Author Topic: Changelog 07.06.2010.zip (Malware not detected?)  (Read 7314 times)

0 Members and 1 Guest are viewing this topic.

Saffron_Blaze

  • Guest
Changelog 07.06.2010.zip (Malware not detected?)
« on: June 11, 2010, 06:05:05 PM »
I received an obvious attempt at infecting our computer. Typical email with a short note offering a file we never requested from someone we don't know. The attached zip file had the file name given in the subject heading. I am curious as to how the file even made it to our inbox. Avast is scanning incoming emails so why did it not detect the virus/worm in the email attachment?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #1 on: June 11, 2010, 06:13:14 PM »
Well I don't know if avast scans .zip attachments by default as they are inert until the user saves the attachment to disk, extracts the files and tries to run an executable. At the point of extraction and certainly before they are executed the File System Shield would scan the contents.

So if you save the attachment to your hard disk (no risk) and then right click on the .zip file and have avast scan it, does it detect it then ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #2 on: June 11, 2010, 06:13:40 PM »
Maybe it's a new threat..!!?
You can send it to avast: virus(at)avast.com
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #3 on: June 11, 2010, 06:20:42 PM »
Before getting carried away, lets see if it has even been scanned by avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #4 on: June 11, 2010, 06:37:27 PM »
Before getting carried away, lets see if it has even been scanned by avast.

All right, David..! ;)
Let's wait for a reply first.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #5 on: June 11, 2010, 08:55:06 PM »
we've seen this nasty already.. it was an e-mail worm coded in Visual Basic and packed with PECompact using a double extension (.doc.exe).. all known variants were detected afaik... if this is a new variant, we would appreciate to have an sample.. btw: v5 should detect it in your mailbox heuristically

Saffron_Blaze

  • Guest
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #6 on: June 11, 2010, 09:46:01 PM »
I saved the file and then did a scan of it. Avast did detect the malware at this point as Win32:Malware-gen. I am still not certain why avast isn't scanning these attachments as they come in. It certainly ups the risk level in that I have to rely on every user of the computer to be fairly knowledgeable about malware.

YoKenny

  • Guest
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #7 on: June 11, 2010, 09:54:47 PM »
Maybe if you posted your operating system and Service Pack level and email client it would help.  :)

Saffron_Blaze

  • Guest
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #8 on: June 12, 2010, 10:04:15 PM »
Vista SP2, Outlook 2003.

When I open Outlook the Avast MS Office plugin splash shows on start up.
Mail shield is running and both inbound and outbound messages are selected for scanning.
Attachment scan is also checked off.
Heuristics is set to normal.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #9 on: June 12, 2010, 10:09:38 PM »
When I open Outlook the Avast MS Office plugin splash shows on start up.
Mail shield is running and both inbound and outbound messages are selected for scanning.
Attachment scan is also checked off.
Heuristics is set to normal.

So did you send the sample to avast yet..??
If not, please do so..!!
Thanks..!
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Saffron_Blaze

  • Guest
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #10 on: June 12, 2010, 11:03:06 PM »
Oddly enough when I sent it to Avast the scanner detected the malware and blocked it.

Saffron_Blaze

  • Guest
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #11 on: June 12, 2010, 11:09:42 PM »
Oddly enough when I sent it to Avast the scanner detected the malware and blocked it.


Note in the original email it reports the email as clean.

Quote
From: Nettie Beatty [mailto:henpeckedbg26@rollover.com]
Sent: June-08-10 8:10 PM
To: [deleted]
Subject: Changelog 07.06.2010

 

Hello,
as promised,
Nettie




--------------------------------------------------------------------------------

avast! Antivirus: Inbound message clean.

Virus Database (VPS): 08/06/2010
Tested on: 08/06/2010 7:40:40 PM
avast! - copyright (c) 1988-2010 ALWIL Software.


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #12 on: June 12, 2010, 11:10:14 PM »
Oddly enough when I sent it to Avast the scanner detected the malware and blocked it.

That's not so odd, but if avast already dedects it, there's no need to send it..!! ;)
asyn

W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Saffron_Blaze

  • Guest
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #13 on: June 12, 2010, 11:29:04 PM »
I think you are missing the point. Avast is NOT detecting these virus laden attachments when the email comes inbound to my mailbox. If it were the attachment would have been blocked. I suppose the virus variant might not have been in the database when it was sent but is now? Just looking to understand.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Changelog 07.06.2010.zip (Malware not detected?)
« Reply #14 on: June 12, 2010, 11:35:49 PM »
I think you are missing the point. Avast is NOT detecting these virus laden attachments when the email comes inbound to my mailbox. If it were the attachment would have been blocked. I suppose the virus variant might not have been in the database when it was sent but is now? Just looking to understand.

Well, the point is avast dedects it now..! ;)
There are thousands of new threats every! day, so we (users) have to participate..!!
And that's what you did, so thank you for that...!!
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0