr
Fortinet (BETA) W32/Delf.APX!tr.dldr
Ikarus -
Kaspersky Trojan-Downloader.Win32.Delf.apx
McAfee -
McAfee (BETA) -
Microsoft -
Nod32 -
Norman W32/Suspicious_U.gen
Panda Suspicious file
Panda (BETA) Suspicious file
QuickHeal Suspicious (warning)
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 -
VirusBuster -
WebWasher Heuristic.Crypted.Layered.B
YY_Spybot -

============================================================

Get free blog up and running in minutes with Blogsome | Theme designs available here