Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 31st, 2009, 12:51 AM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Interesting piece of malware

Hello Wilders Finest,

I just came across a sample that is at least 3 months old and is detected by 1/41 on VT. (Sophos detected it)

Surprisingly I scanned it with SAS Free and it detected it too! MBAM did not detect.

PM me if you would like to play.
  #2  
Old July 31st, 2009, 04:56 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,413
Default Re: Interesting piece of malware

What is interesting in it? What actions it is supposed to do?
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #3  
Old July 31st, 2009, 07:16 AM
BrendanK.'s Avatar
BrendanK. BrendanK. is offline
Frequent Poster
 
Join Date: Jun 2008
Location: Australia
Posts: 520
Default Re: Interesting piece of malware

Please PM me the sample.
  #4  
Old July 31st, 2009, 07:26 AM
Retadpuss's Avatar
Retadpuss Retadpuss is offline
Suspended Member
 
Join Date: Apr 2009
Posts: 226
Default Re: Interesting piece of malware

me too
  #5  
Old July 31st, 2009, 08:33 AM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Interesting piece of malware

Quote:
Originally Posted by aigle
What is interesting in it? What actions it is supposed to do?

It's rare that a piece of malware that has been out at least 3 months will go undetected by this many AV's. I'm not sure what it does. Sophos detects it as Mal/WaledPak-D
  #6  
Old July 31st, 2009, 08:44 AM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,000
Default Re: Interesting piece of malware

I doubt it's anything serious, feel free to send me it.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #7  
Old July 31st, 2009, 08:45 AM
BrendanK.'s Avatar
BrendanK. BrendanK. is offline
Frequent Poster
 
Join Date: Jun 2008
Location: Australia
Posts: 520
Default Re: Interesting piece of malware

I just submitted it to 30+ vendors so we will find out
  #8  
Old July 31st, 2009, 08:47 AM
dawgg's Avatar
dawgg dawgg is offline
Frequent Poster
 
Join Date: Jun 2006
Posts: 808
Default Re: Interesting piece of malware

Maybe its simply not "wild" enough, or corrupt, or not malicious? - not "interesting" IMO.
  #9  
Old July 31st, 2009, 08:50 AM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Interesting piece of malware

Quote:
Originally Posted by dawgg
Maybe its simply not "wild" enough, or corrupt, or not malicious? - not "interesting" IMO.

Then this thread will be intended for people who find it "interesting" then.
  #10  
Old July 31st, 2009, 10:20 AM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,216
Default Re: Interesting piece of malware

Just a reminder. This isn't a malware trading forum. I recommend reading the Terms Of Service.

Any further posts of this type will be removed without notice.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:27 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums