Clicky

Pages

Showing posts with label Malware Zoo. Show all posts
Showing posts with label Malware Zoo. Show all posts

Tuesday, December 22, 2009

Software informer. Adware / Malware - most likely

Software informer.
This information was sent by a reader. I am posting it here with minimal editions. If you would like to download, test it, and resolve the controversy, the link is below. Thank you for your help.

There seem to be a lot of controversy on whether a Russian made software piece called Software Informer is malware/adware or not. http://aroundsap.blogspot.com/2007/08/remove-software-informer-system.html

I believe it is an adware and must be avoided - like anything associated with RBN. If you search for software updates, you often run into links poisoned by their ads like this
hxxp://aventail-access-manager.software.informer.com/download/
or this
hxxp://camera-assistant-software.software.informer.com/
 
"IP range (208.88.224.0/24) from files.informer.com (IP = 208.88.224.211) is in the RBN block rules.

http://www.emergingthreats.net/rules/emerging-rbn-BLOCK.rules

The domains in this range are not trustworthy
http://www.robtex.com/cnet/208.88.224.html
 


Download the file --> hxxp://files.informer.com/siinst.exe (MD5: f81ccc88fe9c73d54a3bbc72e760265b / Size: 744'538 Bytes)


Monday, December 7, 2009

Dec.7 Attack of the Day. Poison Ivy zip download link. Our soliders in Afghanistan Mon. Dec 07, 2009 10:34 AM




Download Afghanistan.zip 052e62513505a25ccfadf900a052709c http://www.mediafire.com/file/dwo2kih2ayn/Afghanistan8.zip



 From: XXX@yahoo.com]
Sent: Monday, December 07, 2009 10:34 AM
To: XXX@xxx.xxx
Subject: Our soliders in Afghanistan
President Obama recently announced that he was determined to "finish the job"
in Afghanistan, and aides signaled to allies that he would send as many as
25,000 to 30,000 additional American troops there. 2009 is shaping up to be
the deadliest year yet for coalition troops - twice as deadly as 2008.
Here are images of the country and conflict over the past month...
http://www.dreamlifes.net/Afghanistan/Afghanistan.zip
Regards


Virustotal scan 
http://www.virustotal.com/analisis/16952bc60a64af478fd7fd74bfb662b2f2c26cebc515cf4d17adeed90da6cf06-1260935214
File Afghanistan.scr received on 2009.12.16 03:46:54 (UTC)
Result: 22/41 (53.66%)

a-squared 4.5.0.43 2009.12.16 Riskware.RemoteAdmin.Win32.PoisonIvy!IK
AhnLab-V3 5.0.0.2 2009.12.15 Dropper/Malware.1259008.B
AntiVir 7.9.1.108 2009.12.15 TR/Mepaow.jvr
Avast 4.8.1351.0 2009.12.15 Win32:Malware-gen
AVG 8.5.0.427 2009.12.15 SHeur2.BTHV.dropper
BitDefender 7.2 2009.12.16 BehavesLike:Win32.ExplorerHijack
eSafe 7.0.17.0 2009.12.15 Win32.TRMepaow.Jvr
F-Secure 9.0.15370.0 2009.12.15 BehavesLike:Win32.ExplorerHijack
Fortinet 4.0.14.0 2009.12.16 RAT/PoisonIvy
GData 19 2009.12.16 BehavesLike:Win32.ExplorerHijack
Ikarus T3.1.1.77.0 2009.12.16 not-a-virus:RemoteAdmin.Win32.PoisonIvy
K7AntiVirus 7.10.920 2009.12.14 not-a-virus:RemoteAdmin.Win32.PoisonIvy.c
Kaspersky 7.0.0.125 2009.12.16 not-a-virus:RemoteAdmin.Win32.PoisonIvy.c
McAfee+Artemis 5833 2009.12.15 potentially unwanted program Artemis!052E62513505
McAfee-GW-Edition 6.8.5 2009.12.15 Trojan.Mepaow.jvr
nProtect 2009.1.8.0 2009.12.15 Trojan/W32.Agent.1259008.C
Panda 10.0.2.2 2009.12.15 Malicious Packer
PCTools 7.0.3.5 2009.12.16 Backdoor.Trojan
Rising 22.26.02.01 2009.12.16 Backdoor.Win32.RemoteAdmin.a
Sophos 4.48.0 2009.12.16 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.12.16 Trojan.Win32.Generic!BT
Symantec 1.4.4.12 2009.12.16 Backdoor.Trojan

Additional information
File size: 1259008 bytes
MD5...: 052e62513505a25ccfadf900a052709c
SHA1..: 5ba291b3a0810bc319e243bb496f3b99a5280a64
SHA256: 16952bc60a64af478fd7fd74bfb662b2f2c26cebc515cf4d17adeed90da6cf06
ssdeep: 24576:PxW/6gOd4NpwO7ghtSaKvq+dh1j9gBYH+/kXEok48:ZWlhwWghtSq+rjgB

Headers
....
Received: from [174.139.22.106] by web56506.mail.re3.yahoo.com via HTTP; Mon, 07 Dec 2009 07:33:57 PST

X-Mailer: YahooMailClassic/8.1.6 YahooMailWebService/0.8.100.260964
Date: Mon, 7 Dec 2009 07:33:57 -0800 (PST)
From: XXXXXXXXX stolen yahoo account
Subject: Our soliders in Afghanistan
To: XXXXXXXX
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-743893425-1260200037=:86552"
Return-Path: XXXXXXXXX stolen yahoo account
X-OriginalArrivalTime: 07 Dec 2009 15:34:01.0709 (UTC) FILETIME=[B39069D0:01CA7752]

174.139.22.106
Hostname: customer.krypt.com

ISP: VPLS Inc. d/b/a Krypt Technologies
Organization: Kevin Perry
Type: Corporate
Country: United States
State/Region: CO
City: Boulder

Friday, November 27, 2009

熊猫烧香 Panda Burning Incense virus - the new version is a variant, called Worm_Piloyd.B

Li Jun, aka “Virus King,” designed the 熊猫烧香 / Panda Burning Incense / joss-sticks virus that wreaked havoc in China in 2006 - 2007.  He spent 2 1/2 years in prison and was/is supposed to be released in the end of this year. Maybe he already was because a new version of this virus is now making rounds in China


Here is a Chinese language article (Google translated) about the author of the virus


The script below (from someone by name 'bobo') is supposed to remove the original version of the virus:





Friday, October 30, 2009

Compromised computer

C:\RECYCLER\1\nc\exe. And in the black screen that pops up it reads: mail.linkum.com.br [216.75.20.82] 8082 (?) open
Hostname:
mail.linkum.com.br
ISP:
California Regional Intranet
Organization:
California Regional Intranet
Proxy:
None detected
Type:
Corporate
Blacklist:
Geo-Location Information
Country:
United States
State/Region:
ME
City:
Prospect Harbor
Latitude:
44.4286
Longitude:
-68.0052
Area Code:
207

Tuesday, June 2, 2009

win32update.exe MD5 eec80fd4c7fc5cf5522f0ca4eb2d9c6f

Link updated: Jan 18, 2023

https://www.virustotal.com/gui/file/4f6e68bff29aed584a68c21616dd8c052ba0eee220c911d98b9bb9fabe7db06a


File win32update.exe received on 2009.06.02 04:43:06 (UTC)
Result: 15/39 (38.47%)
Located in c:\windows\system32
Prevx
3
2009.06.02
Medium Risk
NOD32
4121
2009.06.02
probably Win32/PSW.Agent
AVG
8.5.0.339
2009.06.01
PSW.Agent.XOU
AntiVir
7.9.0.180
2009.06.01
TR/PSW.Agent.kny
BitDefender
7.2
2009.06.02
Trojan.Generic.980251
GData
19
2009.06.02
Trojan.Generic.980251
McAfee-GW-Edition
6.7.6
2009.05.29
Trojan.PSW.Agent.kny
VirusBuster
4.6.5.0
2009.06.01
Trojan.PWS.Agent.HWJL
TheHacker
6.3.4.3.335
2009.06.01
Trojan/PSW.Agent.kny
CAT-QuickHeal
10
2009.06.01
TrojanPSW.Agent.kny
F-Secure
8.0.14470.0
2009.06.02
Trojan-PSW.Win32.Agent.kny
Kaspersky
7.0.0.125
2009.06.02
Trojan-PSW.Win32.Agent.kny
VBA32
3.12.10.6
2009.06.02
Trojan-PSW.Win32.Agent.kny
Authentium
5.1.2.4
2009.06.02
W32/Pws.BIXJ
F-Prot
4.4.4.56
2009.06.02
W32/Pws.BIXJ