VSUB - Malware Submissions

Thursday 26th October, 2006

VS0610003 Possible new malware [Mechbot?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via e-mail
using a website link in the e-mail.

This was caught by an end-user.

I have included data on a sample for your information and analysis.

2 copies have been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: postcards.exe
FileDateTime: 26/10/2006 11:52:45
Filesize: 647943
MD5: 71d2dc1e6fb0ae9f54ca40ef4220ab28
CRC32: 8ABFA1EC
File Type: PE Executable RAR
Packer: UPX

============================================================
Scan report of: postcards.exe

@Proventia-VPS -
AntiVir -
Avast! Win32:Mechbot [Trj]
AVG BackDoor.Generic2.CGZ (Trojan horse)
BitDefender Application.Vtext.12
ClamAV -
Command -
Dr Web BackDoor.IRC.Mech
eSafe Win32.Mechbot.d
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure Backdoor.Win32.Mechbot.d
F-Secure (BETA) Backdoor.Win32.Mechbot.d
Fortinet suspicious
Fortinet (BETA) suspicious
Ikarus -
Kaspersky Backdoor.Win32.Mechbot.d
McAfee VText.12 (potentially unwanted program)
McAfee (BETA) VText.12 (potentially unwanted program)
Microsoft Backdoor:Win32/IRCbot!E2AB
Nod32 -
Norman -
Panda W32/IRCBot.PN.worm
Panda (BETA) W32/IRCBot.PN.worm
QuickHeal -
Rising Backdoor.Mechbot.a
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 Backdoor.Win32.Mechbot.d
VirusBuster -
WebWasher Worm.Ircbot.PN
YY_Spybot ERROR

============================================================

Friday 20th October, 2006

VS0610002 Possible new malware [Banload?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via e-mail
using a website link in the e-mail.

This was caught by an end-user.

I have included data on a sample for your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: newfoto.exe
FileDateTime: 16/10/2006 17:41:34
Filesize: 182089
MD5: f27e13acf595fe5fdb9a1dbac8dfbf8f
CRC32: 40B774F3
File Type: PE Executable
Packer: FSG

============================================================

Scan report of: newfoto.exe

@Proventia-VPS Malicious (Cancelled)
AntiVir TR/Delphi.Downloader.Gen
Avast! -
AVG Downloader.Generic2.SKL (Trojan horse)
BitDefender -
ClamAV ERROR
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido Downloader.Banload.aoo
F-Prot -
F-Secure Trojan-Downloader.Win32.Banload.aoo
F-Secure (BETA) Trojan-Downloader.Win32.Banload.aoo
Fortinet W32/Banload.AOO!tr.dldr
Fortinet (BETA) W32/Banload.AOO!tr.dldr
Ikarus suspicious
Kaspersky Trojan-Downloader.Win32.Banload.aoo
McAfee -
McAfee (BETA) -
Microsoft -
Nod32 Win32/TrojanDownloader.Banload.AOO trojan (variant)
Norman W32/Banload.HKN
Panda Trj/Nabload.QE
Panda (BETA) Trj/Nabload.QE
QuickHeal Suspicious (warning)
Rising Trojan.DL.Banload.iun
Sophos Mal/Packer
Symantec -
Symantec (BETA) -
Trend Micro Possible_Virus
Trend Micro (BETA) Possible_Virus
UNA -
VBA32 -
VirusBuster -
WebWasher Heuristic.Malware
YY_Spybot ERROR
============================================================

Wednesday 4th October, 2006

VS0610001 Possible new malware [Agent?]

Filed under: All, Submitted

Data on a sample of a suspected new malware being spread via IM
using a website link in the IM [MSN].

Which uses a PHP script to download a file.

This was caught by an end-user.

I have included data on a sample for your information and analysis.

1 copy has been trapped so far.

I haven’t had a chance to test it on a goat system yet.

============================================================

Details:

FileName: photo211.pif
FileDateTime: 03/10/2006 17:03:30
Filesize: 137216
MD5: 50f685141c9252a13ece1febd372e491
CRC32: B2851914
File Type: PE Executable

============================================================

Scan report of: photo211.pif

@Proventia-VPS Malicious (Cancelled)
AntiVir -
Avast! Win32:Agent-BNP [Trj]
AVG -
BitDefender -
ClamAV -
Command -
Dr Web -
eSafe Trojan/Worm [100] (suspicious)
eTrust-INO -
eTrust-INO (BETA) -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure -
F-Secure (BETA) -
Fortinet -
Fortinet (BETA) -
Ikarus -
Kaspersky -
McAfee -
McAfee (BETA) -
Microsoft -
Nod32 -
Norman -
Panda -
Panda (BETA) -
QuickHeal Suspicious (warning)
Rising -
Sophos -
Symantec -
Symantec (BETA) -
Trend Micro -
Trend Micro (BETA) -
UNA -
VBA32 -
VirusBuster -
WebWasher Worm.Win32.Malware.gen (suspicious)
YY_Spybot -

============================================================

Get free blog up and running in minutes with Blogsome | Theme designs available here