Can you tell me why this file is not a false alarm ?

Hi :slight_smile:

Can you tell me why this file is not a false alarm ?

Site where threat was found:wxw.sulikavan.us/sp3/tmp/collab.pdf

Virustotal:http://www.virustotal.com/analisis/0aac13058e6541f85e8c5d65d71b3a2952acb4fe7c7b1fd54234f21cf32abc10-1265242256

Have a nice day. :slight_smile:

Can you tell me why this file IS a false alarm?

We always assumed that when people talk about false alarms, that they surely know everything and anything about the origin of the file.

Do you really know what is this file origin, why it should be believed etc?

Malicious software includes 6 trojan(s).

This site was hosted on 2 network(s) including AS28753 (NETDIRECT), AS15772 (WNET).

General Information
Location of website Ukrain

Report of threats: 1

 Drive-bydownload

Threat found: 1
Hiere the full list:
Name of threat: MSIE ADODB.Stream Object File Installation Weakness
Location: hxtp://sulikavan.us/sp3/index.php?n=uk_lapp

Not a false positive,

polonus

Hello JuninhoSlo,

I have answered you yesterday about 5 pdf files you had submitted as false positives - none of them is false positive - including this one. A was asking you “why are you thinking these files should be clean?”. Can you please tell us why those pdfs are clean in your point of view?

BTW: sulikavan.us will be blocked as malware domain.

Regards

The infected site (hxxp://sulikavan.us) seems to be down. Hopefully it stays that way.