USB worm

First submission 2016-12-26 07:54:27 UTC ( 1 month, 3 weeks ago )
https://virustotal.com/en/file/fb65c2425069a2584590acf67878f5591d40e47834694276423d4e6baff9d002/analysis/1487259934/

Must have slipped true the labs auto analyse, no avast / AVG detection … good we have MCShield :wink:

This is a downloader…probably downloads ransom.Yet again it proves avast’s cybercapture and deepscreen not monitoring these .js and .vbs extensions is a flaw.

should be repaired anymore antivirus avast again to investigate the problem ransomware :wink:

dont worry , behavior protection still activated :wink:

I will create a gen detection for the file, too :wink:

This VBS script probably has download link that is long gone/terminated.

In this case yes >> http://www.downforeveryoneorjustme.com/http://vlc.servehttp.com/

https://virustotal.com/en/url/babadaa16c0bf4ca60761ee23fcd3f386a9caf2cfa156b0cd95eb7a3bdb161e4/analysis/1487341795/

hi , i found the problem delete sample in the virus chest . (that sample block by IDP)
suppose delete instantly ,did u fix soon ?

You mean the sample is not detected if deleted from virus chest? Can you attach screenshot and explain what you mean?

i means a sample blocked by IDP , and u go check in the chest , try delete that sample , it take a few minute delete sample.