Receive a suspicious email/Trojan-PSW.Win32.Magania.dsg titled "good stuff"
EndurerOriginal
Supplement Kaspersky's reaction at 2008-02-01
Detected: Trojan programTrojan-PSW.Win32.Magania.dsgFile: D:/test/script. Zip/CMD/data.rar/41.sfx.exe/data.rar/41.exe
2008-01-25 th1Version
I suddenly received an email from a user who had not been in touch for a long time.
Mail title: good stuff
The body of the email is: show you something nice. If you want it, return @@
Attachment: script. Zip-zip compressed file. The package size is 317042 bytes.
Include: script. CMD-Self-extract format RAR compressed file, the size of the package is 275241 bytes
Note:
Setup000041.sfx.exe
Tempmode
Silent = 1
Overwrite = 1
41.sfx.exe-Self-extracting RAR compressed file. The size of the unwrapped file is 117025 bytes.
Note:
Setup000041.exe
Presetup = mm
Silent = 1
Overwrite = 1
The shells used in this file are rare and seem to be a variant of the Beidou shell ~
Online scan results
| Anti-Virus engine |
Version |
Last update |
Scan results |
| AhnLab-V3 |
2008.1.26.10 |
2008.01.25 |
- |
| AntiVir |
7.6.0.53 |
2008.01.25 |
TR/crypt. nspm. gen |
| Authentium |
4.93.8 |
2008.01.26 |
Possibly a new variant of W32/pwstealer3! Generic |
| Avast |
4.7.20.8.0 |
2008.01.25 |
- |
| AVG |
7.5.0.516 |
2008.01.25 |
- |
| BitDefender |
7.2 |
2008.01.26 |
- |
| Cat-quickheal |
9.00 |
2008.01.25 |
Win32.packed. nsanti. r |
| ClamAV |
0.91.2 |
2008.01.26 |
- |
| Drweb |
4.44.0.09170 |
2008.01.25 |
- |
| Esafe |
7.0.15.0 |
2008.01.16 |
Suspicious Trojan/Worm |
| ETrust-vet |
31.3.5486 |
2008.01.26 |
- |
| Ewido |
4.0 |
2008.01.25 |
- |
| Fileadvisor |
1 |
2008.01.26 |
- |
| Fortinet |
3.14.0.0 |
2008.01.26 |
- |
| F-Prot |
4.4.2.54 |
2008.01.25 |
W32/pwstealer3! Generic |
| F-Secure |
6.70.13260.0 |
2008.01.26 |
Suspicious: W32/malware! Gemini |
| Ikarus |
T3.1.1.20 |
2008.01.26 |
- |
| Kaspersky |
7.0.0.125 |
2008.01.26 |
- |
| McAfee |
5216 |
2008.01.26 |
New malware. HW |
| Microsoft |
1.3109 |
2008.01.26 |
Virtool: Win32/obfuscator! Mal |
| Nod32v2 |
2823 |
2008.01.25 |
- |
| Norman |
5.80.02 |
2008.01.24 |
- |
| Panda |
9.0.0.4 |
2008.01.25 |
Suspicious File |
| Prevx1 |
V2 |
2008.01.26 |
Heuristic: Suspicious self modifying exe |
| Rising |
201728.50.00 |
2008.01.26 |
- |
| Sophos |
4.25.0 |
2008.01.26 |
Mal/encpk-ce |
| Sunbelt |
2.2.907.0 |
2008.01.25 |
- |
| Symantec |
10 |
2008.01.26 |
- |
| Thehacker |
6.2.9.198 |
2008.01.25 |
- |
| Vba32 |
3.12.2.5 |
2008.01.21 |
- |
| Virusbuster |
4.3.26: 9 |
2008.01.25 |
Trojan. lineage. Gen! Pac.3 |
| Webcycler-Gateway |
6.6.2 |
2008.01.25 |
Trojan. crypt. nspm. gen |
| Additional information |
| File Size: 117025 bytes |
| MD5: a97da1d472795f6292dd7d04cb6359fe |
| Sha1: 957f638cf7a4e280006bd215a2f3df1c40a62c40 |
| Peid :- |
| Prevx info: http://info.prevx.com/aboutprogramtext.asp? Px5 = 039dc4132194491ac98301583b234e00d83fb8d1 |