Avast WEBforum

Other => Viruses and worms => Topic started by: Lisandro on August 13, 2014, 04:39:27 PM

Title: avast! false negative
Post by: Lisandro on August 13, 2014, 04:39:27 PM
I've sent the file to analysis.
https://www.virustotal.com/en/file/b8a63e6bbcf1ad7b1c92dc6c70b400eef71add79ed401c908610980db95822a8/analysis/1407938301/

The vector was an email telling I've got a banking credit:

Quote
Comprovante Transferência Bancaria.

Arquivo(s) em Anexo(s) : Comprovante.pdf ( 238KB )

Por Favor conferir a transferencia .
Segue o comprovante da transferencia feito em 13/08/2014
no valor de: R$ 6.830,00

The file was a false exe passing as a pdf inside a zip.
Title: Re: avast! false negative
Post by: jefferson sant on August 13, 2014, 05:24:40 PM
Reported to vírus analyst

This has clearly been sent to our vlab, so there will be a detection soon hopefully.
Title: Re: avast! false negative
Post by: Lisandro on August 13, 2014, 07:24:02 PM
Reported to vírus analyst

This has clearly been sent to our vlab, so there will be a detection soon hopefully.
Jefferson, but did Honza received the same malware? Why are you quoting him here?
Title: Re: avast! false negative
Post by: DavidR on August 13, 2014, 07:52:37 PM
The quote from jefferson santiag is also incorrect as it just goes to his profile not to the topic/post, so we have no idea what it related too.
Title: Re: avast! false negative
Post by: jefferson sant on August 13, 2014, 09:08:45 PM
Jefferson, but did Honza received the same malware? Why are you quoting him here?

I'm not sure, but best if you can use the ticket support

https://support.avast.com/Tickets/Submit

mark status for urgent, so reporting today, tomorrow you will receive a response,at most two days.
Title: Re: avast! false negative
Post by: polonus on August 14, 2014, 12:15:40 AM
Seems this is revived malware dating back to 2012: http://tools.cisco.com/security/center/viewThreatOutbreakAlert.x?alertId=25701

polonus
Title: Re: avast! false negative
Post by: Lisandro on August 15, 2014, 03:22:48 AM
Seems this is revived malware dating back to 2012: http://tools.cisco.com/security/center/viewThreatOutbreakAlert.x?alertId=25701

polonus
Another reason to have been detected... Shame?
Title: Re: avast! false negative
Post by: Asyn on August 15, 2014, 05:59:19 AM
We've detection now: https://www.virustotal.com/en/file/b8a63e6bbcf1ad7b1c92dc6c70b400eef71add79ed401c908610980db95822a8/analysis/
Title: Re: avast! false negative
Post by: Lisandro on August 15, 2014, 11:16:17 PM
Thanks Virus Lab!