VSUB - Malware Submissions

Details on new malware submitted to anti-malware vendors for inclusion in their products...

Tuesday, 24 July 2007

VS0707002 - Possible New Malware [Spambot?]

All,

Data on a sample of a suspected new malware being seeded
via a spam e-mail with a link to the attached sample.

URL used: http://[SITE NAME REMOVED]/media/cell_phone_prank.scr

4 copies have been trapped so far.

I haven't had a chance to test them on a goat system yet.

============================================================

Details:

FileName: cell_phone_prank.scr
FileDateTime: 20/07/2007 17:07:48
Filesize: 219256
MD5: 7c63924fdb8046940d77bfffa6772d7b
CRC32: B8574631
File Type: PE Executable

============================================================

Scan report of: cell_phone_prank.scr

@Proventia-VPS -
AntiVir -
Avast! -
AVG -
BitDefender -
ClamAV -
Command -
Dr Web -
eSafe -
eTrust-VET -
eTrust-VET (BETA) -
Ewido -
F-Prot -
F-Secure -
F-Secure (BETA) -
Fortinet Possible_MLWR.5
Fortinet (BETA) Possible_MLWR.5
Ikarus -
Kaspersky -
McAfee -
McAfee (BETA) -
Microsoft Trojan:Win32/Mespam.B
Nod32 Win32/TrojanProxy.Jaber.NAD trojan
Norman -
Panda -
Panda (BETA) -
QuickHeal Suspicious (warning)
Rising -
Sophos Sus/UnkPacker (suspicious)
Symantec -
Symantec (BETA) -
Trend Micro Possible_MLWR-5
Trend Micro (BETA) Possible_MLWR-5
VBA32 Trojan.Spambot
VirusBuster -
WebWasher Heuristic.Crypted
YY_A-Squared -
YY_Spybot -

============================================================

Labels: ,

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home