Author Topic: Strange file here...  (Read 2318 times)

0 Members and 1 Guest are viewing this topic.

Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1431
Strange file here...
« on: February 19, 2012, 06:26:18 AM »
The file received from this link seem suspicious...

hxxp://alexresort.com/album.php?Facebook.com-IMG216089.JPG

When downloaded and saved into the desktop, it seems kind of invisible. When you try to upload it in to virustotal, this file cannot be found. It can't also be added in the sandbox...

REDACTED

  • Guest
Re: Strange file here...
« Reply #1 on: February 19, 2012, 06:39:49 AM »
The file received from this link seem suspicious...

hxxp://alexresort.com/album.php?Facebook.com-IMG216089.JPG

When downloaded and saved into the desktop, it seems kind of invisible. When you try to upload it in to virustotal, this file cannot be found. It can't also be added in the sandbox...


http://online.us.drweb.com/cache/?i=5f46027e9a4fb6c57938a65341083b9f

Trojan.DownLoader5.47980

Sent to Avast


Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1431
Re: Strange file here...
« Reply #2 on: February 19, 2012, 10:15:40 AM »

REDACTED

  • Guest
Re: Strange file here...
« Reply #3 on: February 19, 2012, 11:19:00 AM »
And this is actually what I've got after a full scan...

https://www.virustotal.com/file/f13fb6acb305d0cfd4d8a42ba95ee497bb5ffa1bd53d9ef983d2e7cc483cf5cb/analysis/1329642736/


The link that you have already defines a virus Avast (only in version 7, due to streaming update), it is still on VT Avast is not known, but with streaming updates have already determined at the end, I saw this technology in action, and I like it.

https://www.virustotal.com/file/117a60c421c19cbca807d18c7006c5f3f6811a75c49c0163356d22f3ce9be6d3/analysis/1329646007/

and the fact that you have found, I hope you have sent to the laboratory Avast?  (mdm.exe)

Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1431
Re: Strange file here...
« Reply #4 on: February 19, 2012, 02:30:49 PM »
And this is actually what I've got after a full scan...

https://www.virustotal.com/file/f13fb6acb305d0cfd4d8a42ba95ee497bb5ffa1bd53d9ef983d2e7cc483cf5cb/analysis/1329642736/


The link that you have already defines a virus Avast (only in version 7, due to streaming update), it is still on VT Avast is not known, but with streaming updates have already determined at the end, I saw this technology in action, and I like it.

https://www.virustotal.com/file/117a60c421c19cbca807d18c7006c5f3f6811a75c49c0163356d22f3ce9be6d3/analysis/1329646007/

and the fact that you have found, I hope you have sent to the laboratory Avast?  (mdm.exe)
Indeed using the cloud is actually a lot better for updates and also for fixing updates when there's trouble in it :)