About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Sunday, March 11, 2012

008 - Crime - Blackhole payload FakeAV - trojan - Web - Feb 2012

MD5:  4135cbcf65163b39ea4ed00da7114cbe

Download (pass infected) 




Name  Blackhole delivered FakeAV
Category
Crime
type trojan  dropper
vector  Web
Sample credit Mila
Date Feb 2012

https://www.virustotal.com/file/d2444eb298bcbcecc31c548b6f2554424304672e727fbf7497b3cc3df2e36e24/analysis/
 SHA256:     d2444eb298bcbcecc31c548b6f2554424304672e727fbf7497b3cc3df2e36e24
SHA1:     329c53e760aa26d6242fe61f0dd6bca7d3ba367d
MD5:     4135cbcf65163b39ea4ed00da7114cbe
File size:     801.0 KB ( 820224 bytes )
File name:     4135cbcf65163b39ea4ed00da7114cbe
File type:     Win32 EXE
Detection ratio:     23 / 43
Analysis date:     2011-12-10 15:30:24 UTC ( 3 months ago )
Antivirus     Result     Update
AhnLab-V3     Trojan/Win32.Jorik     20111209
AntiVir     TR/Crypt.XPACK.Gen3     20111209
Antiy-AVL     Trojan/win32.agent.gen     20111210
Avast     Win32:FakeAlert-BPF [Trj]     20111209
AVG     Generic26.SLF     20111210
BitDefender     Gen:Variant.Kazy.47732     20111210
Comodo     UnclassifiedMalware     20111210
DrWeb     Trojan.Fakealert.26233     20111210
Emsisoft     Win32.SuspectCrc!IK     20111210
eTrust-Vet     -     20111209
F-Secure     Gen:Variant.Kazy.47732     20111210
Fortinet     W32/FakeAlert_Rena.BG!tr     20111210
GData     Gen:Variant.Kazy.47732     20111210
Ikarus     Win32.SuspectCrc     20111210
Kaspersky     HEUR:Trojan.Win32.Generic     20111210
McAfee     FakeAlert-Rena.bg     20111210
McAfee-GW-Edition     FakeAlert-Rena.bg     20111210
Norman     W32/Suspicious_Gen2.TVZEA     20111210
Panda     Trj/CI.A     20111210
Sophos     Mal/FakeAV-LX     20111210
SUPERAntiSpyware     -     20111210
TrendMicro     TROJ_GEN.R72C7L8     20111210
TrendMicro-HouseCall     TROJ_GEN.R72C7L8     20111210