Amazon

Thursday, 26 August 2010

New FedEx malware run... Zbot

Been a while since I've posted to here, so thought it was about time...

A new malware run *just* came in... with a nice jpg and a not-so-nice exe in a zip file...




















Submitted the exe to VirusTotal and the detection, isn't great...






Already being detected as: Sanesecurity.Malware.14529.UNOFFICIAL

Cheers,

Steve
Sanesecurity

Tuesday, 27 October 2009

Fake Facebook Password Reset Confirmation

Hi,

Has loads of these hit the inbox this morning....
















Virus Total:

AntivirusVersionLast UpdateResult
a-squared4.5.0.412009.10.27-
AhnLab-V35.0.0.22009.10.26-
AntiVir7.9.1.442009.10.26-
Antiy-AVL2.0.3.72009.10.26-
Authentium5.1.2.42009.10.27W32/Bredolab!Generic
Avast4.8.1351.02009.10.26-
AVG8.5.0.4232009.10.26Win32/Heur
BitDefender7.22009.10.27Trojan.Downloader.Bredolab.AZ
CAT-QuickHeal10.002009.10.27-
ClamAV0.94.12009.10.27-
Comodo27442009.10.27Heur.Packed.Unknown
DrWeb5.0.0.121822009.10.27-
eSafe7.0.17.02009.10.25Suspicious File
eTrust-Vet35.1.70842009.10.26-
F-Prot4.5.1.852009.10.26-
F-Secure9.0.15370.02009.10.22Trojan.Downloader.Bredolab.AZ
Fortinet3.120.0.02009.10.26-
GData192009.10.27Trojan.Downloader.Bredolab.AZ
IkarusT3.1.1.72.02009.10.27-
Jiangmin11.0.8002009.10.26-
K7AntiVirus7.10.8792009.10.24-
Kaspersky7.0.0.1252009.10.27Packed.Win32.Krap.w
McAfee57832009.10.26Bredolab.gen.a
McAfee+Artemis57832009.10.26Bredolab.gen.a
McAfee-GW-Edition6.8.52009.10.27-
Microsoft1.52022009.10.27TrojanDownloader:Win32/Bredolab.X
NOD3245452009.10.26-
Norman6.03.022009.10.26W32/Obfuscated.D2!genr
nProtect2009.1.8.02009.10.26-
Panda10.0.2.22009.10.26-
PCTools4.4.2.02009.10.19-
Prevx3.02009.10.27-
Rising21.53.10.002009.10.27-
Sophos4.46.02009.10.27Mal/Bredo-A
Sunbelt3.2.1858.22009.10.26Trojan.Win32.Bredolab.Gen.1 (v)
Symantec1.4.4.122009.10.27-
TheHacker6.5.0.2.0542009.10.26-
TrendMicro8.950.0.10942009.10.27TROJ_BREDLAB.SMF
VBA323.12.10.112009.10.26-
ViRobot2009.10.27.20062009.10.27-
VirusBuster4.6.5.02009.10.26-

Detected as:

Sanesecurity.Malware.12841
Sanesecurity.Malware.12842

Wednesday, 26 August 2009

Spammer Fail

A nice big...





















to the spammer that sent this...





Firefox says....






I think they meant http:// not htt://

:)

Friday, 26 June 2009

michael jackson virus already :(

Well, it didn't take long for the "them" to abuse the situation did it? :(

News item, with a picture and "video" to download:





















Here's the Anubis report on the "video"

Being detected as : Sanesecurity.Malware.11747.UNOFFICIAL

Update: Other article with translation here

Cheers,

Steve
Sanesecurity

Monday, 16 March 2009

Fake News/Flash Player

Interesting email came in just:

I worry about you httx: // ho.bestbreakingfree.com/news.php

Here's the "news page" that you are taken too....

















Downloading the fake Player and running it through VirusTotal gives you this:
















VirusTotal

As you can see the 0-hour detection rates aren't that good (3/39 scanners) :(

I'm sure we'll see more of this.