Author Topic: Faktura5.js  (Read 4096 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Faktura5.js
« on: February 23, 2017, 06:07:19 PM »
My father got a .js file in his mail today, and it´s very new, only a few days old.

https://www.hybrid-analysis.com/search?query=Faktura5

Only 5 hits on hybrid analysis.

How long until it is added to avast?

I'm afraid it´s ransomware..

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Faktura5.js
« Reply #1 on: February 23, 2017, 06:10:35 PM »
Upload and scan it here  www.virustotal.com  if scanned before, click rescan
Post link to scan result here

Quote
I'm afraid it´s ransomware..
Most likely the ransomware downloader

« Last Edit: February 23, 2017, 06:12:29 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Faktura5.js
« Reply #2 on: February 23, 2017, 06:16:08 PM »
How to send samples to avast > https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

They will also recive it from VirusTotal   ;)


Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Faktura5.js
« Reply #3 on: February 23, 2017, 06:18:28 PM »
My father got a .js file in his mail today, and it´s very new, only a few days old.

https://www.hybrid-analysis.com/search?query=Faktura5

Only 5 hits on hybrid analysis.

How long until it is added to avast?

I'm afraid it´s ransomware..

Avast! mail shield blocks these as soon as they arrive as a e-mail.  :)

Mail shield has some algorithms that detect these numecod downloaders.Even if avast doesn't detect in virustotal report doesn't mean they don't protect us.  :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Faktura5.js
« Reply #4 on: February 23, 2017, 06:19:55 PM »
Quote
Avast! mail shield blocks these as soon as they arrive as a e-mail.
Not if you use webmail   ;)


Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Faktura5.js
« Reply #5 on: February 23, 2017, 06:23:03 PM »
Quote
Avast! mail shield blocks these as soon as they arrive as a e-mail.
Not if you use webmail   ;)

Well that's the only way you get infected with these...webmail services have their own spam filter to block these.Gmail for example blocks js downloads.Same with most of the webmail services which are very secure.

There is a reason why you don't see too many cerber/locky infected systems over here since most are blocked at the arrival.The one's that are missed are blocked during the binary download and caught by IDP.

I have found these type of downloader type malware come in a IT office based systems where webmail is very much used.

« Last Edit: February 23, 2017, 06:26:03 PM by TrueIndian »

REDACTED

  • Guest
Re: Faktura5.js
« Reply #6 on: February 23, 2017, 06:24:52 PM »
He was too fast, threw it away before I got to see the file.

The senders mail adress used was mailto:ldingwall@inetlink.ca
and it was a dropbox-link.

Perhaps someone else can help with the reporting.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Faktura5.js
« Reply #7 on: February 23, 2017, 06:27:50 PM »
So far i only recive this in my Yahoo mail and one time in my FastMail (fake American Express)

My oldest mail accounts, Hotmail / Gmail seems to eat all crap they try to send 


Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Faktura5.js
« Reply #8 on: February 23, 2017, 06:29:30 PM »
Now that changes things....Malware writers never seem to attack web mail since its so secure.

I have seen dropbox links on reverse.it....Never thought they actually use it to infect users.

It would still be classified as spam by the avast mail filter and if it arrives in web mail it goes straight to junk anyway.But this is really a good way for malware writers to bypass antiviruses like avast that have specific filters.

P.S. It would be more interesting if someone from avast labs chips in on this.  ;)
« Last Edit: February 23, 2017, 06:31:26 PM by TrueIndian »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Faktura5.js
« Reply #9 on: February 23, 2017, 06:30:39 PM »
He was too fast, threw it away before I got to see the file.

The senders mail adress used was mailto:ldingwall@inetlink.ca
and it was a dropbox-link.

Perhaps someone else can help with the reporting.
Searching the hash i found it, already uploaded

https://www.virustotal.com/en/file/8c401cf64cdee877d5d9ad0ec4873d02c0e4330fcf7db9a70bf05d122880fd1d/analysis/



REDACTED

  • Guest
Re: Faktura5.js
« Reply #10 on: February 23, 2017, 06:33:14 PM »
He was too fast, threw it away before I got to see the file.

The senders mail adress used was mailto:ldingwall@inetlink.ca
and it was a dropbox-link.

Perhaps someone else can help with the reporting.
Searching the hash i found it, already uploaded

https://www.virustotal.com/en/file/8c401cf64cdee877d5d9ad0ec4873d02c0e4330fcf7db9a70bf05d122880fd1d/analysis/

Thanks for that!

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Faktura5.js
« Reply #11 on: February 23, 2017, 06:33:20 PM »
Well its still tough for av vendors to detect js downloaders since they are polymorphic malware.So if avast can't block it in the mail the only way we have is to block it during the binary download process and there is where Avvast behaviour shield comes into play detecting these as IDP.ALEXA.51

REDACTED

  • Guest
Re: Faktura5.js
« Reply #12 on: February 23, 2017, 06:35:09 PM »
Now that changes things....Malware writers never seem to attack web mail since its so secure.

I have seen dropbox links on reverse.it....Never thought they actually use it to infect users.

It would still be classified as spam by the avast mail filter and if it arrives in web mail it goes straight to junk anyway.But this is really a good way for malware writers to bypass antiviruses like avast that have specific filters.

P.S. It would be more interesting if someone from avast labs chips in on this.  ;)

If the dad in question actually do click on the link, wich he most certainly did, I will have to save him...

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Faktura5.js
« Reply #13 on: February 23, 2017, 07:01:26 PM »
I have requested someone from avast to answer our queries :)

Offline Jiří Šembera

  • Avast team
  • Jr. Member
  • *
  • Posts: 46
  • Developer/Malware Analyst, former VPS maintainer
Re: Faktura5.js
« Reply #14 on: February 23, 2017, 10:19:20 PM »
Hi,

thank you for letting us know about these new campaigns. We are currently analysing them and hopefully we'll have new generic detections in place soon. In the meantime our other detection engines should cover the most of the malware downloaded when the .js script is executed (it's usually just a downloader, not directly harmful).

Jiri