Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Samples missed by avast (VirusTotal links only!)
« previous
next »
Print
Pages:
1
...
23
24
[
25
]
26
27
...
66
Go Down
Author
Topic: Samples missed by avast (VirusTotal links only!) (Read 405713 times)
0 Members and 1 Guest are viewing this topic.
DavidR
Avast Überevangelist
Certainly Bot
Posts: 88446
No support PMs thanks
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #360 on:
June 12, 2011, 04:14:48 PM »
Quote from: esr30 on June 12, 2011, 11:59:35 AM
So avast will get the files if I submit them or not.
Yes they do, but a) it takes time and b) they also get a lot of chaff with the wheat/samples, as has been mentioned in the forums. So it is going to take longer to sort that wheat from the chaff to get the benefit, direct submission to avast is quicker.
Logged
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 23.10.6086 (build 23.10.8563.800) UI 1.0.784/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #361 on:
June 13, 2011, 05:55:22 PM »
Hi folks,
This one not yet detected by avast:
http://www.virustotal.com/file-scan/report.html?id=75153fa12146d3505d83dda9fb2ae5cedc085f0360adad5640bfe29a2e14c6f1-1307976186
See:
http://www.threatexpert.com/report.aspx?md5=5e27d125661e91796759b542c59240d3
See:
http://www.garyshood.com/virus/results.php?r=5e27d125661e91796759b542c59240d3
Is the Trojan horse TR/Crypt.FKM.Gen..Fraudtool
Malware link forwarded to virus AT avast dot com
polonus
«
Last Edit: June 13, 2011, 06:14:29 PM by polonus
»
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #362 on:
June 15, 2011, 10:10:57 PM »
Hi folks,
This backdoor,... keys.jpg - ALERT: [PHP/BackDoor.D] keys.jpg
Contains detection pattern of the PHP virus PHP/BackDoor.D,
not detected by avast: VT scan:
http://www.virustotal.com/url-scan/report.html?id=c1d19d8a76b2fb50290f6afd3a04b067-1308160512
file detection VT:
http://www.virustotal.com/file-scan/report.html?id=7c55c7b55c745d07ea75c2b944eb6a4ff57447bbc005e7d669851178c48505b6-1308167744
16/ 42 (38.1%)
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #363 on:
June 18, 2011, 05:10:46 PM »
Hi forum friends,
This sample not detected by avast yet:
http://www.virustotal.com/file-scan/report.html?id=1ee330f81e3999a8bfdf95461ccf7052eac3ba04e2b061e7822f90f9fcb3e714-1308408426
generic malware
File hash: 9cd70492ad620bb922ad0bb815708c5a
See:
http://vscan.urlvoid.com/analysis/9cd70492ad620bb922ad0bb815708c5a/cmVhZG1lLWV4ZQ==/
&
See:
http://www.threatexpert.com/report.aspx?md5=9cd70492ad620bb922ad0bb815708c5a
Sent to virus AT avast dot com
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Pondus
Probably Bot
Posts: 37332
Not a avast user
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #364 on:
June 18, 2011, 10:01:04 PM »
uploaded to avast / MBAM / SAS
http://www.virustotal.com/file-scan/report.html?id=1b95fd5c45a1314f4abf593ce012f413f017b93949af506f7a8e85bd3fe79c71-1308425693
http://www.virustotal.com/file-scan/report.html?id=5cae17ca820c5a818e0648cf9de76ad1cc2a7c997c51f8912b67bcdd53b343ed-1308425362
http://www.virustotal.com/file-scan/report.html?id=91eda36708ce8277e84fcbecfb65dfb5e81c0f9ea0e89c70cd38872a66104601-1308425376
http://www.virustotal.com/file-scan/report.html?id=64dfb39015b938dca3e510b1eb3ba08a8535e830abe8ecbfcd2f3d1e765bae41-1308425387
Logged
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #365 on:
June 18, 2011, 10:30:05 PM »
Hi Pondus,
Can this have been a different variant, seen to the MD5 hash?
http://file.virscan.org/report/842711ae4167a3045aee49d8b9b43567.html
See:
http://anubis.iseclab.org/?action=result&task_id=1b48f9caf85a67c142906d1ed5ed7893a&format=html
polonus
P.S. And this one:
http://www.virustotal.com/file-scan/report.html?id=d6edb11340619afb783ff8086f64c4ecb6733373d26ec57d23432318b8791423-1308412278
«
Last Edit: June 18, 2011, 10:34:24 PM by polonus
»
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Pondus
Probably Bot
Posts: 37332
Not a avast user
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #366 on:
June 18, 2011, 10:39:37 PM »
sure looks like it.....not same MD5
ThreatExpert report on the first sample
http://www.threatexpert.com/report.aspx?md5=2c2d488d727589158f907dd36c04eb9e
«
Last Edit: June 18, 2011, 11:21:40 PM by Pondus
»
Logged
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #367 on:
June 19, 2011, 04:50:55 PM »
Missed by avast redirect to Zeusv2, see:
http://www.virustotal.com/url-scan/report.html?id=645dbea8d0d2249d2a3be5f523f28f36-1308487354
and
http://www.virustotal.com/file-scan/report.html?id=a4888546e938c43404b307e6416fcaaa06cf7363d94efed5cfbd491280f564ab-1308494558
also re:
http://wepawet.iseclab.org/view.php?hash=645dbea8d0d2249d2a3be5f523f28f36&t=1308494638&type=js
and accompanying Anubis report:
http://anubis.iseclab.org/?action=result&task_id=1947012aa7e40552481eed1a3ec1d6ad9
Info forwarded to virus AT avast dot com
polonus
«
Last Edit: June 19, 2011, 04:53:49 PM by polonus
»
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #368 on:
June 19, 2011, 07:35:28 PM »
This malbanker malware, Winsanta.exe not detected by avast, see:
http://www.virustotal.com/file-scan/report.html?id=51f4d16f405ec3d5b7b16d2528a0718613acceb3b03e7e1e4b33fd987350b40b-1308482476
Threatexpert analysis:
http://www.threatexpert.com/report.aspx?md5=47ba243c524c6a978a53d36f73663a66
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #369 on:
June 20, 2011, 09:12:25 PM »
Generic trojan mot detected by avast, VT:
http://www.virustotal.com/url-scan/report.html?id=097498da46f8ac24e7b4407db4ffa237-1308588739
File analysis at VT:
http://www.virustotal.com/file-scan/report.html?id=0b8a79442001bede8cd3ff233a296e5868cfa48ae6a52b903f46d05e5f91135d-1308596320
See Anubis report:
http://anubis.iseclab.org/?action=result&task_id=10a02c524dadf2b942dcdd8b155f0baea
polonus
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
grantdb
Guest
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #370 on:
June 21, 2011, 11:13:07 AM »
Hello
This malware was shutting Avast down especially it seemed while Avast was updating or scanning.
http://www.virustotal.com/file-scan/report.html?id=0ed55ae8fc6d7ff2dc4a5175b644f5fc6068c257ceaaf5f2b47e392b786bd1f9-1308641359
emailing sample to virus(at)avast
The file name is system32StopAllWorw.exe but not sure what its classified as (trojan, backdoor etc)
Thanks for great Antivirus software!
Grant
Logged
Lisandro
Avast team
Certainly Bot
Posts: 67198
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #371 on:
June 21, 2011, 01:28:41 PM »
Thanks for submitting grantdb.
Malware that kill the antivirus must have special attention imho.
Logged
The best things in life are free.
polonus
Avast Überevangelist
Probably Bot
Posts: 33810
malware fighter
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #372 on:
June 21, 2011, 03:54:06 PM »
Hi here is the behaviour summary for this:
http://xml.ssdsandbox.net/view/334fa2a25a6097143f540b26dd13878b
Can also come as part of downloaders:
e.g.
Look up at ViCheck.ca and get VT results:
http://www.virustotal.com/file-scan/report.html?id=e548a71809e0c66deca4aa92752021c1dfa4db2f8deb95b8ba588c2d2abfc51a-1241488981
avast detects...
.\system32stopallworw.exe
6.0.2900.3156
Microsoft Corporation
efd496c8e5507f188e47df4edbc91aa9 = MD5hash
.\system32stopallworw.exe
6.0.2900.3156
Microsoft Corporation
407364a0c3ebd0b544d8689c45383935
\system32stopallworw.exe
6.0.2900.3156
Microsoft Corporation
3c41382942fb749fd6f1f2144e2e9dca
..\system32stopallworw.exe
6.0.2900.3156
Microsoft Corporation
1db8c421b4fa7bfcddcc14bd38f5c89c
.\system32stopallworw.exe
6.0.2900.3156
Microsoft Corporation
12cc1b486051536d9ffa7b3459cb745d
polonus
«
Last Edit: June 21, 2011, 04:12:04 PM by polonus
»
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
JuninhoSlo
Avast Evangelist
Advanced Poster
Posts: 849
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #373 on:
June 21, 2011, 05:39:17 PM »
Undetected malware
1:http://www.virustotal.com/file-scan/report.html?id=8c16baa04cd8055ffb228cf152a03724cb80fccfbd7f39853af6d08217986ad7-1308667154
Sent to Avast team/lab
Logged
Banankage
Newbie
Posts: 5
Re: Samples missed by avast (VirusTotal links only!)
«
Reply #374 on:
June 24, 2011, 05:40:39 PM »
Fake antivirus that are not detected by avast
http://www.virustotal.com/file-scan/report.html?id=361d27adc51258db9e3e50858d592dbd6b236aeece3568993a768b255c1b2c6f-1308927934
http://www.virustotal.com/file-scan/report.html?id=d8b361811b4e12bc1e292b074f6cd6150d0f5e45b49ba0912043b8e2eec9a62e-1308928565
http://www.virustotal.com/file-scan/report.html?id=89ee3e6255ec44d1ef7ba3a746d49eecdf860c851c0ac8c0c7631f00fb614221-1308928781
«
Last Edit: June 24, 2011, 05:45:29 PM by Banankage
»
Logged
Print
Pages:
1
...
23
24
[
25
]
26
27
...
66
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Samples missed by avast (VirusTotal links only!)