Author Topic: Avast! continues to show poor detection against JS:Numecod  (Read 4398 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: Avast! continues to show poor detection against JS:Numecod
« Reply #15 on: February 05, 2017, 11:24:07 AM »
I found a something similar to numecod and avast completely missed it:
<snip sharing url>

And similar to this I have seen numecod from some URL's I have already submitted most.

I would advise that samples are sent directly to avast and not posted using sharing links. You have no control over who downloads it/them from the sharing link, nor what purpose they use them.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9412
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! continues to show poor detection against JS:Numecod
« Reply #16 on: February 05, 2017, 11:39:05 AM »
Hello,
I found a something similar to numecod and avast completely missed it:
htxps://s3-us-west-1.amazonaws.com/comp.3/complaint97989.zip

And similar to this I have seen numecod from some URL's I have already submitted most.

Interesting obfuscation technique within a BAT file. Haven't tried decrypting it yet, but I find it interesting the way it's done (after checking it briefly).
Visit my webpage Angry Sheep Blog

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Avast! continues to show poor detection against JS:Numecod
« Reply #17 on: February 05, 2017, 11:40:20 AM »
As per what dave said the URL is now been submitted.Again dual extension comes into play:
https://www.virustotal.com/en/file/80d21093ecf7c5f10f1846689c3d592a5b54bfe2437ac305970b9531d9f330ac/analysis/1486291370/

poor detection ratio for a old sample
« Last Edit: February 05, 2017, 11:46:38 AM by TI199 »