Author Topic: Spora Ransomware  (Read 4106 times)

0 Members and 2 Guests are viewing this topic.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Spora Ransomware
« on: January 11, 2017, 09:23:55 AM »
Spora Ransomware

SHA256:   3fb2e50764dea9266ca8c20681a0e0bf60feaa34a52699cf2cf0c07d96a22553
File name:   spora.hta
Detection ratio:   9 / 55
Analysis date:   2017-01-11 08:20:29 UTC ( 0 minutes ago )
V.T-https://www.virustotal.com/en/file/3fb2e50764dea9266ca8c20681a0e0bf60feaa34a52699cf2cf0c07d96a22553/analysis/1484122829/
Avast failed to block this new sample(Ransomware). SUD to Avast Lab.

Malware Analysis Report: https://www.hybrid-analysis.com/sample/3fb2e50764dea9266ca8c20681a0e0bf60feaa34a52699cf2cf0c07d96a22553?environmentId=100
« Last Edit: January 11, 2017, 09:26:16 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

REDACTED

  • Guest
Re: Spora Ransomware
« Reply #1 on: February 16, 2017, 07:44:24 AM »
How do I get rid of this Malware? Avast does not even pick it up! :-[

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Spora Ransomware
« Reply #2 on: February 16, 2017, 08:03:00 AM »
How do I get rid of this Malware? Avast does not even pick it up! :-[
Follow instructions here  >>  https://forum.avast.com/index.php?topic=194892.0
Then start your own topic and attach requested logs



REDACTED

  • Guest
Re: Spora Ransomware
« Reply #3 on: February 16, 2017, 08:27:49 AM »
i have test in vmware , avast blocked this ransomware . but avast doesnt delete the sample like .hta , .js 

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Spora Ransomware
« Reply #4 on: February 16, 2017, 11:55:26 AM »
I think its better off sending the undetected files to submit AT virus DOT avast DOT com.  :)

Avast is detecting spora by the way:
https://virustotal.com/en/file/2637247ad66e6e57a68093528bb137c959cdbb438764318f09326fc8a79bdaaf/analysis/
https://virustotal.com/en/file/3251403ff9848ed520230a0fb8979ea4b5c8a4aa4e4a392da4c4458390f040db/analysis/

@ymchen did behav. shield pick up on the js file? because it should
« Last Edit: February 16, 2017, 11:58:22 AM by TI199 »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Spora Ransomware
« Reply #5 on: February 16, 2017, 11:56:58 AM »

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Spora Ransomware
« Reply #6 on: February 16, 2017, 12:02:54 PM »
FYI I found the .hta and js file that was reported and I have mailed it to avast  :)


Ymchen,keep me posted on whether behav. shield picks it up or not.

REDACTED

  • Guest
Re: Spora Ransomware
« Reply #7 on: February 16, 2017, 01:09:21 PM »
I think its better off sending the undetected files to submit AT virus DOT avast DOT com.  :)

Avast is detecting spora by the way:
https://virustotal.com/en/file/2637247ad66e6e57a68093528bb137c959cdbb438764318f09326fc8a79bdaaf/analysis/
https://virustotal.com/en/file/3251403ff9848ed520230a0fb8979ea4b5c8a4aa4e4a392da4c4458390f040db/analysis/

@ymchen did behav. shield pick up on the js file? because it should

this sample not a js file ,the file name extension is .hta , so behaviour shield doesnt pick up . i have test other new sample like .js file successfully blocked and quarantine sample by behaviour shield.
« Last Edit: February 16, 2017, 01:13:50 PM by ymchen »

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Spora Ransomware
« Reply #8 on: February 16, 2017, 04:52:24 PM »
I blocked the .hta files that TI199 sent me ;)

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Spora Ransomware
« Reply #9 on: February 16, 2017, 05:07:33 PM »
I blocked the .hta files that TI199 sent me ;)

Thanks for protecting us!  :)

Nice to hear ymchen
« Last Edit: February 17, 2017, 02:02:54 AM by TrueIndian »