Jump to content
robertutzu

Facebook imprastie virusi !

Recommended Posts

Posted
Era detectat ca IRC Bot, deci o porcarie probabil. Oricum, ideea de spreding e oarecum noua, imi place ca se descarca automat.

Se folosete de un soft care are optiunea spread facebook si yahoo ?

sau e un script php :)

Posted (edited)

A fost creata o aplicatie (de Facebook), si nu stiu cum (si nici nu ma intereseaza) a facut redirect pe o pagina [de pe Facebook] (chiar daca utilizatorul nu a dat Allow la acea aplicatie) catre un executabil.

Modificare: Am gasit link-ul fisierului, si ma uit peste el.

Initial am dat de: "imbot.exe|1|M|0|0|/stext "C:\pass.txt"|0|7|0|0|0|1|0|bak burda ne war!|1|1|1|10|" care este un sir de setari folosit de bindere/cryptere. Ceea ce imi spune ca va scrie fisierul imbot.exe care probabil va salva ceva in C:\pass.txt. Deci e vorba de un rahat, nu e ceva complex.

Nu am timp si nici chef sa aflu in detaliu ce face, ma uit doar putin peste el. PS: "bak burda ne war" = "Uite aici, ce r?zboi!". Interesant.

Edited by Nytro
Posted

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

File name:

facebook-pic000934519.exe

Submission date:

2011-02-02 18:54:28 (UTC)

Current status:

finished

Result:

7 /43 (16.3%)

VT Community

not reviewed

Safety score: -

Compact

Print results

Antivirus Version Last Update Result

AhnLab-V3 2011.01.27.01 2011.01.27 -

AntiVir 7.11.2.59 2011.02.02 -

Antiy-AVL 2.0.3.7 2011.01.28 -

Avast 4.8.1351.0 2011.02.02 Win32:Malware-gen

Avast5 5.0.677.0 2011.02.02 Win32:Malware-gen

AVG 10.0.0.1190 2011.02.02 Dropper.Generic3.IVP

BitDefender 7.2 2011.02.02 -

CAT-QuickHeal 11.00 2011.02.02 -

ClamAV 0.96.4.0 2011.02.02 -

Commtouch 5.2.11.5 2011.02.02 -

Comodo 7568 2011.02.02 -

DrWeb 5.0.2.03300 2011.02.02 Trojan.Inject.3631

Emsisoft 5.1.0.2 2011.02.02 -

eSafe 7.0.17.0 2011.02.02 -

eTrust-Vet 36.1.8136 2011.02.02 -

F-Prot 4.6.2.117 2011.02.01 -

F-Secure 9.0.16160.0 2011.02.02 -

Fortinet 4.2.254.0 2011.02.02 W32/Injector.fam!tr

GData 21 2011.02.02 Win32:Malware-gen

Ikarus T3.1.1.97.0 2011.02.02 -

Jiangmin 13.0.900 2011.02.02 -

K7AntiVirus 9.81.3725 2011.02.02 -

Kaspersky 7.0.0.125 2011.02.02 -

McAfee 5.400.0.1158 2011.02.02 -

McAfee-GW-Edition 2010.1C 2011.02.02 -

Microsoft 1.6502 2011.02.02 Backdoor:Win32/IRCbot.gen!M

NOD32 5841 2011.02.02 -

Norman 6.07.03 2011.02.02 -

nProtect 2011-01-27.01 2011.02.02 -

Panda 10.0.3.5 2011.02.02 -

PCTools 7.0.3.5 2011.02.02 -

Prevx 3.0 2011.02.02 -

Rising 23.43.02.07 2011.02.02 -

Sophos 4.61.0 2011.02.02 -

SUPERAntiSpyware 4.40.0.1006 2011.02.02 -

Symantec 20101.3.0.103 2011.02.02 -

TheHacker 6.7.0.1.123 2011.02.02 -

TrendMicro 9.200.0.1012 2011.02.02 -

TrendMicro-HouseCall 9.200.0.1012 2011.02.02 -

VBA32 3.12.14.3 2011.02.02 -

VIPRE 8284 2011.02.02 -

ViRobot 2011.2.2.4288 2011.02.02 -

VirusBuster 13.6.178.0 2011.02.02 -

Additional information

Show all

MD5 : 6dd1cbc6a63907d54e452757c502cd2c

SHA1 : a8940af2d66483b0bcf81f3f09a3af46043d61f6

SHA256: 1b14534cfb0f63d0bf8e4910632e3de3c4331fcd7bee4fac5980865756e55454

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...