Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 19th, 2010, 11:19 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default New round of infected emails!

Scan from a Xerox WorkCentre Pro #1471642

VT results 12/42

TH

Name:  Capture19-08-2010-10.59.47 PM.jpg
Views: 593
Size:  60.3 KB
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #2  
Old August 19th, 2010, 11:34 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,410
Default Re: New round of infected emails!

TH, just received Print_document2938.zip. VT was 13/42 and virSCAN (8/36). Submitted the sample to Microsoft because MSE did not detect it.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #3  
Old August 19th, 2010, 11:38 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default Re: New round of infected emails!

Quote:
Originally Posted by JRViejo
TH, just received Print_document2938.zip. VT was 13/42 and virSCAN (8/36). Submitted the sample to Microsoft because MSE did not detect it.

My ISP uses Norton so it got pass that and at this time Prevx doesn't detect nor does VIPRE or ESET on my VM's but I sent in the sample to them!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #4  
Old August 19th, 2010, 11:42 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,410
Default Re: New round of infected emails!

Actually, my ISP caught it, however, I DL it to see if MSE would catch it. I was surprised to see in both VT & VS that ClamAV nailed it!
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #5  
Old August 19th, 2010, 11:47 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default Re: New round of infected emails!

We have a continuing thread going on at CoU about infected emails: http://www.calendarofupdates.com/upd...0&#entry109100

And a story here: http://news.softpedia.com/news/Fake-...n-147954.shtml

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #6  
Old August 20th, 2010, 02:58 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,410
Default Re: New round of infected emails!

MSE virus/spyware definition 1.89.42.0, dated 8/20/2010 at 2:48 am., caught my zipped file, during an individual file scan.

Microsoft is calling it Trojan:Win32/Meredrop, due to the Print_document_Nr195FH.exe inside the zipped file.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #7  
Old August 24th, 2010, 07:35 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default Re: New round of infected emails!

Got another from supposed Fedex this time!

VirusTotal Results: 12/42 at the time of this post!

TH

Name:  Capture24-08-2010-7.19.32 AM.jpg
Views: 386
Size:  52.6 KB
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #8  
Old August 24th, 2010, 01:40 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,410
Default Re: New round of infected emails!

TH, looks like you and I are receiving the same junk.

Just got FEDEXInvoiceEE023812OP.zip. VT (14/40) and virSCAN (7/36). Submitted the sample to Microsoft because MSE did not detect it.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #9  
Old August 24th, 2010, 04:56 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default Re: New round of infected emails!

Quote:
Originally Posted by JRViejo
TH, looks like you and I are receiving the same junk.

Just got FEDEXInvoiceEE023812OP.zip. VT (14/40) and virSCAN (7/36). Submitted the sample to Microsoft because MSE did not detect it.

Hi JR,

My ISP uses Yahoo for there Email so that could be why for me and Yahoo uses Norton and that didn't stop it!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #10  
Old August 24th, 2010, 05:09 PM
Ibrad's Avatar
Ibrad Ibrad is offline
Very Frequent Poster
 
Join Date: Dec 2009
Posts: 1,887
Default Re: New round of infected emails!

I must be lucky because I have never received a email with a virus attached.
__________________
Panda Security TRUSTED MOD


Panda Cloud Antivirus + Rising PC Doctor + Common Sense

My Security Blog: http://igl-security.blogspot.com/
  #11  
Old August 24th, 2010, 06:12 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,410
Default Re: New round of infected emails!

MSE virus/spyware definition 1.89.283.0, dated 8/24/2010 at 10:12 am., caught this FedEx zipped file, during an individual file scan.

Microsoft is calling it TrojanDropper:Win32/Oficla.T, due to the FedexInvoice_EE776129.exe inside the zipped file.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #12  
Old August 29th, 2010, 06:58 PM
Dermot7's Avatar
Dermot7 Dermot7 is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Surrey, England.
Posts: 1,842
Default Re: New round of infected emails!

From M86 Labs blog: "Over the past few days the Asprox botnet has been spamming out a fake FedEx campaign. We noticed this after we saw our old Asprox binaries downloading a new updated "196" version from the bot's command and control server.":
http://labs.m86security.com/2010/08/...asprox-binary/
  #13  
Old September 1st, 2010, 09:38 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default Re: New round of infected emails!

Got another one today from so called Fedex! VT results at time of post 6/43

TH

Name:  Capture01-09-2010-9.13.40 AM.jpg
Views: 127
Size:  42.5 KB
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:18 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums