lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <020501c47e49$1aa59c70$8c00a8c0@hsportatil>
From: bernardo at hispasec.com (Bernardo Quintero)
Subject: (no subject)

> (In regards to new_price.zip file attachment)
> 
> Anyone have any idea what this is, we had some clients just get pretty
> hard with this email.  I am unable to find anything on it, from my VERY
> Limited knowledge it appears to be a virus exploiting one of the many
> holes in IE.  Anyone else see anything on this yet?

http://www.incidents.org/diary.php?date=2004-08-09

Scan results (http://www.virustotal.com)
 File: price.zip
 Date: 08/09/2004 21:41:30
----
BitDefender 7.0/20040809 found [JS.Dword.dropper]
ClamWin devel-20040727/20040809 found [Trojan.JS.RunMe]
eTrustAV-Inoc 4641/20040728 found [JScript/IE.VM.Exploit]
F-Prot 3.15/20040809 found [HTML/ObjData@exp]
Kaspersky 4.0.2.23/20040809 found nothing
McAfee 4383/20040804 found [JS/IllWill]
NOD32v2 1.836/20040809 found [Win32/Bagle.AI]
Norman 5.70.10/20040806 found [W32/Malware]
Panda 7.02.00/20040809 found [Fichero Sospechoso]
Sybari 7.5.1314/20040809 found [JS/IllWill]
Symantec 8.0/20040809 found nothing
TrendMicro 7.000/20040809 found [HTML_BAGLE.AC]


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ