VBS/Downloader.ac not detected (Solved)

Hello

E-mail trying to trick me
Dear (a) Customer, As your request annexed following the report of income.
Regards.

then file in ZIP, avast again not detected

6 /54 antivirus detected

Rendimentos182734910.vbe

results of the analysis

https://www.virustotal.com/en/file/a7d8ceea4eecc35d484ce93e429ea69374d7b800f8ae6f79ded223d93d07aafa/analysis/1444353946/

https://www.hybrid-analysis.com/sample/a7d8ceea4eecc35d484ce93e429ea69374d7b800f8ae6f79ded223d93d07aafa?environmentId=1

Hi i am submitted the file to avast! :slight_smile:

I wonder how Eset is quickly block this threat.

It is the heuristic detection.

So why avast! every time fail to block it.Avast! has heuristic detection and HIPS.

Hello,

detection was added. We are working on update of our heuristic detections right now,

thanks for sample.

You are wellcome.Detection is Other Malware-gen[Trj] :slight_smile:

Why Avast! missed such “a variant of MSIL/Injector.MEN” results of the analysis https://www.virustotal.com/en/file/0614c8e7579b5876aa479295acfba8d0d179fe8655772fd2490cac874c0eea7c/analysis/1444374752/
https://www.hybrid-analysis.com/sample/0614c8e7579b5876aa479295acfba8d0d179fe8655772fd2490cac874c0eea7c?environmentId=4
I am submitted the sample via VirusChest :slight_smile:

thanks for the answer
really is Other:Malware-gen [Trj]
It should soon be set the new name to the VBE

Now 21 antivirus is detecting the sample

https://www.virustotal.com/en/file/a7d8ceea4eecc35d484ce93e429ea69374d7b800f8ae6f79ded223d93d07aafa/analysis/1444418869

Hi,

detection name Other:Malware-gen [Trj] is ok. This is usually used for some automatical detection based on our filters etc which are released with every stream update. This detection is a regular detection so there shouldn’t be any problem with it.

this file is different this is another detection.When trojans bankers are defined with a detection based on signatures created, but then name is changed.
Detection is permanent, this case will not suffer change
Thank you for the Clarification. :slight_smile:

Detection was added on 11/10/15
already detects MSIL: Stealer-AY [Trj].

Thanks for the info :slight_smile:

You are welcome.