Author Topic: Another dodgy attachement received in Yahoo mail  (Read 5079 times)

0 Members and 3 Guests are viewing this topic.

Offline davexnet

  • Poster
  • *
  • Posts: 546
Another dodgy attachement received in Yahoo mail
« on: May 07, 2011, 09:03:48 PM »
HI, I have Windows Defender running with Avast (sans behavior shield).

Downloaded an attachment from Yahoo mail today.  Yahoo's own AV scan didn't detect it,
(what do they use - Norton) ?
Avast didn't detect it, but Windows Defender caught it during the download.

http://www.virustotal.com/file-scan/report.html?id=aa3602bafcf9f73e92c33a559ce560ec8add36a0453654b36e3bb0987bde6536-1304794336


Who was it who said WD was useless? On the contrary, it seems.
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

MAG

  • Guest
Re: Another dodgy attachement received in Yahoo mail
« Reply #1 on: May 07, 2011, 09:16:21 PM »
Thanks for the info.

I would say expect at least one supportive comment, and maybe the odd dismissive 'it's got to get lucky sometime' from some others :)
« Last Edit: May 07, 2011, 09:58:18 PM by mag »

spg SCOTT

  • Guest
Re: Another dodgy attachement received in Yahoo mail
« Reply #2 on: May 07, 2011, 09:20:02 PM »
Those FedEx ones...oh your delivery info is wrong, download a zip and fill in the info using the exe inside...
Yeah right...

Good catch.

Did you forward it to avast? ;)

The only thing it ever catches on my machine is EICAR ;D

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Another dodgy attachement received in Yahoo mail
« Reply #3 on: May 07, 2011, 09:29:59 PM »
Quote
Yahoo's own AV scan didn't detect it, (what do they use - Norton) ?
yes... and this seems to be very new

Quote
First seen: 2011-05-07 18:52:16
Last seen : 2011-05-07 18:52:16
AV vendors are usually quickly updated on these mail malware as they are spreading quick so they all get samples quick
If you scan this again in 48 hours i guess you will have a 90% VT score

Offline davexnet

  • Poster
  • *
  • Posts: 546
Re: Another dodgy attachement received in Yahoo mail
« Reply #4 on: May 07, 2011, 09:47:46 PM »
Would you like me to forward the sample?

I have to ask, how is MS beating many AV companies at early detection?
What mechanisms do they have in place?  Is it their SpyNet ?
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Another dodgy attachement received in Yahoo mail
« Reply #5 on: May 07, 2011, 09:57:56 PM »
Would you like me to forward the sample?

I have to ask, how is MS beating many AV companies at early detection?
What mechanisms do they have in place?  Is it their SpyNet ?
could be.... maybe someone like you sendt them a sample...or one of those working at MS got it in the mail...
everyone knows that when you recive a mail from Fedex/ups/DHL etc, they are sucpious and you need to test it at VT before you open....especially if you dont expect to recive anything

MAG

  • Guest
Re: Another dodgy attachement received in Yahoo mail
« Reply #6 on: May 07, 2011, 10:00:49 PM »
Would you like me to forward the sample?

I have to ask, how is MS beating many AV companies at early detection?
What mechanisms do they have in place?  Is it their SpyNet ?

MS is also an av company. WD reporting back to MS is default, and I believe that with MSE it is mandatory - so I guess that must help.

Offline davexnet

  • Poster
  • *
  • Posts: 546
Re: Another dodgy attachement received in Yahoo mail
« Reply #7 on: May 07, 2011, 10:07:05 PM »
Sample sent to Pondus at the email address he provided me.

The point I was trying to make was that MS seems to be beating dedicated security companies
at early detection.

What ever mechanism they're using, it seems to work.

Dave

AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Another dodgy attachement received in Yahoo mail
« Reply #8 on: May 07, 2011, 10:07:17 PM »
1. http://www.virustotal.com/file-scan/report.html?id=aa3602bafcf9f73e92c33a559ce560ec8add36a0453654b36e3bb0987bde6536-1304794336

2. Who was it who said WD was useless?

1. Does anyone get a result with this link..?? If so, please post it, as I get: queued
2. I'm one of them. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline davexnet

  • Poster
  • *
  • Posts: 546
Re: Another dodgy attachement received in Yahoo mail
« Reply #9 on: May 07, 2011, 10:10:31 PM »
You're right - I'm the one who submitted it.  I merely copied the URL when the report was shown to me.
Is there something else I should be doing to get a permanent report?
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

spg SCOTT

  • Guest
Re: Another dodgy attachement received in Yahoo mail
« Reply #10 on: May 07, 2011, 10:18:27 PM »
1. http://www.virustotal.com/file-scan/report.html?id=aa3602bafcf9f73e92c33a559ce560ec8add36a0453654b36e3bb0987bde6536-1304794336
...
1. Does anyone get a result with this link..?? If so, please post it, as I get: queued
...

File name:
FedEx.zip
Submission date:
2011-05-07 18:52:16 (UTC)
Current status:
finished
Result:
11/ 40 (27.5%)

avast isn't one of them...

Bear in mind that MS also has hotmail...these are a dime a dozen there...they know what to look for ;)

Offline davexnet

  • Poster
  • *
  • Posts: 546
Re: Another dodgy attachement received in Yahoo mail
« Reply #11 on: May 07, 2011, 10:20:00 PM »
Here's a screen print for anybody who cannot see VT properly.
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Another dodgy attachement received in Yahoo mail
« Reply #12 on: May 07, 2011, 10:27:16 PM »
Here's a screen print for anybody who cannot see VT properly.

Thanks for posting the screnshot, but avast's results are not included...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Another dodgy attachement received in Yahoo mail
« Reply #14 on: May 07, 2011, 10:55:27 PM »
Fedex,good old Bredolab.
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus