Do you have a question? Post it now! No Registration Necessary. Now with pictures!
- Virus Guy
May 14, 2014, 12:27 pm
rate this thread
detection rate was 2/52 at that time.
4/53 (really just 3/53 because TrendMicro = TrendMicro-Housecall)
So no real identity given to this.
Sample can be downloaded from here:
I had to set a password for FT to accept it. PW = a
up-shift.net DNS_TYPE_A 22.214.171.124 YES udp
Request: GET /Backup/test/1405UKmw.enc
Response: 200 "OK"
1405UKmw.enc can be downloaded from here:
Again, pw = a.
For some reason, unlike previous examples, Filepost is not accepting
these files unless I encrypt them. Not even the .enc payload. VT had
not seen the payload before my submission:
0/53 detection rate
Avira still missing from VT scanning.
Received: from cpe-107-185-90-201.socal.res.rr.com ([126.96.36.199])
Date: Wed, 14 May 2014 03:51:37 -0800
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1)
Subject: New Voicemail
New Voicemail Message
You have been left a 1:06 long message (number 1) in mailbox from
"Florigene" 07509nnnnnn, on Wednesday, 14 May, 2014 at 06:29:02 AM
The voicemail message has been attached to this email - which you can
play on most computers.
Please do not reply to this message. This is an automated message which
comes from an unattended mailbox.
This information contained within this e-mail is confidential to, and is
for the exclusive use of the addressee(s). If you are not the addressee,
then any distribution, copying or use of this e-mail is prohibited. If
received in error, please advise the sender and delete/destroy it
immediately. We accept no liability for any loss or damage suffered by
any person arising from use of this e-mail.