Author Topic: Samples missed by avast (VirusTotal links only!)  (Read 415784 times)

0 Members and 2 Guests are viewing this topic.

true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #960 on: June 13, 2013, 02:49:52 PM »
Good find Pol,show how fast these things spread  :)

true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #961 on: June 15, 2013, 11:56:20 AM »
Again FUD autorun sample  >:(

https://www.virustotal.com/en/file/3ff323e2bd69cab9f2a015f1df6402c96477c6591625bcb73c6defa597f0d6e7/analysis/1371289602/
https://www.virustotal.com/en/file/a293e9a0edb0c34de2b348ffa053a2ee4c965a5b678fd545a81ea16414494dc4/analysis/1371289603/

submitted to avast.

EDIT: WTF one of the sample is 4 days old and still FUD,no AV vendor see's it yet  :o :o :o :o:

First submission 2013-06-11 08:24:31 UTC ( 4 days, 1 hour ago )
« Last Edit: June 15, 2013, 12:15:41 PM by true indian »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Samples missed by avast (VirusTotal links only!)
« Reply #962 on: June 15, 2013, 01:53:17 PM »
These samples were found here: http://forums.malwarebytes.org/index.php?showtopic=127787
and also sunmitted here: http://support.emsisoft.com/topic/11569-true-indians-submissions/
i04040.js for instance should be detected by avast as HTML:Iframe-MS [Trj]

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: Samples missed by avast (VirusTotal links only!)
« Reply #964 on: June 24, 2013, 06:15:42 PM »
There should be no distribution of samples via this forum, it is a support forum and not a quasi malware distribution service.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #965 on: June 24, 2013, 06:19:10 PM »
There should be no distribution of samples via this forum, it is a support forum and not a quasi malware distribution service.

Oops! many apologizes david..I have removed that from my reply I was only saying that because if anyone else wants to circulate the samples to some other AV vendors but I will take a note of that.



TheBeateMaker

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #968 on: July 08, 2013, 07:29:20 PM »
https://www.virustotal.com/de/file/83eac1bc7aa643e82215911f7fc5bbae1e9c0bf290d02f1ba2783c264891d60a/analysis/
https://www.virustotal.com/de/file/164864255d356996cd8111dd74b5b2733fa578a60081a433eb6ff8ee70315281/analysis/
https://www.virustotal.com/de/file/afaae780f6d98834728b31b799cf1f094c4429398a54702946d68ea7642aec98/analysis/
https://www.virustotal.com/de/file/22cd8de3dcba2fb38cd8b4a11c39c899f8ce5441f6020d7aff5c4e789b1b593a/analysis/
https://www.virustotal.com/de/file/41b87401075228c0d8129e3a8522f1ab6ca4fb592aacbff53c241a14cfafa7b4/analysis/
https://www.virustotal.com/de/file/a4661ed1dff681b214f04a22c57ef06bbe79ea57c51f10eaca61f9364e267559/analysis/
https://www.virustotal.com/de/file/893fcdfdc1797eaea7d56d92f98068b27d1b68f9eaadd17495118a4d7c6d4885/analysis/
https://www.virustotal.com/de/file/315f9a5fcd45dc3a3cad55d74e59a445b9758319bf286cb9ae9bb3cb1d56e15b/analysis/
https://www.virustotal.com/de/file/237bedfebbcce3d2751c49cf6cc6f879ce4a81ee34eaee74f053e3706a5ded68/analysis/
https://www.virustotal.com/de/file/393215b42032762ec30cfebf731fd7756fcd9c6535032ea5f78f0e9b74831805/analysis/
https://www.virustotal.com/de/file/0a18573765d6e32a12c070ea5fbfd09b848ad24281ff315450121dca274322dd/analysis/
https://www.virustotal.com/de/file/8b66cd525e28891f8d57bb1c7ea502c1f61e9d3dd9deb7045b744d9b41e460e5/analysis/

https://www.virustotal.com/de/file/f0f903dcbd8df45681478cf11b8a5ae405b9705350dc3b94130eccdb12e46216/analysis/
https://www.virustotal.com/de/file/de19110db290c4bcb94d0d9302a6c44c976bde1389c75cecd245363627e16123/analysis/
« Last Edit: July 08, 2013, 08:10:05 PM by TheBeateMaker »

true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #969 on: July 10, 2013, 06:17:02 PM »
TheBeateMaker,Are you sending all samples to avast via virus@avast.com through e-mail,if not then posting links here will be of no use.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
« Last Edit: July 11, 2013, 04:42:23 PM by alan1998 »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Samples missed by avast (VirusTotal links only!)
« Reply #972 on: July 11, 2013, 02:54:52 PM »
IDS flagged it here: http://urlquery.net/report.php?id=3533128
loaded will be kernel32.dll (where IsDebuggerPresent is located)
The circumvention is for a particular code example !
mov eax,dword ptr fs:[18]
mov eax,dword ptr ds:[EAX+30]
mov byte ptr ds:[eax+2],0

This will patch the IsPresent flag, ensuring IsDebuggerPresent always returns 0 
(credits go to  kuba on reverse engineering)

Adware - two detect in latest scan: https://www.virustotal.com/en/file/411240f7d25a1a63a68b0874eb8d122c3b2c2e0bddb94eee55818b6a535b6915/analysis/ (installer detection -> Global\Phoenix_Installer (failed) & RasPbFile (failed), this issue is a class of bug called a "Token Leak"....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Samples missed by avast (VirusTotal links only!)
« Reply #973 on: July 18, 2013, 12:37:49 PM »
https://www.virustotal.com/en/file/619531aa8bf0000586f23549475d523b36ac70a0f916ba17ddf9586137d532f4/analysis/1374143415/

Adware. It was "Supposed" to be a movie. I noticed the .exe part at the end. I figured it'd be malicous, thought I'd see what I could do to help. This seems like a good place.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

true indian

  • Guest
Re: Samples missed by avast (VirusTotal links only!)
« Reply #974 on: July 18, 2013, 12:41:26 PM »
https://www.virustotal.com/en/file/619531aa8bf0000586f23549475d523b36ac70a0f916ba17ddf9586137d532f4/analysis/1374143415/

Adware. It was "Supposed" to be a movie. I noticed the .exe part at the end. I figured it'd be malicous, thought I'd see what I could do to help. This seems like a good place.

send the file to virus@avast.com via mail,dont report it here it is not going to help avast in anyway  :)