Author Topic: VBS/Downloader.ac not detected (Solved)  (Read 5021 times)

0 Members and 1 Guest are viewing this topic.

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
VBS/Downloader.ac not detected (Solved)
« on: October 09, 2015, 03:47:22 AM »
Hello

E-mail trying to trick me
Dear (a) Customer, As your request annexed following the report of income.
Regards.

then file in ZIP, avast again not detected

6 /54 antivirus detected

Rendimentos182734910.vbe

results of the analysis
 
https://www.virustotal.com/en/file/a7d8ceea4eecc35d484ce93e429ea69374d7b800f8ae6f79ded223d93d07aafa/analysis/1444353946/

https://www.hybrid-analysis.com/sample/a7d8ceea4eecc35d484ce93e429ea69374d7b800f8ae6f79ded223d93d07aafa?environmentId=1
« Last Edit: October 09, 2015, 09:37:25 PM by jefferson sant »

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: VBS/Downloader.ac not detected
« Reply #1 on: October 09, 2015, 04:13:29 AM »
Hi i am submitted the file to avast! :)
« Last Edit: October 09, 2015, 04:20:08 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: VBS/Downloader.ac not detected
« Reply #2 on: October 09, 2015, 04:18:38 AM »
I wonder how Eset is quickly block this threat.
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: VBS/Downloader.ac not detected
« Reply #3 on: October 09, 2015, 04:27:58 AM »
I wonder how Eset is quickly block this threat.

It is the heuristic detection.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: VBS/Downloader.ac not detected
« Reply #4 on: October 09, 2015, 04:34:55 AM »
I wonder how Eset is quickly block this threat.

It is the heuristic detection.
So why avast! every time fail to block it.Avast! has heuristic detection and HIPS.
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: VBS/Downloader.ac not detected
« Reply #5 on: October 09, 2015, 08:34:22 AM »
Hello,

detection was added. We are working on update of our heuristic detections right now,

thanks for sample.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: VBS/Downloader.ac not detected
« Reply #6 on: October 09, 2015, 09:10:48 AM »
Hello,

detection was added. We are working on update of our heuristic detections right now,

thanks for sample.
You are wellcome.Detection is Other Malware-gen[Trj] :)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
« Last Edit: October 09, 2015, 09:19:55 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: VBS/Downloader.ac not detected
« Reply #8 on: October 09, 2015, 09:37:08 PM »
Hello,

detection was added. We are working on update of our heuristic detections right now,

thanks for sample.

thanks for the answer
really is Other:Malware-gen [Trj]
It should soon be set the new name to the VBE

Now 21 antivirus is detecting the sample

https://www.virustotal.com/en/file/a7d8ceea4eecc35d484ce93e429ea69374d7b800f8ae6f79ded223d93d07aafa/analysis/1444418869



« Last Edit: October 09, 2015, 10:13:21 PM by jefferson sant »

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: VBS/Downloader.ac not detected (Solved)
« Reply #9 on: October 09, 2015, 10:11:09 PM »
Hi,

detection name Other:Malware-gen [Trj]  is ok. This is usually used for some automatical detection based on our filters etc which are released with every stream update. This detection is a regular detection so there shouldn't be any problem with it.

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: VBS/Downloader.ac not detected (Solved)
« Reply #10 on: October 09, 2015, 10:18:38 PM »
Hi,

detection name Other:Malware-gen [Trj]  is ok. This is usually used for some automatical detection based on our filters etc which are released with every stream update. This detection is a regular detection so there shouldn't be any problem with it.

this file is different this is another detection.When trojans bankers are defined with a detection based on signatures created, but then name is changed.
Detection is permanent, this case will not  suffer change
Thank you for the Clarification.   :)
« Last Edit: October 09, 2015, 10:32:24 PM by jefferson sant »

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: VBS/Downloader.ac not detected
« Reply #11 on: October 15, 2015, 04:32:56 AM »

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: VBS/Downloader.ac not detected
« Reply #12 on: October 15, 2015, 04:45:54 AM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
« Last Edit: October 15, 2015, 04:48:53 AM by jefferson sant »