Most Prevalent Malware Files – November 2013
MOST PREVALENT MALWARE FILES (COMPILED BY SOURCEFIRE)
Cyber Security: This is a list of this month’s most prevalent malware files as seen “in the wild.”. The list provides the hash checkup values for each file as well as a link to the entry on virustotal. To assist computer forensics analysts or incident responders, the list provides the file name and the fake publisher claimed by the malware.
SHA 256:
00B7ACFCACD70642EB75871708D59F
MD5:
e66e725e10b9cb8a6f5c74d7ca9e98
VirusTotal:
https://www.virustotal.com/en/
Typical Filename: BitGuard.exe
Claimed Product: Protector
Claimed Publisher: MediaTechSoft Inc.
SHA 256:
a1f8f37d2d5646e06201ae961e6246
MD5:
dad6f82c589cd0d558374a8b5fa293
VirusTotal:
https://www.virustotal.com/en/
Typical Filename: smodsulog.exe
Claimed Product: Worm.Palevo
Claimed Publisher: None
SHA 256:
ca24a8f7c04fe15a758f3360c8e561
MD5:
ec63f649f7090f885ebd4770ffb92f
VirusTotal:
https://www.virustotal.com/en/
Typical Filename: UpdateTask.exe
Claimed Product: W32.Trojan.16l1
Claimed Publisher: None
SHA 256:
b2cad8322db85f67db6ea074d00c2e
MD5:
249a44dcfa2500eb1c020e33a3e9f2
VirusTotal:
https://www.virustotal.com/en/
Typical Filename: FlashPlayerUpdateService.exe
Claimed Product: W32.Downloader:AgentASEBTrj.
Claimed Publisher: None
SHA 256:
df83a0d6940600e4c4954f4874fcd4
MD5:
25aa9bb549ecc7bb6100f8d1794525
VirusTotal:
https://www.virustotal.com/en/
Typical Filename: ygrqpx.exe
Claimed Product: W32.Sality
Claimed Publisher: None