Author Topic: Really malware, but still not on major blacklists?  (Read 1142 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Really malware, but still not on major blacklists?
« on: March 11, 2012, 05:58:12 PM »
Executable is flagged as TR/Agent.114688.86, and avast flags Win32:Malware-gen: hxtps://www.virustotal.com/file/9d305794f6b5dfd8c2489a7c507973b1689a85d61fca6d016b60095a52f3da9a/analysis/
See: hxtp://vscan.urlvoid.com/analysis/29e658b4c3457fe06efc50088674b266/ZG9na2V5LWRyaXZlci1leGU=/
Also detected here: htxp://zulu.zscaler.com/submission/show/7fc113842f0e4fe49998bd6ee62573cd-1331484087 as a 100/100 malware
Why then it is being missed here at Sucuri"s htxp://sitecheck.sucuri.net/results/http://60.248.179.124/3-Update/files/dogKey-driver.exe
Norton Safe Web does not have it, google safe browsing and some blacklists. Good to know that avast detects,
more details also here: htxp://avpclub.alone.tw/discuz/redirect.php?tid=41336&goto=lastpost  (link poster kinkids on AVPClub Security Forums)

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!