Author Topic: Executable possibly harmless?  (Read 4026 times)

0 Members and 7 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34062
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Executable possibly harmless?
« Reply #1 on: June 17, 2014, 07:05:32 PM »
reported. will have answer tomorrow


Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Executable possibly harmless?
« Reply #2 on: June 17, 2014, 09:42:27 PM »
Hey,i found this file which has the same MD5 with the one you posted,it is here
https://www.virustotal.com/nl/file/d87bfda9ac76f7e894bafb75b8eb66447e596abe638683fbb65b82228ea286a2/analysis/1383131752/
It's pretty much the same file but this one is detected 8/47.
Apart from that they share the same original file name which is  hao123Inst.exe
You can find more info here http://regrunreanimator.com/newvirus/trojan/hao123inst-exe-2.htm
"The file HAO123INST.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords."
Also Ikarus detects the file as Trojan.Win32.Spy .
It looks like an "evil" thing to me  ;D
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Executable possibly harmless?
« Reply #3 on: June 17, 2014, 09:56:44 PM »
Polonus, where did you get the file?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Executable possibly harmless?
« Reply #4 on: June 17, 2014, 09:57:22 PM »
@left123   your VT scan is from oktober 2013 ....
And if you see the scan date.... and click the blue link just to the right of it.... what happens then?      ;)

« Last Edit: June 17, 2014, 10:00:21 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Executable possibly harmless?
« Reply #5 on: June 17, 2014, 09:59:48 PM »
Polonus, where did you get the file?
The info is there Michael ..... i give you 10min to find it    ;D


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Executable possibly harmless?
« Reply #6 on: June 17, 2014, 10:00:26 PM »
Hao123 was linked to a Zeus trojan network once. I wouldn't trust it. Malicious I believe. But can someone post a DL link?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Executable possibly harmless?
« Reply #7 on: June 17, 2014, 10:01:16 PM »
Polonus, where did you get the file?
The info is there Michael ..... i give you 10min to find it    ;D

Aha! Got it! Now time for malwr.com
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Executable possibly harmless?
« Reply #8 on: June 17, 2014, 10:10:52 PM »
@left123   your VT scan is from oktober 2013 ....
And if you see the scan date.... and click the blue link just to the right of it.... what happens then?      ;)
It's exactly the same file,they share the same entry point,packer,everything.
So,that could be an old false positive that was fixed recently
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Executable possibly harmless?
« Reply #9 on: June 17, 2014, 10:18:46 PM »
@left123   your VT scan is from oktober 2013 ....
And if you see the scan date.... and click the blue link just to the right of it.... what happens then?      ;)
It's exactly the same file,they share the same entry point,packer,everything.
So,that could be an old false positive that was fixed recently
When you click the link it changes to the scan Polonus posted....
impossible to say when it was fixed..... anyway i will have FP confirmation from Norman tomorrow



Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Executable possibly harmless?
« Reply #10 on: June 17, 2014, 10:21:56 PM »
@left123   your VT scan is from oktober 2013 ....
And if you see the scan date.... and click the blue link just to the right of it.... what happens then?      ;)
It's exactly the same file,they share the same entry point,packer,everything.
So,that could be an old false positive that was fixed recently
When you click the link it changes to the scan Polonus posted....
impossible to say when it was fixed..... anyway i will have FP confirmation from Norman tomorrow
Ye i saw that,but i am just saying,it's still the same file but now it is detected only by 1 AV,if it is not an fp then i have no idea  :-X
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Executable possibly harmless?
« Reply #11 on: June 18, 2014, 07:08:01 AM »
From Norman lab

Quote
FP Case closed. FP Confirmed