Pondus
February 16, 2017, 3:51pm
1
First submission 2016-12-26 07:54:27 UTC ( 1 month, 3 weeks ago )
https://virustotal.com/en/file/fb65c2425069a2584590acf67878f5591d40e47834694276423d4e6baff9d002/analysis/1487259934/
Must have slipped true the labs auto analyse, no avast / AVG detection … good we have MCShield
This is a downloader…probably downloads ransom.Yet again it proves avast’s cybercapture and deepscreen not monitoring these .js and .vbs extensions is a flaw.
system
February 17, 2017, 3:29am
3
should be repaired anymore antivirus avast again to investigate the problem ransomware
system
February 17, 2017, 3:56am
4
dont worry , behavior protection still activated
HonzaZ
February 17, 2017, 7:55am
5
I will create a gen detection for the file, too
This VBS script probably has download link that is long gone/terminated.
Pondus
February 17, 2017, 2:32pm
7
system
February 17, 2017, 5:09pm
8
hi , i found the problem delete sample in the virus chest . (that sample block by IDP)
suppose delete instantly ,did u fix soon ?
You mean the sample is not detected if deleted from virus chest? Can you attach screenshot and explain what you mean?
system
February 17, 2017, 5:18pm
10
i means a sample blocked by IDP , and u go check in the chest , try delete that sample , it take a few minute delete sample.