Im not have the file to upload online have the link for virustotal. Upload the link of virustotal ?
Thanks for answer the question. (sorry my english is bad)
We’ve done this before David. There are many ways of ensuring that User’s are not put at risk; something I neglected to mention in my hastily written reply. (Such as password protecting the archive).
However, you must recognize that a text file (which, is exactly what this is) poses no risk to users, unless they’re stupid enough to open it, and try to find links to open.
Magic ASCII text
That's taken form the VT Report, where magic refers to "Magic Byte". You would need the actual executable from Emotet to make use of that file. (Emotet is commonly spread through DOCX files, using a vulnerability/exploit in how Word handles Macro's. The macro runs powershell, which decides a base64 encoded command and executes it. That command could reach out to a C2 server and download additional malware, or it may drop one itself.)
They do not answer my question, can you send MD5 or sha256 hash files to avast yes or no? How do I report a threat not detected by Avast having only the Virustotal link?
Thank you
This is not the actual malware file but just a dat file (text file with info) made by the malicious program
And that is probably why so many vendors chose not to add detection for it. The malicious program that made the file is most likely detected
All files uploaded to virustotal is shared among all members so avast lab already have the file
Hi, Avast! will receive a copy of the file from VirusTotal automatically.
Avast! will have already received this file - no further threat reporting is required at this point. The file that is being detected poses no risk to your system. It’s the program that made said file that poses a risk.
No solution 100% detection rate - assuming you don’t detect every file (harmful or not). It’s also a matter of whether or not it’s worth their time. No use in detecting malware from 30 years ago - it wouldn’t run in modern environments.