Author Topic: Not detected or sandboxed  (Read 6535 times)

0 Members and 4 Guests are viewing this topic.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Not detected or sandboxed
« on: February 25, 2013, 08:42:08 PM »
The file that is available at this link is not sandboxed or detected by avast!.   http://fileham.com/ad/setup/exad016.exe

Virus Total Scan:  hxxps://www.virustotal.com/de/file/b930594a81444fbffb4c75b310bc96998bbe018289f3935bb41e51f164c76966/analysis/1361821195/

This is definitely Adware. There is no reputation warning.
« Last Edit: February 27, 2013, 07:16:26 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #1 on: February 25, 2013, 09:47:33 PM »
I am in the process of running it on my VM

I received this warning

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #2 on: February 25, 2013, 09:54:47 PM »
This is the install screen

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89692
  • No support PMs thanks
Re: Not detected or sandboxed
« Reply #3 on: February 25, 2013, 09:58:12 PM »
@ Steven Winderlich
Please 'modify' your post change the URL from http to hXXp, to break the link and avoid accidental exposure to suspect malware, thanks.

I think part of this problem is that virustotal can't replicate all of the real-time avast functions like the behavior shield as in essexboy's post...

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #4 on: February 25, 2013, 10:02:23 PM »
Quote
O4 - HKLM..\Run: [FileHamBrowser] C:\Program Files\Fileham.com\FileHamBrowser\ÆÄÀÏÇÔŽ»ö±â.exe menu File not found
C:\Documents and Settings\All Users\Start Menu\Programs\ÆÄÀÏÇÔ
C:\Program Files\FileHam.com

These are the elements installed
I am going to reboot to see what happens next

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34066
  • malware fighter
Re: Not detected or sandboxed
« Reply #5 on: February 25, 2013, 10:10:22 PM »
Hi Steven Winderlich,

Make that link non-click-through with hxtp. This is unknown_file_FileHamBrowser/BrowserUninstall.ex-.
See: https://www.virustotal.com/nb/file/349220b2be2684675b81d1d9953f8eea12b38e49138d0c43ad5d8c1baafc8d44/analysis/
Avast may flag this upon running after download as riskware or PUP.
See: http://www.threatexpert.com/report.aspx?md5=c7774f488d6b0d587a94823de0ce9896
A lot of it has been closed: http://support.clean-mx.com/clean-mx/viruses.php?domain=fileham.com&sort=inetnum%20ASC
Closed 2013-02-16 23:14:29  after being 3676.7 hrs of activity...
See: http://anubis.iseclab.org/?action=result&task_id=1c911c60fa1aa8c142ddbac118b7153e0&format=html
Firekeeper alert for this Trojan.Agent./Gen-Banker
=== Triggered rule ===
alert (msg:"The address you tried to access points to a Malware. Please visit http://www.malwarepatrol.net for more information"; url_content:"htxp://fileham.com/"; reference:url,www.malwarepatrol.net; fid:340704; rev:20130225172726;)

=== Request URL ===
htxp://fileham.com/ad/setup/exad016.exe


polonus
« Last Edit: February 25, 2013, 10:38:20 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #6 on: February 25, 2013, 10:19:54 PM »
It installs another browser, and does not appear to hijack IE or FF as I can see so far


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #7 on: February 25, 2013, 10:29:44 PM »
It has an uninstall entry and uninstalls relatively cleanly

I feel this may just be another browser, that in this case is tailored towards Korean users


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34066
  • malware fighter
Re: Not detected or sandboxed
« Reply #8 on: February 25, 2013, 10:30:25 PM »
Hi essexboy,

Also consider this: http://google.com/safebrowsing/diagnostic?site=fileham.com/
And this: http://windowfin.com/bbs/board.php?bo_table=windowfin&wr_id=31410
and here: http://rightsecurity.blogspot.nl/2012/01/blog-post.html
But as I downloaded it with Malzilla and scanned with SAS (I just skimmed/scanned and never ran the executable), it detected Trojan,Agent/Gen-Banker, and even asked me to do a reboot to remove any further traces of it. There must be a generic detection pattern that both triggered SAS and my particular  firekeeper IDS  (with malwarepatrol latests installed),

polonus
« Last Edit: February 25, 2013, 10:36:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #9 on: February 25, 2013, 10:34:25 PM »
I played around with it and nothing untoward happened apart from the fact that to run it you need to use the Korean language pack, so I guess no one who does not speak Korean will use it

Edit: I ran OTL ,AdwCleaner and Combofix on completion all clean apart from a folder remnant

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34066
  • malware fighter
Re: Not detected or sandboxed
« Reply #10 on: February 25, 2013, 10:40:55 PM »
Hi essexboy,

Trust your expertise in analyzing the download status. Again here I would play completely safe and classify it as riskware for the time being.
By the way urlquery dot net scan IDS flags an alert: http://urlquery.net/report.php?id=1123533

Damian
« Last Edit: February 25, 2013, 10:45:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #11 on: February 25, 2013, 10:43:19 PM »
Yep would concur, running some remaining tests to be 100%

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34066
  • malware fighter
Re: Not detected or sandboxed
« Reply #12 on: February 25, 2013, 10:56:30 PM »
From another download link scanned I get: https://www.virustotal.com/nb/url/78eceba99b91021a29d23673d3daffffb9a07c6f2698cfcab47b77a44d6f42cb/analysis/1361829120/ and https://www.virustotal.com/nb/file/b930594a81444fbffb4c75b310bc96998bbe018289f3935bb41e51f164c76966/analysis/
Rather consitent results.
This is alos strange on the initial download link that Steven Winderlich provided: http://vurldissect.co.uk/default.asp?url=http%3A%2F%2Ffileham.com%2F&btnvURL=Dissect&selUAStr=1&selServer=1&ref= (vurldissect scans scans are being IP-monitored against abuse)
Quote
Page Title:      No HTML title tags found
Server Response:    200 [ OK ]
Server Type:    Apache
Server IP:    115.71.7.14
115.71.7.15
115.71.7.16
115.71.7.17
115.71.7.11
115.71.7.12
115.71.7.13
IP PTR:    IP does not appear to have a PTR record
IP does not appear to have a PTR record
IP does not appear to have a PTR record
IP does not appear to have a PTR record
IP does not appear to have a PTR record
IP does not appear to have a PTR record
IP does not appear to have a PTR record
Links found?:    0
Scripts found?:    4
iFrames found?:    0
MD5:    49471e6d5bba1b2e268ba4a9dd86abb0
Dissected:    This URL has been dissected 1 times
Last Dissected:    2/25/2013 10:01:30 PM
Link to this query:    http://vurldissect.co.uk/?url=XXXXXX
Flagged here: http://www.siteadvisor.com/sites/115.71.7.14

polonus

« Last Edit: February 25, 2013, 11:18:35 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not detected or sandboxed
« Reply #13 on: February 25, 2013, 11:01:10 PM »
Well I went on a clicking frenzy and nothing happened .. All tools report clear

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
« Last Edit: February 27, 2013, 07:57:37 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10