Author Topic: Worm:JS/Bondat not detected  (Read 2815 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Worm:JS/Bondat not detected
« on: September 09, 2018, 08:52:29 PM »
I've foud a worm detected by MS Defender as Worm:JS/Bondat that doesn't get detected by Avast.
This worm infects mainly in thumb drives

https://drive.google.com/file/d/17sVUA6GrW1EeiMJmh4mAtPQ3vtOLikyN/view?usp=sharing (password: virus)

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34024
  • malware fighter
Re: Worm:JS/Bondat not detected
« Reply #1 on: September 09, 2018, 10:53:51 PM »
Here on VT avast does not detect this: https://www.virustotal.com/pl/file/c823dfff4415a07b6c738e5cc8cad1282d1f2f54ab50c8206fe5763f2bc56bdb/analysis/

But it could well be it detects in pup-mode. It is Bitcoin virus, so a mining blocker will help: -myvtfile.exe is a sort of malicious software that mines digital currency. -> https://www.fortinet.com/blog/threat-research/the-growing-trend-of-coin-miner-javascript-infection.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76017
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Worm:JS/Bondat not detected
« Reply #2 on: September 10, 2018, 10:42:26 AM »
You can report a suspicious/malicious sample (File/Website) here: https://www.avast.com/report-malicious-file.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline savcin

  • Avast team
  • Full Member
  • *
  • Posts: 113
Re: Worm:JS/Bondat not detected
« Reply #3 on: September 10, 2018, 01:02:32 PM »
Detection has been created.

REDACTED

  • Guest
Re: Worm:JS/Bondat not detected
« Reply #4 on: September 10, 2018, 01:30:56 PM »
Thank you all!

@asyn the file has been sent through this link, but since it doesn't provide any feedback I thought that a forum post could provide feedback to other users with the same issue.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: Worm:JS/Bondat not detected
« Reply #5 on: September 11, 2018, 12:23:46 AM »
Here on VT avast does not detect this: https://www.virustotal.com/pl/file/c823dfff4415a07b6c738e5cc8cad1282d1f2f54ab50c8206fe5763f2bc56bdb/analysis/

But it could well be it detects in pup-mode. It is Bitcoin virus, so a mining blocker will help: -myvtfile.exe is a sort of malicious software that mines digital currency. -> https://www.fortinet.com/blog/threat-research/the-growing-trend-of-coin-miner-javascript-infection.html

polonus
Not bitcoin related

Info  >>  https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Worm%3AJS%2FBondat

Quote
Payload
Steals information about your PC

The worm collects information about your PC, including:

Malware version
User name
Computer name
Product ID
Infection GUID
Language/localization (for example, "0409" for "en-us")
Operating system version (for example, "5.1.2600.0")
This information is encoded using the RC4 algorithm, plus another custom encoder, and sent to a remote server through HTTP POST. The server's URL is hardcoded in the malware body.   


Symantec info  >>  https://www.symantec.com/security-center/writeup/2015-021912-5112-99


« Last Edit: September 11, 2018, 12:26:06 AM by Pondus »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76017
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Worm:JS/Bondat not detected
« Reply #6 on: September 11, 2018, 05:16:48 AM »
@asyn the file has been sent through this link, but since it doesn't provide any feedback I thought that a forum post could provide feedback to other users with the same issue.
OK, thanks for the report.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0