oss-sec mailing list archives

Virii in the wild


From: Henri Salo <henri () nerv fi>
Date: Fri, 4 Jun 2010 22:47:23 +0300

http: //ecard-gre etings-com.googlegrou ps.com/web/ecard.zip

ecard.zip
8e4830ee84783c6fd17d4475cd1120f0
75adc566ab7ee7fc06c19c01413ddb13c090406b
0bdb420658f31cadad291ae497066e8f9227166a02976a548cdb5c57

ecard.exe
ba8e39a695ea84767adb0b90f5973332
73383ca43fc98fbba5d1358bebfeb9e09864d306
9a995e18175cedcdb5c041fc96bd71cf6202b8534348664ccae179a9

PC_protect.exe
ae875123e2325a54249974eaf425697a
411329f5eee7b35494e05d23919122671251343b
f8d1df776592d7159be5ece59059a9fa76c47cf511dd49ed642cd5ac

https://anubis.iseclab.org/?action=result&task_id=1d65344c1a22298d4c91244f24710205c
https://anubis.iseclab.org/?action=result&task_id=14865c640caefc854815769e2262e7297
http://www.virustotal.com/analisis/b1d265068e42add36d161de63abcd09d461ba7598bc7bf2187843bcfb1db2e2a-1275679442
http://www.virustotal.com/analisis/8a0d55265395aa8d947d012de267c808e9432d0c218e35210d735f2dd49bae86-1275679472
http://virusscan.jotti.org/en/scanresult/e09e3c7d2a494edc53cc43005ab60c27fde134f7
http://virusscan.jotti.org/en/scanresult/548e8b7a6995c70f3c79dcafbc33cd1d8ea0d3ef

I already reported this to ClamAV, F-Secure and AVG. Contact me if you
want the binaries.


Best regards,
Henri Salo


Current thread: