Hi,
Thank you for your submission, we’ll check it.
Kind Regards,
Erik M.
Hi,
Thank you for your submission, we’ll check it.
Kind Regards,
Erik M.
Hi,
Thank you for your submission, we’ll check it.
Kind Regards,
Umamaheshwari M
Hi Umamaheshwari,
Hi,
Thank you for your submission, we’ll check it.
Kind Regards,
Umamaheshwari M
Riskware.Unsafe.Tweakbit.PcRepairKit
https://valkyrie.comodo.com/get_info?sha1=6f7d35310e801dc9548d27283409c3b87224bd07
Some suspicious/malicious Indicators : Compiler/Packer Signature: Compiler: Borland Object Pascal, Packer: Inno Setup Module 5 SFX - [v.(5.5.7) [ 5.5.9 Unicode ] ] - Delphi 2009, File has multiple binary anomalies (File ignores DEP, The location of the entry-point is suspicious > section: .itext:“0x000117DC”, Contains zero size sections, Contains several executable sections, Contains a virtualized section section: “.tls,2”), Found mutliple Anti-VM Strings (Tries to suspend Cuckoo threads, Checks the version of Bios, Checks the CPU name from registry, Queries the disk size, Checks adapter addresses), Escalade priviledges, Reads Windows Product ID, Reads Windows owner settings, Reads the cookies of Mozilla Firefox, Runs a Keylogger, Calls the “sleep-function” many times, Checks if process is being debugged, Possible date expiration check, exits too soon after checking local time, Creates guardes memory sections, Changes read-write memory protection to read-execute, Duplicates the process handle of an other process to obtain access rights to that process, Steals private information from local Internet browsers (Firefox & Chrome), Changes settings of System certificates, Modifies WPAD proxy autoconfiguration file for traffic interception, HTTP traffic contains suspicious features (HTTP traffic contains multiple POST requests with no referer header > suspicious_request: hxxp://www.google-analytics.com/collect), Connects to an IP/Domain that is known to spread harmful content > “104.237.131.139” - “tweakbit.com” > VirusTotal
Hi pio,
We will verify it.
Regards,
Ionel
Hi Ionel,
thanks for notification and classification!
Since I assume that the Human Expert Analysis also includes the simultaneous creation of a signature, I would like to point out that until now none has been created. :a0
Due to the sheer amount of malicious software distributed by Tweakbit, would it be appropriate to rate this manufacturer as untrustworthy via File Certificate Validation?! In this way, Valkyrie could automatically create a negative verdict for unrecognized and future applications of this vendor, and also CAV/CIS could detect files without Signature via File Certificate (Vendor) validation.
As can be seen from the link, the list of malicious files downloaded from “Tweakbit.com” is almost “endless”.
Best Regards,
pio
Some older files with high detection rates on VT, so I will not give any more indicators this time.
Trojan.Glupteba
https://valkyrie.comodo.com/get_info?sha1=b1730ec46d49af0b689fc4ee8015839dc1da9394
Trojan.Banload
https://valkyrie.comodo.com/get_info?sha1=7a78f9822c7fc080a9408ae35b965d942379185a
Trojan.Packed.Autoit
https://valkyrie.comodo.com/get_info?sha1=7ff45804c8f465219c65ab504acaaa8385121057
Trojan.Spy.Fareit
https://valkyrie.comodo.com/get_info?sha1=0cbd0202c9e344ca1da3b38cdea82339ed7d4152
Trojan.Generic
https://valkyrie.comodo.com/get_info?sha1=922bb933837dea4ab40b18065f15abdc62b3f574
Trojan.Spy.HawkEye
https://valkyrie.comodo.com/get_info?sha1=53ffdbadf70d68f0ef039bd66d3ce04f90b99c04
Hi,
Thank you for your submission, we’ll check it.
Kind Regards,
Qiuhui.■■■■
Some more older files with very high recognition rates. Verified with a short counter-analysis.
Trojan.Script.Dropper
https://valkyrie.comodo.com/get_info?sha1=72421b795d22476c509b869f616c174b1e2385ba
Riskware.Application.RemoteAgent.UltraVNC
https://valkyrie.comodo.com/get_info?sha1=f843a88eb7d4caf51d4c3a548707a309662eb049
Trojan.Generic
https://valkyrie.comodo.com/get_info?sha1=04e6b5699d091d127be616d9e9f6bdf5b29decb0
Hi pio,
Thank you for your submission, we’ll check it.
Kind Regards,
Qiuhui.■■■■
Malware confirmed by more than 50 scan engines
but not detected by comodo as well as valkyrie
Hi SivaSuresh,
We will check it.
Regards,
Ionel
Please continue in Submit Malware Here To Be Blacklisted - 2020 (NO LIVE MALWARE!).
This topic will stay open to handle open submissions.