Author Topic: Avast does not detect PHP/Small.AA here...  (Read 2264 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Avast does not detect PHP/Small.AA here...
« on: February 02, 2012, 04:53:34 PM »
See: https://www.virustotal.com/url/6a37cbb8aa1df4d5baae3b8d041ed8ca72bed6580216abc4f003dd36554b4bf0/analysis/1328197283/
and given safe here: http://urlquery.net/report.php?id=18880
But indeed infected, see:
http://vscan.urlvoid.com/analysis/f9bb68fa94b0229b41d6fe4ba1758e98/eW91dHViZS1waHA=/
See: -http://jsunpack.jeek.org/?report=c6d2dfa4f952727f5d0c2309467e8a2440d53f89
Open last link when security savvy, with ample script protection and in a VM,

first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools

syntax error: *
  correction: SELECT
syntax error: .
  correction: FROM
syntax error: /* 18 Des 2011 Kalimantan Barat ... <end>
  correction: <end> bad web rep, see: * recky a.k.a bogel /*  ->
http://www.mywot.com/en/scorecard/reverber8.net

polonus


« Last Edit: February 02, 2012, 04:58:05 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
« Last Edit: February 02, 2012, 05:01:54 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Avast does not detect PHP/Small.AA here...
« Reply #2 on: February 02, 2012, 05:12:28 PM »
Hi Pondus,

Thanks for confirming avast does not detect this yet, Norman does not either.
But the avast webshield should detect this, as it detects JS:Illredir-AQ[Trj] on  
-http://sucuri.net/malware/malware-entry-mwjsgen2
But for the given malcious page, the php download will begin immediately without any avast  alert.
Additionaly I will give the bizimbal report: http://www.bizimbal.com/odb/details.html?id=1181546
Here we can read more about this PHP malware: -http://www.bizimbal.com/docs/article02.html(avast will alert this link as PHP:Small-AG[Trj] a flag that is safe to ignore. as it detects parts of the code, but there is no payload inside the article. It describes how easily site servers are being probed...article author = Yavuz Darendelioglu a.k.a bioyavuz of Offensive IP Database,

polonus
« Last Edit: February 02, 2012, 07:09:24 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!