Author Topic: Avast does not detect uppa.exe?  (Read 3203 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
« Last Edit: March 11, 2013, 06:13:55 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

true indian

  • Guest
Re: Avast does not detect uppa.exe?
« Reply #1 on: March 12, 2013, 06:31:42 AM »
Hi Pol,
Avast! Web shield blocks as FilerepMalware  :D
« Last Edit: March 12, 2013, 06:34:42 AM by true indian »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Avast does not detect uppa.exe?
« Reply #2 on: March 12, 2013, 08:03:52 AM »
Hi true indian,

Thanks for confirming the shield detection. We are being protected,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Avast does not detect uppa.exe?
« Reply #3 on: March 13, 2013, 01:49:43 PM »
Hi Pol,
the file has been packed 3 time by 3 different packers.No wonder Avast detects it.
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Avast does not detect uppa.exe?
« Reply #4 on: March 13, 2013, 03:14:30 PM »
Hi Left123,

Yes, see that:
F-Prot packer identifier
AutoIt, UTF-8, UPX

Default packer used by AutoIt is the free UPX,
but if you wanna more protection you need to use some commercial products like TheMida, Execryptor or ZProtect.
UTF-8 is an alternative to compressing, so using the ISO-8859-1/UTF-8 setting...

Remember, if you not use UPX, to disable UPX compression and after apply the chosen packer compression

Also 3 mutexes created:
CritOpMutex  (created by the second)
MSCTF.Shared.MUTEX.IFG typical for e.g. Zeus tracker malware & win32 trojans
_SHuassist.mtx

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Avast does not detect uppa.exe?
« Reply #5 on: March 14, 2013, 12:47:47 AM »
Hi Pol,just found more time to look into it.Searching at a forum i found a confirmed Win32/Phorphiex sample
You can see it here https://www.virustotal.com/ru/file/edb1a99271f8c7b871829ec9b530e2715dc2a90685f30693730434f645a0ae18/analysis/ .
Again here,the behavioural analysis will save us.Not only this sample is packed by the very 3 same packers as uppa.exe but the created/opened ifles are the same.
The sample you provided(843921.exe):
C:\1705c491dd4ca9a8e0b82e7bd106bef10bbb08fdad752d0cb5a7bae74ea09c2b (successful)
\\.\PIPE\lsarpc (successful)
\\.\MountPointManager (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\aut1.tmp (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\noir.art (successful)
C:\WINDOWS\system32\rsaenh.dll (successful)

The sample i provided(IMG0540230-JPG.sc_):
C:\edb1a99271f8c7b871829ec9b530e2715dc2a90685f30693730434f645a0ae18 (successful)
\\.\PIPE\lsarpc (successful)
\\.\MountPointManager (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\aut1.tmp (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\noir.art (successful)
C:\WINDOWS\system32\rsaenh.dll (successful)

Is there any need to continue?You can check it on your own to find more similarities :) .
Regards,
Philip
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Avast does not detect uppa.exe?
« Reply #6 on: March 14, 2013, 05:28:07 PM »
Hi Left123,

Thanks for this instructional informative posts. It stands out in white lines on my "inner blackboard" and the lesson learnt will be applied with further investigations.
Thanks again for your positive and inspirational input,

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!