Author Topic: Malware  (Read 2046 times)

0 Members and 1 Guest are viewing this topic.


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Malware
« Reply #1 on: December 09, 2021, 12:03:46 PM »
Hi, you can report a suspicious/malicious sample (File/Website) here: https://www.avast.com/report-malicious-file.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline hozewm

  • Newbie
  • *
  • Posts: 16
Re: Malware
« Reply #2 on: December 09, 2021, 12:05:29 PM »
I don't have the sample.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Malware
« Reply #3 on: December 09, 2021, 12:31:07 PM »
How did you upload it to VirusTotal (or didn't you) ?

I'm not sure if this is correct, but I wonder if you can't give the virus total link as Avast should be able to access that file.

Not to mention   - There are several other AVs detecting this and they aren't small companies.

Not to mention 2- Avast according to the VT link isn't detecting this.  So it is possible that it has been corrected ?

I just refreshed the link and 11 still detect it and not Avast, this is also being reported as an Email
922bc561fe72498410*****************96fb018ded9ec346724645ab.eml

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline hozewm

  • Newbie
  • *
  • Posts: 16
Re: Malware
« Reply #4 on: December 09, 2021, 12:37:10 PM »
I did not upload it , it was upload by someone else

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Malware
« Reply #5 on: December 09, 2021, 01:05:58 PM »
I don't have the sample.
Submit the VT link, should work as well.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline hozewm

  • Newbie
  • *
  • Posts: 16
Re: Malware
« Reply #6 on: December 09, 2021, 01:13:16 PM »
ok

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Malware
« Reply #7 on: December 09, 2021, 05:04:56 PM »
Hi hozewm,

It is a Tesla trojan.
As GData has it, in that case avast should also flag it in so-called pup-mode.

This malware comes in the category Infostealer/spyware like described here:
-https://tria.ge/211013-vn5zbsefg8  (given link as blocked because of downloadable malcode sample).

See signatures and behavioural patterns in that description.

Another analysis of a likewise malcreation: https://www.joesandbox.com/analysis/869868

Underlying is a so-called MITRE attack and this malcode comes classified under infostealer adware, and should be removed,
seen as what it does to your browser info. See with Nir Sofer's 'Web Browser History Viewer' (free Windows proggie)

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)

« Last Edit: December 11, 2021, 12:57:19 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!