Author Topic: What's wrong with these Sites?  (Read 2896 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
What's wrong with these Sites?
« on: February 21, 2014, 08:15:25 PM »
wXw.technofreeks.com/uploads/1/2/8/6/12861493/7z915.exe
wXw.technofreeks.com/uploads/1/2/8/6/12861493/teracopy.exe

(Don't go to these links above this warning!)

https://www.virustotal.com/en/url/26182c1185c3db531f50fb66fdfe6cefe04a3db1dec466ca55d3f6a8b28cb665/analysis/1393009889/
https://www.virustotal.com/en/url/0f441881450d849f5ddc76999d8995fab4782d3ba92ea7d96bc1238b2dd2f302/analysis/1393010063/

Can anyone point out the infection and what it is?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: What's wrong with these Sites?
« Reply #2 on: February 21, 2014, 08:41:15 PM »
https://www.virustotal.com/en/file/0bd035cb8a9c65078b8445f5785bc98c8203acdd3bfa7264ae3451d13258546e/analysis/1392993162/

MBAM Doesn't detect the file? That's messed up!
nope.... Malwarebytes does not detect file infectors and never will
it will detect the main install file, but not any files injected with virus code..... Malwarebytes does not clean files, it only detect and remove files where the hole file is the malware

read and laern Michael..... lots of info in MBAM forum   ;)

MIEKIEMOES - Director of Research @ Malwarebytes
http://miekiemoes.blogspot.no/2009/02/virut-and-other-file-infectors-throwing.html

David H. Lipman
https://forums.malwarebytes.org/index.php?showtopic=102698#entry507785




« Last Edit: February 21, 2014, 08:47:19 PM by Pondus »

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: What's wrong with these Sites?
« Reply #3 on: February 21, 2014, 09:01:55 PM »
Also to get this Sality crap you need to get an executable to be infected, and thats most likely detected. :)

Or you just head over to linux to get around malware.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

gen-hackman

  • Guest
Re: What's wrong with these Sites?
« Reply #4 on: February 21, 2014, 11:36:37 PM »
hello only drweb,AVPTools or SalityKiller can disinfect the files injected

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: What's wrong with these Sites?
« Reply #5 on: February 23, 2014, 12:07:35 PM »
I know. But the sites are not actively blocked by neither MBAM Pro nor Avast! The fact the code is still live and so are the files is dangerous. The links lead directly to the "Infected File"

The post VT results I gacve to FatDCUK are that of the actual themselves. But won't detect it.
« Last Edit: February 23, 2014, 12:10:49 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: What's wrong with these Sites?
« Reply #6 on: February 23, 2014, 12:24:32 PM »
Oh. Nevermind. Avast! was just lagging behind on the blocking of the website.

Object: http://.../teracopy.exe
Infection: Win32 Salicode
Process: IEXPLORE
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: What's wrong with these Sites?
« Reply #7 on: February 23, 2014, 02:51:35 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: What's wrong with these Sites?
« Reply #8 on: February 23, 2014, 04:24:07 PM »
So not only are the links still active. They release new ones to bypass AV detections? Serious business!
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

gen-hackman

  • Guest
Re: What's wrong with these Sites?
« Reply #9 on: February 23, 2014, 04:43:09 PM »
logically , Pre_Scan detects ramnit in htm, html files and exe files but it doesn't desinfect , I didn't make it for.