Author: AlphaCentauri, Posted: Sat May 17, 2008 3:23 am Post subject: Storm worm 5/16/08
This is a copy of storm worm I just downloaded. There are two files on their sites, load.php, which is a short file that is well detected and was first submitted to VirusTotal on May 6, and this one, load2.php, which is longer and more poorly detected. (Both downloads are actually called devnull.exe when you actually download them.)
Jotti:
Scan taken on 17 May 2008 02:57:10 (GMT)
A-Squared
Found nothing
AntiVir
Found TR/Dropper.Gen
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found I-Worm/Nuwar.R
BitDefender
Found Trojan.Peed.PJ
ClamAV
Found nothing
CPsecure
Found W32.Email.W.Zhelatin.yu
Dr.Web
Found Trojan.Packed.460
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Email-Worm.Win32.Zhelatin.yu
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found Email-Worm.Win32.Zhelatin.yu
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
Author: AlphaCentauri, Posted: Sat May 17, 2008 3:25 am Post subject:
Actually, here is the load.php file just in case both are necessary for testing.
Author: tetak, Posted: Sat May 17, 2008 3:14 pm Post subject:
I've added devnull.exe (the 145KB one) to the malware listserv.
Author: AlphaCentauri, Posted: Mon May 19, 2008 9:46 pm Post subject:
There's a round of spam going out. Payload=iloveyou.exe
Jotti:
Scan taken on 19 May 2008 21:19:04 (GMT)
A-Squared
Found nothing
AntiVir
Found TR/Dropper.Gen
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found I-Worm/Nuwar.R
BitDefender
Found Trojan.Peed.PJ
ClamAV
Found nothing
CPsecure
Found W32.Email.W.Zhelatin.yu
Dr.Web
Found Trojan.Packed.460
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Email-Worm.Win32.Zhelatin.yu
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found Email-Worm.Win32.Zhelatin.yu
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
spam=
Quote:
Subject: Missing you with every breath
The Mood for Love http://200.8.72.64/
No proxy or User Agent Switcher necessary to download this one.
Author: AlphaCentauri, Posted: Mon May 19, 2008 10:30 pm Post subject:
This is one tembow found on the same sites, sony.exe.
The detection looks the same, but VirusTotal treated as a distinct malware sample: