* submitter: MilkdadAv's that added because of your submission:
* name: AcroIEHelper.dll
* size: 227894
* md5.: 32929bace82a07c26c1d3877176cb2a9
AntiVir 7.6.0.62/20080212 found [TR/Dldr.Delf.eqb.1]
AVG 7.5.0.516/20080211 found [Downloader.Generic6.AICW]
BitDefender 7.2/20080212 found [Trojan.Downloader.Codec.E]
CAT-QuickHeal None/20080211 found [TrojanDownloader.Delf.eqb]
F-Prot 4.4.2.54/20080211 found [W32/Banload.E.gen!Eldorado]
F-Secure 6.70.13260.0/20080212 found [Trojan-Downloader.Win32.Delf.eqb]
Fortinet 3.14.0.0/20080212 found [W32/Delf.EQB!tr.dldr]
Ikarus T3.1.1.20/20080212 found [Trojan-Downloader.Delf.OGX]
Kaspersky 7.0.0.125/20080212 found [Trojan-Downloader.Win32.Delf.eqb]
Microsoft 1.3204/20080211 found [Trojan:Win32/Delflob.I]
Prevx1 V2/20080212 found [Generic.Malware]
Webwasher-Gateway 6.6.2/20080212 found [Trojan.Dldr.Delf.eqb.1]
packers: ASPack
Avira: TR/Dldr.Delf.eqb.1
Tuesday, February 12, 2008
AcroIEHelper.dll - 32929bace82a07c26c1d3877176cb2a9
Monday, February 11, 2008
And so it begins.....
The new wave of storm is flowing just in time for Valentines. At the time of this post I've only recieved 3 emails for it and I imagine a lot more to come.
The first with the subject "Phone Love" and a body that simply contained the following:
I of course went to the page to get the newest version and this was the image I found

Onto the next one I received:
Subject: Valentine Invitation
Body:
<---And yet another pretty pic Now for the third:
The first with the subject "Phone Love" and a body that simply contained the following:
Love Machine http:// 24.131.212.16/
I of course went to the page to get the newest version and this was the image I found

Onto the next one I received:
Subject: Valentine Invitation
Body:
Happy Valentine's Day! http:// 200.75.106.166
<---And yet another pretty pic Now for the third:

Subject: Be My Valentine
Body:
Ahh another pretty pic, reminds me a elementary school.
The ones thing all of the files have in common is no detection at the time of the post!
Be very careful opening any valentines emails that you receive they could be more trouble than you ever wanted.
http:// 24.131.212.16/ - valentine.exe MD5: d1789d5bbc74bcf4def368f9b9db303e
http:// 200.75.106.166/ - valentine.exe MD5: 8ef7be6c05aca940b1e9cf677d471a41
http:// 59.92.53.16/ - valentine.exe MD5: 74ca598169f8fdee49d04e22c8ac7514
While I was writing this I received another one but it seems to be dead already. Here is the info from it.
Subject: You're Super Sweet
Body:
I've stayed away from the technical details here at least for now. Our friends over at asert.arbornetworks.com have posted some details check it out at:
http://asert.arbornetworks.com/2008/02/new-storm-valentines-day-campaign/
Edit:
Here's some more if the images:




More subject lines and bodies:
Safe surfing!
Uploadmalware.com
Body:
Valentine Friends http:// 59.92.53.16/
Ahh another pretty pic, reminds me a elementary school.
The ones thing all of the files have in common is no detection at the time of the post!
Be very careful opening any valentines emails that you receive they could be more trouble than you ever wanted.
http:// 24.131.212.16/ - valentine.exe MD5: d1789d5bbc74bcf4def368f9b9db303e
http:// 200.75.106.166/ - valentine.exe MD5: 8ef7be6c05aca940b1e9cf677d471a41
http:// 59.92.53.16/ - valentine.exe MD5: 74ca598169f8fdee49d04e22c8ac7514
While I was writing this I received another one but it seems to be dead already. Here is the info from it.
Subject: You're Super Sweet
Body:
Love Rose http:// 203.128.211.219/
I've stayed away from the technical details here at least for now. Our friends over at asert.arbornetworks.com have posted some details check it out at:
http://asert.arbornetworks.com/2008/02/new-storm-valentines-day-campaign/
Edit:
Here's some more if the images:




More subject lines and bodies:
Just you: Rockin' Valentine http:// 71.156.93.100/
Rockin' Valentine: My Love http:// 65.34.217.24/
Rockin' Valentine: Powerful Love http:// 58.63.155.16/
My Heart: World Love http:// 76.68.144.52/
Safe surfing!
Uploadmalware.com
The Mega-D botnet that everyone was led to believe was so huge apparently isn't according to a recent blog post at asert.arbornetworks.com
Read the full story at the link below.
http://asert.arbornetworks.com/2008/02/secureworks-ozdokmega-d-trojan-analysis/
SecureWorks: Ozdok/Mega-D Trojan Analysis
by Danny McPhersonEnabled by some spam samples Marshal provided, Joe Stewart and the good folks @SecureWorks, with an assist from Team Cymru and my|NetWatchman, have identified the malware and botnet referred to as Mega-D.
It turns out Mega-D is composed of bots from the little-known Ozdok malware family. Joe provides some analysis on scale and distribution of the botnet here, as well as some detailed bits on behaviors of the Trojan itself.
Based solely on the hostnames provided in the analysis we (Jose, actually) was able to find three samples in our database, with dates all well over a year old:
Read the full story at the link below.
http://asert.arbornetworks.com/2008/02/secureworks-ozdokmega-d-trojan-analysis/
video.exe - 9f36a92add503d6c08a97d5dc0d5eb8c
AV's that added because of your submission:
* name: video.exe
* size: 91831
* md5.: 9f36a92add503d6c08a97d5dc0d5eb8c
AntiVir 7.6.0.62/20080208 found [TR/Dropper.Gen]
eSafe 7.0.15.0/20080128 found [suspicious Trojan/Worm]
Ikarus T3.1.1.20/20080210 found [Trojan-Spy.Win32.Banker.caw]
Panda 9.0.0.4/20080209 found [Suspicious file]
VBA32 3.12.6.0/20080209 found [suspected of Trojan-IM.VB.1 (paranoid heuristics)]
Webwasher-Gateway 6.6.2/20080209 found [Trojan.Dropper.Gen]
packers: UPX_LZMA
Trojan-Downloader.Win32.Banload.hjl
album_leticia.exe - 532c3c5674bb03464d4d990c291d8a14
* name: album_leticia.exe
* size: 14794
* md5.: 532c3c5674bb03464d4d990c291d8a14
ClamAV 0.92/20080210 found [Trojan.Downloader-13210]
Rising 20.29.22.00/20080130 found [Trojan.DL.Win32.Agent.ejs]
Webwasher-Gateway 6.6.2/20080210 found [Virus.Win32.FileInfector.gen!90 (suspicious)]
AV's that added based on your submission:
Avira Lab: TR/Dldr.Agent.iwf
Kaspersky: Trojan-Downloader.Win32.Agent.iwf
elxxfghg.dll- 227f6af6fb4ae8063b5f7348fd9694ee
* name: elxxfghg.dll
* size: 80084 bytes
* md5.: 227f6af6fb4ae8063b5f7348fd9694eeAntiVir 7.6.0.62/20080210 found [TR/Dldr.ConHook.Gen]
Avast 4.7.1098.0/20080210 found [Win32:TratBHO]
AVG 7.5.0.516/20080210 found [Lop]
BitDefender 7.2/20080210 found [Trojan.Vundo.DYM]
DrWeb 4.44.0.09170/20080210 found [Trojan.Virtumod.272]
eTrust-Vet 31.3.5522/20080208 found [Win32/Vundo.MO]
F-Prot 4.4.2.54/20080210 found [W32/Virtumonde.G.gen!Eldorado]
Ikarus T3.1.1.20/20080210 found [not-a-virus:AdWare.Win32.Virtumonde]
Kaspersky 7.0.0.125/20080210 found [not-a-virus:AdWare.Win32.Virtumonde.gen]
Microsoft 1.3204/20080210 found [Trojan:Win32/Vundo.gen!A]
Norman 5.80.02/20080208 found [W32/Virtumonde.KYQ]
Panda 9.0.0.4/20080210 found [Suspicious file]
Sophos 4.26.0/20080210 found [Troj/Virtum-Gen]
Symantec 10/20080210 found [Trojan.Adclicker]
TheHacker 6.2.9.215/20080209 found [Adware/Virtumonde.gen]
VirusBuster 4.3.26:9/20080210 found [Adware.Vundo.V.Gen]
Webwasher-Gateway 6.6.2/20080210 found [Trojan.Dldr.ConHook.Gen]
sbsm.exe - ead7b53b7a67d39dfe74ff6fe981d389
* size: 2759 bytes
* md5.: ead7b53b7a67d39dfe74ff6fe981d389
AVG 7.5.0.516/20080211 found [Downloader.Zlob]
F-Secure 6.70.13260.0/20080211 found [Trojan-Downloader.Win32.Zlob.hku]
Kaspersky 7.0.0.125/20080211 found [Trojan-Downloader.Win32.Zlob.hku]
NOD32v2 2865/20080211 found [Win32/TrojanDownloader.Zlob.BPH]
Prevx1 V2/20080211 found [Downloader.Zlob]
Symantec 10/20080211 found [Trojan.Startpage]
VirusBuster 4.3.26:9/20080211 found [Trojan.DL.Zlob.Gen.34]
Edit 1: Added by Ikarus as Virus.Win32.Zlob.AJV
Edit 2: Added by Avira as TR/Dldr.Zlob.hku
Edit 3: Added by DrWeb as Virus: Trojan.Popuper
Subscribe to:
Posts (Atom)
