Author Topic: TR/Drop.Zbot.M malware last contact reported for April 21st?  (Read 1446 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
TR/Drop.Zbot.M malware last contact reported for April 21st?
« on: April 24, 2012, 03:25:03 PM »
Hi forum friends,

Malware detections sometimes lag behind the real actual situation.
Sites have been cleansed, malware does not respond any longer, has been closed or dead, and still urls appear in blacklists. Example here: htxp://zulu.zscaler.com/submission/show/aa0753fe99d05f8713cf643be0d3d7f5-1335272335
see: htxps://www.virustotal.com/file/17455abd797b1a6d17b02a599df011817db8ebe50f76e8f3e50646f476b5fd1c/analysis/
But then again this was added on April 24st: htxp://vxvault.siri-urz.net/ViriFiche.php?ID=17651
Going to that site with Malzilla the particular download starts, I get this scan result: htxp://virusscan.jotti.org/nl/scanresult/34358428b5fc30284e813b9cdab063c2e88734bd
So what is the real status of the suspicious URLor the malware of 21st and 24th launched from there is different?

reported to virus AT avast dot com to add to detection,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!