Author Topic: Potentially damaging executable not detected?  (Read 5392 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Potentially damaging executable not detected?
« Reply #1 on: December 26, 2013, 08:18:55 PM »
Kaspersky is detecting it as UDS:Dangerous.Object.Multi.Generic.

Undetected by Avast.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Potentially damaging executable not detected?
« Reply #3 on: December 26, 2013, 09:00:42 PM »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Potentially damaging executable not detected?
« Reply #4 on: December 26, 2013, 09:34:30 PM »
That homepage. I've seen it before.

also, Is this a a 0access rootkit?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Potentially damaging executable not detected?
« Reply #5 on: December 26, 2013, 09:38:42 PM »
I saw that webpage also before. Common with Adware and PUPs.

According to Virustotal this is an Generic Trojan.

After execution its downloading something in the background and BOTH files are running in memory then.

File is still being processed by Kaspersky Lab.
« Last Edit: December 26, 2013, 09:48:41 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Potentially damaging executable not detected?
« Reply #6 on: December 27, 2013, 12:24:32 AM »
Hi Steven Winderlich, alan1998 and Pondus,

Maybe we have stumbled onto something suspicious here, time to forward to avast for detection results, I guess,
related to this down loader: http://camas.comodo.com/cgi-bin/submit?file=308a13460daa2e6cb624bf91d08391d2e2a457dee57f31f9ebd8d3e77b200fe8

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Potentially damaging executable not detected?
« Reply #7 on: December 27, 2013, 12:27:08 AM »
I reported the file via quarantine to Avast Research Lab.

Will see how they do.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Potentially damaging executable not detected?
« Reply #8 on: December 27, 2013, 12:30:20 AM »
Hi Steven Winderlich,

The
Quote
sample_1.exe&ini=open.ini
makes it suspicious looking enough to qualify as malware.
See: Up(nil):   unknown_file_$INSTDIR/GreenDou.exe   APNIC   CN   abuse at gddc dot com dot cn   113.107.56.85    to 113.107.56.85   qiniudn dot com   htxp://vvdown.u.qiniudn.com/exe/0.exe?download/av2015-202-12554.exe -> http://support.clean-mx.de/clean-mx/viruses?id=17409280
-> https://www.virustotal.com/en/file/308a13460daa2e6cb624bf91d08391d2e2a457dee57f31f9ebd8d3e77b200fe8/analysis/
Generic Genome Downloader variant, there also missed by avast! 29 out of 47 detect  :o


polonus
« Last Edit: December 27, 2013, 12:40:01 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Potentially damaging executable not detected?
« Reply #9 on: December 27, 2013, 12:32:24 AM »
Yep.

Cannot give a new VT scan cause file scanner is not working at the moment, URL Scan is working, also last analysis.

The Greendeu.exe file is loading and running a ton of dll files as you can see under behavioral analysis in Malwr.
« Last Edit: December 27, 2013, 12:36:02 AM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Potentially damaging executable not detected?
« Reply #10 on: December 27, 2013, 12:46:07 AM »
Hi Steven Winderlich,

As far as I can establish it modifies registry settings to prevent anti-virus and firewall applications from functioning correctly.
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment.
Good you guys responded to me initially reporting,

Damian

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Potentially damaging executable not detected?
« Reply #11 on: December 27, 2013, 12:48:46 AM »
No problem.

Thats the only good thing we can do.

Everything else is Avasts job. :D

With an Mac you dont really need to bother about these threats, but there are also Mac threats out there.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Potentially damaging executable not detected?
« Reply #12 on: December 27, 2013, 01:43:35 PM »
It is a randomized download and this should also be considered: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Generic-A/detailed-analysis.aspx
The urlquery dot net report should flag this by an IDS alert,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!