Author Topic: Possible virus/malware report  (Read 4940 times)

0 Members and 1 Guest are viewing this topic.

Serevinus

  • Guest
Possible virus/malware report
« on: February 06, 2011, 06:46:07 PM »
Hi,

I just received an email with an attachment that I believe to be a virus or at least malware...

Attachment removed

This file has managed to bypass at least 3 separate antivirus systems (Clam AV, Avast Server, Avast 5 IS), so maybe it is not virus/malware at all.

Subject: Post Express Service. Your package delivered! NR2029
From: Post Express <postmail-pn623@laredo.com>
Attachment: Post_Express_Label_INN19767.zip
Attachment contents: Post Express Label.exe (has an MS Word icon)
Message body (the last paragraph is hidden):
Good afternoon

Your package has been returned to the Post Express office.
The reason of the return is "Incorrect delivery address of the package"

Attached to the letter mailing label contains the details of the package delivery.
You have to print mailing label, and come in the Post Express office in order to receive the packages.

Thank you for your attention.
Post Express Service.

A deputation of the assembly, apprised of his approach, came to meet him: Sire, said the president of this deputation, the assembly, eager to provide for your safety, offers you and your family an asylum in its bosom.The procession resumed its march, and had some difficulty in crossing the terrace of the Tuileries, which was crowded with an animated mob, breathing forth threats and insults. The king and his family had great difficulty in reaching the hall of the assembly, where they took the seats reserved for the ministers. Gentlemen, said the king, I come here to avoid a great crime; I think I cannot be safer than with you. Sire, replied Vergniaud, who filled the chair, you may rely on the firmness of the national assembly. Its members have sworn to die in maintaining the rights of the people, and the constituted authorities. The king then took his seat next the president. But Chabot reminded him that the assembly could not deliberate in the presence of the king, and Louis XVI.
« Last Edit: February 06, 2011, 08:46:36 PM by Serevinus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Possible virus/malware report
« Reply #2 on: February 06, 2011, 08:30:50 PM »
@ Serevinus
Please remove the attachment, suspect files shouldn't be posted to the forums. The last thing we want as and when this is detected is for avast to be alerting on its own support forums.

Samples should be sent directly to avast:
Send the sample to avast as a Undetected Malware:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.
Or
Send the sample to virus (at) avast (dot) com zipped and password protected with the password in email body, a link to this topic might help and false positive/undetected malware in the subject.

Note the VT results for email.eml are seen under a different MD% and SH1 and had a higher number of detections 17/43 http://www.virustotal.com/file-scan/report.html?id=b279e6f147eafa85a5f42619a78c57c271dfcf8895788491655b3129102075a1-1297020989.
« Last Edit: February 06, 2011, 08:41:58 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Possible virus/malware report
« Reply #3 on: February 06, 2011, 08:47:49 PM »
Quote
Note the VT results for email.eml are seen under a different MD% and SH1 and had a higher number of detections 17/43
yepp, i only scanned the code i found inside...

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Possible virus/malware report
« Reply #4 on: February 06, 2011, 09:03:31 PM »
Seems to make a big difference on the number of detections.

@ Serevinus
Thanks for removing the attachment.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Serevinus

  • Guest
Re: Possible virus/malware report
« Reply #5 on: February 06, 2011, 09:07:30 PM »
No problem,

Have now emailed the report

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Possible virus/malware report
« Reply #6 on: February 06, 2011, 09:08:43 PM »
OK, as you can see (click my first image to enlarge) I have also submitted it from the avast chest.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Possible virus/malware report
« Reply #7 on: February 07, 2011, 11:38:45 AM »
NORMAN analysis

Quote
The File "email.eml" is having an attachment in it namely "Post_Express_Label_INN19767.zip" in which the extracted File "Post Express Label.exe" is malicious and detected as "Suspicious_Gen2.HVSIA".