CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[MIRT#5565] Trojan on Yahoo

 
Post new topic   Reply to topic       All -> FavForums -> MIRT Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Robin

Site Admin
Phishing Squad Team Lead

Joined: Oct 15, 2003
Posts: 8946

1st Responder Mentors a-squared Anti-Malware Administrators Forums Admin MIRT Moderators MVP Phishing Squad Security Experts Team CC Committee Team F@H

PostPosted: Tue Oct 30, 2007 7:08 pm    Post subject: [MIRT#5565] Trojan on Yahoo
Reply with quote

Malware Alert
 
 Full Report: CastleCops Link/Trojan_malware5565.html
 
 Changed status to confirmed malware.


IP Converted: 216.39.58.194

dword = 3626449602
hex1 = 0xd8273ac2
hex2 = 0xd8.0x27.0x3a.0xc2
oct = 0330.047.072.0302

Antivirus Version Last Update Result
AhnLab-V3 2007.10.31.0 2007.10.30 Win-Trojan/Xema.variant
AntiVir 7.6.0.30 2007.10.30 TR/Crypt.XPACK.Gen
Authentium 4.93.8 2007.10.30 W32/Downloader.AGZG
Avast 4.7.1074.0 2007.10.30 Win32:Small-DSK
AVG 7.5.0.503 2007.10.30 Downloader.Generic3.HWT
BitDefender 7.2 2007.10.30 Trojan.Spy.Agent.OO
CAT-QuickHeal 9.00 2007.10.30 TrojanDownloader.Delf.aww
ClamAV 0.91.2 2007.10.30 -
DrWeb 4.44.0.09170 2007.10.30 Trojan.Dav
eSafe 7.0.15.0 2007.10.28 suspicious Trojan/Worm
eTrust-Vet 31.2.5253 2007.10.30 Win32/Kollah!generic
Ewido 4.0 2007.10.30 Downloader.Delf.aww
FileAdvisor 1 2007.10.30 -
Fortinet 3.11.0.0 2007.10.19 -
F-Prot 4.3.2.48 2007.10.30 W32/Downloader.AGZG
F-Secure 6.70.13030.0 2007.10.30 Trojan-Downloader.Win32.Delf.aww
Ikarus T3.1.1.12 2007.10.30 Trojan-Downloader.Win32.Delf.aww
Kaspersky 7.0.0.125 2007.10.30 Trojan-Downloader.Win32.Delf.aww
McAfee 5151 2007.10.29 Spy-Agent.bw
Microsoft 1.2908 2007.10.30 Backdoor:Win32/Kollah.A
NOD32v2 2627 2007.10.30 a variant of Win32/Spy.Agent.PZ
Norman 5.80.02 2007.10.30 W32/Delf.SNN
Panda 9.0.0.4 2007.10.30 -
Prevx1 V2 2007.10.30 TROJAN.AGENT.GEN
Rising 19.47.12.00 2007.10.30 Trojan.DL.Delf.doi
Sophos 4.23.0 2007.10.30 Mal/Behav-010
Sunbelt 2.2.907.0 2007.10.29 -
Symantec 10 2007.10.30 Downloader.Trojan
TheHacker 6.2.9.110 2007.10.27 -
VBA32 3.12.2.4 2007.10.28 -
VirusBuster 4.3.26:9 2007.10.30 -
Webwasher-Gateway 6.0.1 2007.10.30 Trojan.Crypt.XPACK.Gen
Additional information
File size: 28672 bytes
MD5: 8f2e19d808028b80fb45620264f8aff6
SHA1: 59499cdbf59eb2170ca0c3cc0b7409651ad4c3e9
packers: UPX
packers: PE_Patch.UPX, UPX
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5=A6BEF79E003ABA6F7018009296F20900BDA887F2

View CIDR AS14779 Report: http://www.cidr-report.org/cgi-bin/as-report?as=14779

"14779 | US | arin | 2000-02-07 | INKTOMI-LAWSON - Inktomi Corporation"<br />

Extended information for AS14779:
State/Province: ca
Country: us
Responsible Domain: inktomi.com
Abuse Email: *disable*@yahoo-inc.com

;international-finance.info. IN A
international-finance.info. 600 IN A 216.39.58.194
international-finance.info. 600 IN A 216.39.58.195
international-finance.info. 600 IN A 216.39.58.196
international-finance.info. 600 IN A 216.39.58.237
international-finance.info. 600 IN A 216.39.58.192
international-finance.info. 600 IN A 216.39.58.193
international-finance.info. 86400 IN NS yns1.yahoo.com.
international-finance.info. 86400 IN NS ns8.san.yahoo.com.
international-finance.info. 86400 IN NS yns2.yahoo.com.
international-finance.info. 86400 IN NS ns9.san.yahoo.com.

ATTN MIT:

Domain ID:D19790256-LRMS
Domain Name:INTERNATIONAL-FINANCE.INFO
Created On:04-Sep-2007 23:15:31 UTC
Last Updated On:04-Sep-2007 23:15:34 UTC
Expiration Date:04-Sep-2008 23:15:31 UTC
Sponsoring Registrar:MIT (R141-LRMS)
Status:CLIENT TRANSFER PROHIBITED
Status:TRANSFER PROHIBITED
Registrant ID:A118891922623964

This domain has been registered with you for Mule recruitment as well as malware hosting. Please take immediate action against it and any other domain registered for this account.
Quote:
http://international-finance.info/jobseeker_tool.exe

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> MIRT Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer