Another malware missed (2)...

Another malware missed… (2) It’s not the same.

[ file data ]

  • md5.: 7aa6057045528d5efb8c79a2d6e93f07
  • sha1: 29e48de4c2e50e292f35df1000a7d192051581d2

[ scan result ]
AhnLab-V3 2007.9.29.0/20070928 found nothing
AntiVir 7.6.0.18/20070928 found nothing
Authentium 4.93.8/20070929 found [Possibly a new variant of W32/NewUnknownMalware-OC05!Maximus]
Avast 4.7.1043.0/20070929 found nothing
AVG 7.5.0.488/20070930 found nothing
BitDefender 7.2/20070930 found [Packer.PESpin.A]
CAT-QuickHeal 9.00/20070929 found [(Suspicious) - DNAScan]
ClamAV 0.91.2/20070930 found [PUA.Packed.PESpin]
DrWeb 4.33/20070930 found nothing
eSafe 7.0.15.0/20070929 found [Suspicious Trojan/Worm]
eTrust-Vet 31.2.5174/20070930 found nothing
Ewido 4.0/20070930 found nothing
F-Prot 4.3.2.48/20070929 found [W32/NewUnknownMalware-OC05!Maximus]
F-Secure 6.70.13030.0/20070929 found nothing
FileAdvisor 1/20070930 found nothing
Fortinet 3.11.0.0/20070930 found [PossibleThreat]
Ikarus T3.1.1.12/20070930 found [Win32.SuspectCrc]
Kaspersky 7.0.0.125/20070930 found nothing
McAfee 5130/20070928 found nothing
Microsoft 1.2803/20070930 found nothing
NOD32v2 2560/20070930 found nothing
Norman 5.80.02/20070928 found nothing
Panda 9.0.0.4/20070930 found [Suspicious file]
Prevx1 V2/20070930 found nothing
Rising 19.42.61.00/20070930 found nothing
Sophos 4.22.0/20070930 found [Mal/Packer]
Sunbelt 2.2.907.0/20070928 found [VIPRE.Suspicious]
Symantec 10/20070930 found nothing
TheHacker 6.2.6.073/20070928 found [W32/Behav-Heuristic-070]
VBA32 3.12.2.4/20070930 found nothing
VirusBuster 4.3.26:9/20070929 found [Packed/PeSpin]
Webwasher-Gateway 6.0.1/20070928 found [Packer.PESpin]

[ notes ]
packers: PESPIN
packers: PESpin
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

This is more complicated. Few antivirus detects this…
Send by Chest.

i don’t know how to interpret these heuristic detections… some AV’s decided to catch packers at all… that’s not our way, but we’ll analyze the file, if you’ve sent it…

I’ve done just after posting. It’s written on the bottom of the first post.

ook… i see it now :slight_smile:

It was asked a long time ago a ‘flag’ that warns the user if a file into Chest has already been sent for analysis. Right now, looking the Chest, I can’t be sure: have I sent or not? ???