Hi Umamaheshwari,
Checked and everything is fine! :-TU
Best Regards!
pio
Hi Umamaheshwari,
Checked and everything is fine! :-TU
Best Regards!
pio
Generic.Malware
Some suspicious/malicious Indicators : Compiler: Microsoft Visual Basic (6.0), File has multiple binary anomalies (File ignores DEP, File ignores Code Integrity, ASLR is disabled, The dos-stub message is missing), Contains API references not part of its Import Address Table, Sample translates to unusual binary language (Chinese), Contains ability to query CPU information, Contains more than one unique useragent, Mimics the system’s user agent string for its own request, Checks for a suspicious privilege (SeDebugPrivilege), Expects Administrative permission, Reads terminal service related keys, Creates RWX memory, Creates guarded memory sections, Loads the visual basic runtime environment, Uses Windows utilities for basic functionality (Shell), Sniffs keystrokes, Stack pivoting was detected when using a critical API, Creates a hidden flie (C:\Users\user\AppData\Roaming\Microsoft\Windows\IETldCache\Low), Attempts to modify proxy settings, Performs HTTP requests not found in PCAP, Communicates with IPs located across a large number of unique countries
Contacted IP’s related to Malware:
93.184.220.29 > VirusTotal
47.97.218.41 > VirusTotal
220.242.139.165 > VirusTotal
205.185.216.42 > VirusTotal
204.79.197.200 > VirusTotal
203.119.206.93 > VirusTotal
195.59.70.226 > VirusTotal
183.131.207.66 > VirusTotal
175.100.207.232 > VirusTotal
150.138.164.227 > VirusTotal
125.88.146.63 > VirusTotal
125.88.146.188 > VirusTotal
120.26.167.216 > VirusTotal
116.207.118.90 > VirusTotal
116.207.118.89 > VirusTotal
104.93.82.81 > VirusTotal
104.24.101.198 > VirusTotal
104.93.82.81 > VirusTotal
Hi pio,
Thank you for your submission.
We’ll check them and if found to be malware detection will be added.
Best regards
Saravanapathi V
PUA.Agent.MailRu
Some suspicious/malicious Indicators : Compiler: Microsoft Visual C++ 8, File has multiple binary anomalies (File ignores DEP, File calls a TLS callback at “0x489CA0” [.text:0x560288], CRC value set in PE header does not match actual value, Unconventionial language used in binary resources > Russian, Imports sensitive Libraries (Process Status Helper, Windows Remote Desktop Session Host Server SDK APIs, Windows HTTP Services, Crypto API32), Contains ability to query CPU information, Contains ability to enumerate processes/modules/threads, Queries kernel debugger information, Queries process information, Reads the active computer name, Reads the cryptographic machine GUID, Reading critical registry keys, Drops executable files, Deleting a recently created file, Creating a process with a hidden window, Accesses System Certificates Settings, Modifies Software Policy Settings, Makes a code branch decision directly after an API that is environment aware, Opens the Kernel Security Device Driver, Creates windows services ((Access type: “CREATE”; Path: “HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS”), HTTP request contains Base64 encoded artifacts, Contactes IP´s / URL´s who are known as malicious (“94.100.180.110” > VirusTotal, “217.69.139.245” > VirusTotal, “217.69.139.110” > VirusTotal)
Hi pio,
Thank you for your submission.
We’ll check them and if found to be malware detection will be added.
Best regards
Umamaheshwari M
Generic.Trojan
Some suspicious/malicious Indicators : Packer: UPX 3.91, File has multiple binary anomalies (File ignores DEP, File ignores Code Integrity, ASLR is disabled, Entrypoint is outside of first section, Checksum mismatches the PE header value, The file contains writable and executable sections, Contains a virtualized section, The time-stamp of the compiler is suspicious, The value of ‘pointer-symbol-table’ is suspicious > value: “0x00479800”), Has no visible windows, Filecode is self-modifying, Command line console output was observed, Detects the presence of Wine emulator, Reads the active computer name, Reads terminal service related keys, Creates guarded memory sections, PEB has been changed to hide loaded modules, Stops Firewall service, Stops Security Center service, Stops Application Layer Gateway service
Hi pio,
Thank you for your submission.
We’ll check them and if found to be malware detection will be added.
Best regards
Saravanapathi V
It is still rated trusted/clean even with a malware signature…
Hi, futuretech
Reported file detection has been fixed.
Please check.
Regards,
Umamaheshwari M
Variant.PUA.Hoax.ReImageRepair
Some suspicious/malicious Indicators : Compiler/Packer signature: Compiler: Microsoft Visual C/C++ 10.0 SP1 - Packer/Crypter: NSIS, Armadillo, File has multiple binary anomalies (File ignores Code Integrity, PE file has unusual entropy sections (“.data” with “7.5741981954”), The file contains another file (type: Nullsoft, location: overlay, offset: 0x00057208), CRC value set in PE header does not match actual value, Contains zero-size sections, The file-ratio of the overlay is suspicious (ratio: 93.18%), The file contains a virtualized section (section: .ndata), The file-ratio of the sections has been determined (ratio: 38.05%), Contains ability to open the clipboard, Contains ability to retrieve keyboard strokes, Contains ability to elevate privileges, Found a reference to a WMI query string known to be used for VM detection (“Win32_ComputerSystem”, “Win32_Processor” ), Queries volume information of an entire harddrive, Found a cryptographic related string (“blowfish”, twofish", “des”, "rc4, “rijndael”), Attempts to repeatedly call a single API many times in order to delay analysis time, Creates a copy of itself, Creates a suspicious process (regsvr32 /s “C:\Windows\system32\jscript.dll”), Queries kernel debugger information, Reads the active computer name, Reads the cryptographic machine GUID, Reads the registry for installed applications, Reads terminal service related keys, Scanning for window names, Executed a command line with /C or /R argument to terminate command shell on completion, Modifies proxy settings, Opens the Kernel Security Device Driver, Queries sensitive IE security settings, Steals private information from local Internet browsers, Creates windows services (Access type: “CREATE”; Path: “HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS”), Uses a User Agent typical for browsers, although no browser was ever launched (NSIS_Inetc (Mozilla)), HTTP request contains Base64 encoded artifacts, Sends traffic on typical HTTP outbound port, but without HTTP header
Hi pio,
Thank you for your submission.
We’ll check them and if found to be malware detection will be added.
Regards,
Umamaheshwari M
Variant.Trojan.Spyware.Banker.TRICKBOT
https://valkyrie.comodo.com/get_info?sha1=e74e2b72d85e12d6e6215f9a4e8ea491a79e765e
Some suspicious/malicious Indicators : Compiler/Packer/Crypter signature: Compiler: Microsoft Visual C++ 7.0, Packer/Crypter: Armadillo v1.71, Armadillo v2.xx (CopyMem II), File has multiple binary anomalies (File ignores Code Integrity, File ignores DEP, ASLR is disabled, Contains another file (type: executable, location: resources, offset: “0x00055EEC”), Imports sensitive Libraries (Windows Socket 2.0 32-Bit DLL), References a string with a suspicious size > “226648” bytes > “0x000730EX”), Found known privilege escalation attack > “DllHost.exe”, Creates guarded memory sections, Reads the active computer name, Reads the cryptographic machine GUID, Reads terminal service related keys, Reads the registry for installed applications, Queries kernel debugger information, Queries volume information of an entire harddrive, Queries sensitive IE security settings, Creates a ADS file, Creates a hidden file, Creates a copy of itself, Writes data to antoher process > “%WINDIR%\System32\sc.exe” & “%WINDIR%\System32\WindowsPowerShell\v1.0\powershell.exe”, Opened the service control manager, Tries to disable/delete the windows firewall using PowerShell, Found strings in conjunction with a procedure lookup that resolve to a known API export symbol, Opens the MountPointManager, Opens the Kernel Security Device Driver, Queries sensitive IE security settings, Modifies proxy settings, Contacting an IP that is known to spread or support harmful content (“192.3.179.203” > VirusTotal)
Hi pio,
Thank you for reporting.
We’ll check it.
Regards,
Kowsalya R
Hi pio,
Thank you for reporting.
We’ll check it.
Regards,
Mageshwaran B
Adware.Riskware.SearchSuite
[b]>>> Advanced File Analysis System | Valkyrie
This file was published one day after the official and latest version was released and was signed with the same certificate. This new version was subsequently created with the “Private Exe Protector V2.30-V2.3” in order to reduce the relatively high detection rates on VT. Furthermore, various anti-debugging and anti-VM techniques were implemented to make execution in a virtual machine more difficult or even impossible. Both projects were successfully implemented! The installer released first is also detected by CAV. >>> VirusTotal
Some suspicious/malicious Indicators : Compiler/Packer/Crypter signature: Compiler: Microsoft Visual C++ v.14 - 2015 ( E8 ), Crypter: Private Exe Protector V2.30-V2.3, File has multiple binary anomalies (File ignores Code Integrity, File calls a TLS callback at “0x45BF60” [.text:0x372576], Imports sensitive libraries (MCI API DLL, Process Status Helper, Windows HTTP Services and delayed > Windows Image Helper, Power Profile Helper DLL), A directory is invalid (type: export-table), The file references an unknown resource (resource: GOOGLEUPDATEAPPLICATIONCOMMANDS), Implements various mechanisms to prevent debugging and execution in a virtual environment (DebuggerCheck__QueryInfo, DebuggerHiding__Thread, DebuggerException__SetConsoleCtrl, Check_OutputDebugStringA_iat, anti_dbg - Checks if being debugged, antisb_threatExpert - Anti-Sandbox checks for ThreatExpert, Found VM detection artifact “CPUID trick” (Offset: 782593), Uses “SwitchToThread” function), Contains ability to create a remote thread, Contains ability to write to a remote process, Contains ability to elevate privileges, Contains ability to create named pipes, Tries to hide a process launching it with different user credentials, Creates guarded memory sections, Changes object ACLs, Has code injection capabilities (CreateRemoteThread, OpenProcess, VirtualAlloc, VirtualAllocEx, WriteProcessMemory), Has code mapping injection capabilities (CreateFileMapping, CreateRemoteThread, MapViewOfFile), Manipulates other processes (OpenProcess, ReadProcessMemory, WriteProcessMemory)
Hi pio,
Verdict has been updated.
Regards,
Ionel
Hi Ionel,
I just saw your answer and thank you for it.
Unfortunately, the file does not yet have a signature recognition. I ask you to add these.
Thanks and Best Regards
pio
Hi futuretech,
Thank you for your notification, we will verify this.
Regards,
Ionel
link of site not function…
for exemple: https://comodo.com.php/|?u=https… :-TU