Author Topic: Samples missed by avast (VirusTotal links only!)  (Read 415808 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Samples missed by avast (VirusTotal links only!)
« Reply #735 on: May 18, 2012, 01:11:57 AM »
Hi !Donovan,

You are right as one of the sacn results give specifically "non-malicious",

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Samples missed by avast (VirusTotal links only!)
« Reply #736 on: May 18, 2012, 08:21:58 AM »
Ransom Kuluoz

https://www.virustotal.com/file/361e0b4554ca3748f3400138dded289532f7aa53fd1c2b2fd2e921df531cdf21/analysis/1337270928/

remains undetected....

http://zulu.zscaler.com/submission/show/fa1f2b17cb31d1b0bb10da8ead1058e1-1337270982

reported to avast!  ;)


First seen by VirusTotal
 2010-06-25 09:46:39 UTC ( 1 år, 10 måneder ago )     yea.....must be malware   ;)

Sigcheck
publisher................: MBTY
product..................: RansomHide
internal name............: ransomhide
file version.............: 0.06.0024
original name............: ransomhide.exe
comments.................: For http://forum.simplix.ks.ua

NORMAN lab
Quote
ransomhide.exe : Clean!


true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #737 on: May 18, 2012, 08:53:42 AM »
There is detection for Polska Policja: https://www.virustotal.com/file/7bbd11c0e9902e6bed46bb4ea2832be45155591f4d85356d5f961b03489a21e1/analysis/
pol

Pol,i guess thats a same one with a different file MD5.  ::) The sample i have is not detected yet.And as far i as the Mebroot samples go i will try looking into sophos FP...


Thanks!  ;D


true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #738 on: May 18, 2012, 08:57:33 AM »

true indian

  • Guest
« Last Edit: May 18, 2012, 09:44:09 AM by true indian »



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Samples missed by avast (VirusTotal links only!)
« Reply #742 on: May 18, 2012, 03:38:22 PM »
Hi Pondus,

Thank you, Pondus, keep these reports coming to add to and to check avast detection. You prove that one has to be selective as what to report to virus AT avast dot com, so that the detections fit their categories.
This thread proves that the common user should have additional non-residential protection next to his avast residential av-solution WITH the shields enabled, like MBAM and SAS on demand and keep these fully updated and perform a quick scan with them now and again.. Personally I combine that with some third-party  in-browser protection like DrWeb's online scanner and BitDefender TrafficLight and  QuickScan to further close the vulnerability gap/vulnerability window. But scanning feedback is very important. If DrWeb's online pre-scanner misses detections I report back (that is why Dim@rik came to join our forums) , and also when Zscaler Zulu does not have detection I will give feedback of what has been found with other scanners.
On a side note. I tried Quttera WIS (beta) at htxp://www.quttera.com/ against all sorts of verified malcious URLs and all the time the scan comes up as clean. Is this scanner a scam for their services or just worthless?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Samples missed by avast (VirusTotal links only!)
« Reply #743 on: May 18, 2012, 05:44:20 PM »
See: htxp://zulu.zscaler.com/submission/show/7168cb24855e4ad93246acc1fd01ae81-1337355518
and accompanying VT results: htxps://www.virustotal.com/file/e56df40e2ba498dec082ef61412c04c578636c618f07cbec6bd1ecf060360ebf/analysis/
trojan banker detection missed,
reported to virus AT avast dot com,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


true indian

  • Guest
« Last Edit: May 19, 2012, 10:43:38 AM by true indian »



Mr Wrong

  • Guest

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Samples missed by avast (VirusTotal links only!)
« Reply #749 on: May 19, 2012, 09:58:44 PM »
Hi Mr Wrong,

This a Smidfraud adware detection,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!