Author Topic: 1.ex-, a generic trojan detection not detected by avast  (Read 2768 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
« Last Edit: December 03, 2011, 10:46:46 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: 1.ex-, a generic trojan detection not detected by avast
« Reply #1 on: December 03, 2011, 10:46:43 PM »
Report    2011-12-03 21:42:41 (GMT 1)
Website    solarelectricinstaller.com
Domain Hash    8827f41357ad51abc94f7a90c12e1d01
IP Address    50.22.91.2 [SCAN]
IP Hostname    taro.websitewelcome.com
IP Country    -- (--)
AS Number    36351
AS Name    SOFTLAYER - SoftLayer Technologies Inc.
Detections    10 / 23 (43 %)
Status    DANGEROUS

http://amada.abuse.ch/?search=solarelectricinstaller.com
http://malc0de.com/database/index.php?search=solarelectricinstaller.com
http://www.malwaredomainlist.com/mdl.php?search=solarelectricinstaller.com
http://www.mywot.com/en/scorecard/solarelectricinstaller.com
http://www.malwareblacklist.com/searchClearingHouse.php?search=solarelectricinstaller.com

Report    2011-12-03 22:38:54 (GMT 1)
IP Address    50.22.91.2
IP Hostname    taro.websitewelcome.com
IP Country    --
AS Number    N/A
AS Name    N/A
Detections    5 / 26 (19 %)
Status    DANGEROUS

http://cbl.abuseat.org/lookup.cgi?ip=50.22.91.2
http://www.malwaredomainlist.com/mdl.php?search=50.22.91.2
http://www.mywot.com/en/scorecard/50.22.91.2
http://www.spamhaus.org/query/bl?ip=50.22.91.2

Web server details
Scan for: hxxp://solarelectricinstaller.com/Gallery-Images/1.exe
Hostname: solarelectricinstaller.com
IP address: 50.22.91.2

System Details:
Running on: Apache
System info: mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635

Blacklist status
Domain blacklisted on the Opera browser (via AVG): solarelectricinstaller.com - reference

Sucuri
web site:    hxxp://solarelectricinstaller.com/Gallery-Images/1.exe
status:    Site blacklisted, malware not identified
web trust:     Site blacklisted.

Security report (Site blacklisted):
error       Blacklisted:      Yes
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

spg SCOTT

  • Guest
Re: 1.ex-, a generic trojan detection not detected by avast
« Reply #2 on: December 03, 2011, 10:50:18 PM »
avast blocks it via the network shield. (oddliy, while it alerted on the malzilla attempt at getting it, it didn't stop it...)

Sent to avast.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: 1.ex-, a generic trojan detection not detected by avast
« Reply #3 on: December 03, 2011, 11:00:41 PM »
Hi spg SCOTT,

Thanks for giving the actual shield protection status and thanks for sending this unknown executable to virus AT avast dot com,

That site has been spreading malware via names like sultan.ex- (dead), face.ex- (dead), x.ex-, sp.ex-, dd.ex-, malware like Trojan.Generic.KDV.433454, Trojan:Win32/Comame, TR/Danmec.L,  DDOS/Dofoil.A.5, W32/FakeAV.OZ!tr (all live), shield protection against this site is vital,

polonus


« Last Edit: December 03, 2011, 11:08:39 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: 1.ex-, a generic trojan detection not detected by avast
« Reply #4 on: December 03, 2011, 11:04:54 PM »
...shield protection against this site is vital,

+1
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0