Saturday, September 01, 2007

Peed Goes Static

For the last few days, the Peed servers have stopped rotating their malware. They are sticking with the static MD5 sum of c05893a656b54164fb486028309bd89e.

Most of the major Antivirus vendors are aware of the file:
File setup.exe received on 09.01.2007 17:54:57 (CET)
AntivirusVersionLast UpdateResult
AhnLab-V32007.9.1.02007.09.01Win32/Zhelatin.worm.138240.B
AntiVir7.4.1.662007.08.31Worm/Zhelatin.HJ
Authentium4.93.82007.09.01W32/Tibs.XB
Avast4.7.1029.02007.09.01Win32:Tibs-BCY
AVG7.5.0.4842007.08.31Generic6.WTZ
BitDefender7.22007.09.01Trojan.Peed.PB
CAT-QuickHeal9.002007.09.01-
ClamAV0.91.22007.09.01-
DrWeb4.332007.09.01BackDoor.Groan
eSafe7.0.15.02007.08.29-
eTrust-Vet31.1.51002007.08.31Win32/Pecoan
Ewido4.02007.09.01-
FileAdvisor12007.09.01-
Fortinet3.11.0.02007.09.01W32/Tibs@mm
F-Prot4.3.2.482007.08.31W32/Tibs.XB
F-Secure6.70.13030.02007.08.31Email-Worm.Win32.Zhelatin.hj
IkarusT3.1.1.122007.09.01Backdoor.Win32.Agent.amd
Kaspersky4.0.2.242007.09.01Email-Worm.Win32.Zhelatin.hj
McAfee51102007.08.31W32/Nuwar@MM
Microsoft1.28032007.09.01-
NOD32v224952007.09.01-
Norman5.80.022007.08.31W32/Tibs.dam
Panda9.0.0.42007.09.01Trj/Alanchum.MV
Prevx1V22007.09.01-
Rising19.38.52.002007.09.01Worm.Mail.Win32.Zhelatin.dau
Sophos4.21.02007.09.01W32/Bagz-I
Sunbelt2.2.907.02007.08.31Trojan-Downloader.Win32.Tibs.jy
Symantec102007.09.01Trojan Horse
TheHacker6.1.9.1752007.08.31W32/Zhelatin.hj
VBA323.12.2.32007.09.01Email-Worm.Win32.Zhelatin.hj
VirusBuster4.3.26:92007.09.01I-Worm.Zhelatin.AA
Webwasher-Gateway6.0.12007.08.31Worm.Zhelatin.HJ

Additional information
File size: 138240 bytes
MD5: c05893a656b54164fb486028309bd89e
SHA1: 8ad506547710d61a6ac0613fdb1d290911f8e600
(Virustotal Results, http://www.virustotal.com)
As you can see, a select few still miss it, so please be careful clicking on those links in email or blog posts!


UPDATE: A closer look at our binaries over the last few days shows that we're still getting random binaries, but only a couple hundred a day, instead of several thousand. By far the most common binary appears to be c05893a656b54164fb486028309bd89e.

Labels: , , , ,

0 Comments:

Post a Comment

<< Home