Robin
Site Admin Phishing Squad Team Lead
 Joined: Oct 15, 2003 Posts: 8946
|
Posted: Tue Oct 30, 2007 7:08 pm Post subject: [MIRT#5565] Trojan on Yahoo |
|
|
Malware Alert Full Report: /Trojan_malware5565.html Changed status to confirmed malware. IP Converted: 216.39.58.194
dword = 3626449602
hex1 = 0xd8273ac2
hex2 = 0xd8.0x27.0x3a.0xc2
oct = 0330.047.072.0302
Antivirus Version Last Update Result
AhnLab-V3 2007.10.31.0 2007.10.30 Win-Trojan/Xema.variant
AntiVir 7.6.0.30 2007.10.30 TR/Crypt.XPACK.Gen
Authentium 4.93.8 2007.10.30 W32/Downloader.AGZG
Avast 4.7.1074.0 2007.10.30 Win32:Small-DSK
AVG 7.5.0.503 2007.10.30 Downloader.Generic3.HWT
BitDefender 7.2 2007.10.30 Trojan.Spy.Agent.OO
CAT-QuickHeal 9.00 2007.10.30 TrojanDownloader.Delf.aww
ClamAV 0.91.2 2007.10.30 -
DrWeb 4.44.0.09170 2007.10.30 Trojan.Dav
eSafe 7.0.15.0 2007.10.28 suspicious Trojan/Worm
eTrust-Vet 31.2.5253 2007.10.30 Win32/Kollah!generic
Ewido 4.0 2007.10.30 Downloader.Delf.aww
FileAdvisor 1 2007.10.30 -
Fortinet 3.11.0.0 2007.10.19 -
F-Prot 4.3.2.48 2007.10.30 W32/Downloader.AGZG
F-Secure 6.70.13030.0 2007.10.30 Trojan-Downloader.Win32.Delf.aww
Ikarus T3.1.1.12 2007.10.30 Trojan-Downloader.Win32.Delf.aww
Kaspersky 7.0.0.125 2007.10.30 Trojan-Downloader.Win32.Delf.aww
McAfee 5151 2007.10.29 Spy-Agent.bw
Microsoft 1.2908 2007.10.30 Backdoor:Win32/Kollah.A
NOD32v2 2627 2007.10.30 a variant of Win32/Spy.Agent.PZ
Norman 5.80.02 2007.10.30 W32/Delf.SNN
Panda 9.0.0.4 2007.10.30 -
Prevx1 V2 2007.10.30 TROJAN.AGENT.GEN
Rising 19.47.12.00 2007.10.30 Trojan.DL.Delf.doi
Sophos 4.23.0 2007.10.30 Mal/Behav-010
Sunbelt 2.2.907.0 2007.10.29 -
Symantec 10 2007.10.30 Downloader.Trojan
TheHacker 6.2.9.110 2007.10.27 -
VBA32 3.12.2.4 2007.10.28 -
VirusBuster 4.3.26:9 2007.10.30 -
Webwasher-Gateway 6.0.1 2007.10.30 Trojan.Crypt.XPACK.Gen
Additional information
File size: 28672 bytes
MD5: 8f2e19d808028b80fb45620264f8aff6
SHA1: 59499cdbf59eb2170ca0c3cc0b7409651ad4c3e9
packers: UPX
packers: PE_Patch.UPX, UPX
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5=A6BEF79E003ABA6F7018009296F20900BDA887F2
View CIDR AS14779 Report: http://www.cidr-report.org/cgi-bin/as-report?as=14779
"14779 | US | arin | 2000-02-07 | INKTOMI-LAWSON - Inktomi Corporation"<br />
Extended information for AS14779:
State/Province: ca
Country: us
Responsible Domain: inktomi.com
Abuse Email: *disable*@yahoo-inc.com
;international-finance.info. IN A
international-finance.info. 600 IN A 216.39.58.194
international-finance.info. 600 IN A 216.39.58.195
international-finance.info. 600 IN A 216.39.58.196
international-finance.info. 600 IN A 216.39.58.237
international-finance.info. 600 IN A 216.39.58.192
international-finance.info. 600 IN A 216.39.58.193
international-finance.info. 86400 IN NS yns1.yahoo.com.
international-finance.info. 86400 IN NS ns8.san.yahoo.com.
international-finance.info. 86400 IN NS yns2.yahoo.com.
international-finance.info. 86400 IN NS ns9.san.yahoo.com.
ATTN MIT:
Domain ID:D19790256-LRMS
Domain Name:INTERNATIONAL-FINANCE.INFO
Created On:04-Sep-2007 23:15:31 UTC
Last Updated On:04-Sep-2007 23:15:34 UTC
Expiration Date:04-Sep-2008 23:15:31 UTC
Sponsoring Registrar:MIT (R141-LRMS)
Status:CLIENT TRANSFER PROHIBITED
Status:TRANSFER PROHIBITED
Registrant ID:A118891922623964
This domain has been registered with you for Mule recruitment as well as malware hosting. Please take immediate action against it and any other domain registered for this account.
| Quote: | | http://international-finance.info/jobseeker_tool.exe |
|
|