Author Topic: avast as a subject of an email  (Read 3417 times)

0 Members and 1 Guest are viewing this topic.

sagitta

  • Guest
avast as a subject of an email
« on: December 02, 2008, 06:03:38 AM »
I'm just reporting a message received with avast subject that is probably a virus. I didn't open it, just copy in the notebook to report at the forum. I think it is helpful for somebody else and avast manager.

Elenir

See bellow

Return-Path: <teste@avast.com.br>
Received: from sinai6-1.uol.com.br (sinai6.srv.intranet [172.27.64.27])
    by samba13-a with LMTPA;
    Tue, 02 Dec 2008 01:27:55 -0200
Received: from localhost (localhost [127.0.0.1])
   by starfury14.uol.com.br (Postfix) with ESMTP id CB2D629E
   for <------>; Tue,  2 Dec 2008 01:27:55 -0200 (BRST)
Received: from linuxserver.midiaimpressa.com.br (revdns.midiaimpressa.com.br [67.205.89.71])
   by starfury14.uol.com.br (Postfix) with ESMTP id 40BC229F
   for <------->; Tue,  2 Dec 2008 01:27:55 -0200 (BRST)
Received: from 189-31-58-126.gnace704.dsl.brasiltelecom.net.br ([189.31.58.126] helo=avast.com.br)
   by linuxserver.midiaimpressa.com.br with esmtpa (Exim 4.69)
   (envelope-from <teste@avast.com.br>)
   id 1L7Kv6-0007Qp-9u
   for ---------; Mon, 01 Dec 2008 23:23:24 -0300
Message-ID: <20081202022321031.7GQcdhPx1X2whwmyyGmV@revdns.midiaimpressa.com.br>
From: "Avast te ajudando" <teste@avast.com.br>
To: "-------------" <----------->
Subject: Teste nosso anti virus
Date: Tue, 2 Dec 2008 00:23:21 -0200
MIME-Version: 1.0
Disposition-Notification-To: "Avast te ajudando" <teste@avast.com.br>
Content-Type: text/html;
   charset="iso-8859-1"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - linuxserver.midiaimpressa.com.br
X-AntiAbuse: Original Domain - uol.com.br
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - avast.com.br
X-SIG5: f238daf0eb4072dc76979e80d0778c0f
Content-Transfer-Encoding: quoted-printable
X-Antivirus: avast! (VPS 081201-0, 01/12/2008), Inbound message
X-Antivirus-Status: Clean


<a href=3D"http:  //w w w.osbrasilleiros.com.br/avast.exe">download</a>.=

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast as a subject of an email
« Reply #1 on: December 02, 2008, 09:44:46 PM »
Shame on .br spreading spam :'(
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: avast as a subject of an email
« Reply #2 on: December 02, 2008, 11:46:30 PM »
Tech, this isn't from any official avast or distributor the from is easily faked and if you check out the full info it comes with an link which they are trying to pass off as avast, either an update or download of avast.exe no doubt to infect unwary recipients of the email. It is too small to be either at 42.5KB.

DrWeb link checker confirms sagitta suspicion the link is to an infected file, see image
wXw.osbrasilleiros.com.br/avast.exe

So you did well to avoid this as avast doesn't detect anything.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: avast as a subject of an email
« Reply #3 on: December 02, 2008, 11:58:53 PM »
Update:

Virustotal gives 21 of 36 scanners finding something they didn't like mostly it looks like another banker variant that seems very frequent in Brazil, http://www.virustotal.com/analisis/8d3a736de4f278e25485bc116087739d

I have submitted the sample to avast (real ;D)
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast as a subject of an email
« Reply #4 on: December 03, 2008, 01:04:39 AM »
Virustotal gives 21 of 36 scanners finding something
Did you download the file and submit it? How? Does virus total allow scanning of files in the web?
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: avast as a subject of an email
« Reply #5 on: December 03, 2008, 02:10:14 AM »
Yes, I downloaded it as my b1971.gif image shows in my first reply.

So VirusTotal doesn't allow scan on-line files, though DrWeb link checker did confirm a trojan.downloader, also in my first post.

I added the file to the user files section of the chest after downloading and submitted to avast from there with the new submission. I then did a manual iAVS update so it kicked off the submission upload right after the update check.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security