Author Topic: hash files  (Read 2916 times)

0 Members and 1 Guest are viewing this topic.

Offline Hobbitmann

  • Newbie
  • *
  • Posts: 19
hash files
« on: November 26, 2019, 04:50:59 PM »
how to send or scan hash files (MD5-SHA256 ..) to Avast Labs ...
i need send a virustotal report because Avast no detect this malware.
Thanks

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: hash files
« Reply #1 on: November 26, 2019, 05:12:34 PM »
Quote
i need send a virustotal report because Avast no detect this malware.
You may post link to virustotal scan result here



How to report to avast lab  >>  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438





Offline Hobbitmann

  • Newbie
  • *
  • Posts: 19

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: hash files
« Reply #3 on: November 27, 2019, 03:54:35 AM »
Hi, Avast! will receive a copy of the file from VirusTotal automatically.

File Upload for Review: https://www.avast.com/en-eu/report-malicious-file.php

On a side note, can you upload that file to Dropbox or similar and post a DL link so I can have a look?

Cheers,
Mike
« Last Edit: November 27, 2019, 03:56:43 AM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: hash files
« Reply #4 on: November 27, 2019, 01:41:18 PM »
Hi Hobbitman & Michael(alan1998) & Pondus,

This is Windows Script Host malware, falling into this realm -> CIMV2PROVIDERSUBSYSTEM malware:
Consider info: https://www.exposedbotnets.com/2010/11/wwwmyroujicommalware-hosted-with-united.html

Would be interesting to see whether it was also launched from Pasadena???

A variant of the Nemucode trojan, as a new variant played out on an existing pattern (since 2010).

Generic malcode, and that is probably why avast does not have it flagged yet. 7 av-engines do now.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Hobbitmann

  • Newbie
  • *
  • Posts: 19
Re: hash files
« Reply #5 on: November 27, 2019, 04:00:43 PM »
Im not have the file to upload online have the link for virustotal. Upload the link of virustotal ?
Thanks for answer the question. (sorry my english is bad)

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: hash files
« Reply #6 on: November 27, 2019, 11:22:02 PM »
Im not have the file to upload online have the link for virustotal. Upload the link of virustotal ?
Thanks for answer the question. (sorry my english is bad)

I was hoping you had the original file that you uploaded to VirusTotal. No matter, I might be able to reach out and grab it from them.

Follow the instructions here >> https://forum.avast.com/index.php?topic=194892.0 - You may have some remnants.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: hash files
« Reply #7 on: November 28, 2019, 12:56:13 AM »
Im not have the file to upload online have the link for virustotal. Upload the link of virustotal ?
Thanks for answer the question. (sorry my english is bad)

I was hoping you had the original file that you uploaded to VirusTotal. No matter, I might be able to reach out and grab it from them.
<snip>

I feel that is fortunate, as a link to live/suspect malware in the forums could well result in alerts in the forums. 

The other point is that with a link to live/suspect malware, there is no control over who downloads it or what they might do with it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: hash files
« Reply #8 on: November 28, 2019, 06:37:09 PM »
Im not have the file to upload online have the link for virustotal. Upload the link of virustotal ?
Thanks for answer the question. (sorry my english is bad)

I was hoping you had the original file that you uploaded to VirusTotal. No matter, I might be able to reach out and grab it from them.
<snip>

I feel that is fortunate, as a link to live/suspect malware in the forums could well result in alerts in the forums. 

The other point is that with a link to live/suspect malware, there is no control over who downloads it or what they might do with it.

We've done this before David. There are many ways of ensuring that User's are not put at risk; something I neglected to mention in my hastily written reply. (Such as password protecting the archive).

However, you must recognize that a text file (which, is exactly what this is) poses no risk to users, unless they're stupid enough to open it, and try to find links to open.

Quote
Magic   ASCII text
That's taken form the VT Report, where magic refers to "Magic Byte". You would need the actual executable from Emotet to make use of that file. (Emotet is commonly spread through DOCX files, using a vulnerability/exploit in how Word handles Macro's. The macro runs powershell, which decides a base64 encoded command and executes it. That command could reach out to a C2 server and download additional malware, or it may drop one itself.)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Hobbitmann

  • Newbie
  • *
  • Posts: 19
Re: hash files
« Reply #9 on: November 28, 2019, 07:17:29 PM »

They do not answer my question, can you send MD5 or sha256 hash files to avast yes or no? How do I report a threat not detected by Avast having only the Virustotal link?
Thank you

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: hash files
« Reply #10 on: November 28, 2019, 07:47:02 PM »

They do not answer my question, can you send MD5 or sha256 hash files to avast yes or no?
How do I report a threat not detected by Avast having only the Virustotal link?
Thank you
This is not the actual malware file but just a dat file (text file with info) made by the malicious program
And that is probably why so many vendors chose not to add detection for it. The malicious program that made the file is most likely detected

All files uploaded to virustotal is shared among all members so avast lab already have the file





« Last Edit: November 28, 2019, 07:59:52 PM by Pondus »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: hash files
« Reply #11 on: November 28, 2019, 09:07:02 PM »

They do not answer my question, can you send MD5 or sha256 hash files to avast yes or no? How do I report a threat not detected by Avast having only the Virustotal link?
Thank you

I answered this question in my first reply.

Quote
Hi, Avast! will receive a copy of the file from VirusTotal automatically.

Avast! will have already received this file - no further threat reporting is required at this point. The file that is being detected poses no risk to your system. It's the program that made said file that poses a risk.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Hobbitmann

  • Newbie
  • *
  • Posts: 19
Re: hash files
« Reply #12 on: November 29, 2019, 06:53:09 PM »

and why do antivirus detect it? I have another link that I just sent and was not detected by Avast, more than 4 months ago.
https://www.virustotal.com/gui/#/file/c09870e2a20ab34a4e50830297d8e2ba9057a7ad994dcef5f25023a91b932dd6/detection
Another file not detected by Avast

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: hash files
« Reply #13 on: November 29, 2019, 08:20:20 PM »

and why do antivirus detect it? I have another link that I just sent and was not detected by Avast, more than 4 months ago.
https://www.virustotal.com/gui/#/file/c09870e2a20ab34a4e50830297d8e2ba9057a7ad994dcef5f25023a91b932dd6/detection
Another file not detected by Avast

No solution 100% detection rate - assuming you don't detect every file (harmful or not). It's also a matter of whether or not it's worth their time. No use in detecting malware from 30 years ago - it wouldn't run in modern environments.

VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.