tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
Posted: Sat Jan 19, 2008 7:29 am Post subject: [MIRT#7276] Trojan-Dropper on 59.53.88.188 AS4134 |
|
|
Malware Alert Full Report: /Trojan_Dropper_malware7276.html Changed status to confirmed malware.setup.exe at this location is malware known as Trojan-Dropper.Win32.Delf.anc (Kaspersky)
Scanning report:
Antivirus;Version;Last Update;Result
AhnLab-V3;2008.1.19.10;2008.01.18;Dropper/Xema.99413
AntiVir;7.6.0.48;2008.01.18;DR/Delphi.Gen
Avast;4.7.1098.0;2008.01.18;Win32:Inject-FD
CAT-QuickHeal;9.00;2008.01.19;TrojanDropper.Delf.ami
ClamAV;0.91.2;2008.01.18;Trojan.QQPass-66
DrWeb;4.44.0.09170;2008.01.18;BackDoor.Citadel
F-Prot;4.4.2.54;2008.01.19;W32/Trojan2.SXC
F-Secure;6.70.13260.0;2008.01.18;Trojan-Dropper.Win32.Delf.anc
Ikarus;T3.1.1.20;2008.01.19;Backdoor.Win32.GrayBird.lc
Kaspersky;7.0.0.125;2008.01.19;Trojan-Dropper.Win32.Delf.anc
Microsoft;1.3109;2008.01.18;TrojanDropper:Win32/Temcry
Norman;5.80.02;2008.01.18;W32/Suspicious_N.gen.dropper
Panda;9.0.0.4;2008.01.18;Suspicious file
Sophos;4.24.0;2008.01.19;Mal/Generic-A
TheHacker;6.2.9.191;2008.01.18;Trojan/Dropper.Delf.ami
VBA32;3.12.2.5;2008.01.15;Trojan.Win32.Inject.oi
Webwasher-Gateway;6.6.2;2008.01.18;Trojan.Dropper.Delphi.Gen
Additional information
File size: 99413 bytes
MD5: 0cfe1dabe62d76ba938848e84839037f
SHA1: d4ce0c439a39065ba18216be62c1744ab638967e
PEiD: BobSoft Mini Delphi -> BoB / BobSoft
packers: embeddedIP Converted: 59.53.88.188
dword = 993351868
hex1 = 0x3b3558bc
hex2 = 0x3b.0x35.0x58.0xbc
oct = 073.065.0130.0274
View CIDR AS4134 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4134
"4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street"<br />
Extended information for AS4134:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
Generated and sent email malware alert to respective parties. | Quote: | | http://www.yinra.com/inf/setup.exe |
|
|