nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Sat Nov 18, 2006 3:30 am Post subject: MD5: f7783dd132bcde2035587cf7cc101cf8 uN5bloL9.com |
|
|
STATUS: FINISHEDComplete scanning result of "uN5bloL9.com", received in VirusTotal at 11.18.2006, 04:22:27 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.39 11.17.2006 no virus found
Authentium 4.93.8 11.17.2006 no virus found
Avast 4.7.892.0 11.15.2006 no virus found
AVG 386 11.17.2006 no virus found
BitDefender 7.2 11.18.2006 Generic.Malware.dld!!.FF85A93C
CAT-QuickHeal 8.00 11.17.2006 no virus found
ClamAV devel-20060426 11.17.2006 no virus found
DrWeb 4.33 11.17.2006 DLOADER.Trojan
eSafe 7.0.14.0 11.16.2006 no virus found
eTrust-InoculateIT 23.73.59 11.18.2006 no virus found
eTrust-Vet 30.3.3197 11.17.2006 no virus found
Ewido 4.0 11.17.2006 no virus found
Fortinet 2.82.0.0 11.17.2006 no virus found
F-Prot 3.16f 11.17.2006 no virus found
F-Prot4 4.2.1.29 11.17.2006 no virus found
Ikarus 0.2.65.0 11.17.2006 no virus found
Kaspersky 4.0.2.24 11.18.2006 no virus found
McAfee 4898 11.17.2006 no virus found
Microsoft 1.1609 11.18.2006 no virus found
NOD32v2 1870 11.17.2006 probably unknown NewHeur_PE virus
Norman 5.80.02 11.17.2006 W32/Downloader
Panda 9.0.0.4 11.17.2006 no virus found
Prevx1 V2 11.18.2006 no virus found
Sophos 4.11.0 11.16.2006 no virus found
TheHacker 6.0.3.120 11.17.2006 no virus found
UNA 1.83 11.17.2006 no virus found
VBA32 3.11.1 11.17.2006 suspected of Win32.Trojan.Downloader (http://...)
VirusBuster 4.3.15:9 11.17.2006 no virus found
Aditional Information
File size: 2048 bytes
MD5: f7783dd132bcde2035587cf7cc101cf8
SHA1: 9ad43309e47f5cd9d8b4e71d078749bff216daff
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* File length: 2048 bytes.
[ Changes to filesystem ]
* Creates directory C:WINDOWSTEMP.
* Creates file C:WINDOWSTEMPs0081.tmp.
* Creates file C:WINDOWSTEMPs0091.tmp.
[ Network services ]
* Downloads file from hxxp://easyglimor.info/traff/sp/s2.php as C:WINDOWSTEMPs0081.tmp.
* Downloads file from hxxp://easyglimor.info/112233.exe as C:WINDOWSTEMPs0091.tmp.
[ Security issues ]
* Starting downloaded file - potential security problem.
|
|