Cyber Security News

Most Prevalent Malware Files – November 2013

MOST PREVALENT MALWARE FILES (COMPILED BY SOURCEFIRE)

Cyber Security: This is a list of this month’s most prevalent malware files as seen “in the wild.”. The list provides the hash checkup values for each file as well as a link to the entry on virustotal.  To assist computer forensics analysts or incident responders, the list provides the file name and the fake publisher claimed by the malware.
SHA 256:
00B7ACFCACD70642EB75871708D59F8D1A7DBCF813F235B7C2B37AC2DF7F87B7
MD5:
e66e725e10b9cb8a6f5c74d7ca9e98a9
VirusTotal:
https://www.virustotal.com/en/file/00B7ACFCACD70642EB75871708D59F8D1A7DBCF813F235B7C2B37AC2DF7F87B7/analysis/
Typical Filename: BitGuard.exe
Claimed Product: Protector
Claimed Publisher: MediaTechSoft Inc.

SHA 256:
a1f8f37d2d5646e06201ae961e6246337ee73569c8e157d21b9211a75fc26630
MD5:
dad6f82c589cd0d558374a8b5fa293b2
VirusTotal:
https://www.virustotal.com/en/file/A1F8F37D2D5646E06201AE961E6246337EE73569C8E157D21B9211A75FC26630/analysis/
Typical Filename: smodsulog.exe
Claimed Product: Worm.Palevo
Claimed Publisher: None

SHA 256:
ca24a8f7c04fe15a758f3360c8e5619205c53807bfc65f82c028cdf808bf2189
MD5:
ec63f649f7090f885ebd4770ffb92fcb
VirusTotal:
https://www.virustotal.com/en/file/CA24A8F7C04FE15A758F3360C8E5619205C53807BFC65F82C028CDF808BF2189/analysis/
Typical Filename: UpdateTask.exe
Claimed Product: W32.Trojan.16l1
Claimed Publisher: None

SHA 256:
b2cad8322db85f67db6ea074d00c2ed56ce1fa92952d07b70baac249fa18236d
MD5:
249a44dcfa2500eb1c020e33a3e9f25b
VirusTotal:
https://www.virustotal.com/en/file/B2CAD8322DB85F67DB6EA074D00C2ED56CE1FA92952D07B70BAAC249FA18236D/analysis/
Typical Filename: FlashPlayerUpdateService.exe
Claimed Product: W32.Downloader:AgentASEBTrj.16mc.1201
Claimed Publisher: None

SHA 256:
df83a0d6940600e4c4954f4874fcd4dd73e781e6690c3bf56f51c95285484a3c
MD5:
25aa9bb549ecc7bb6100f8d179452508
VirusTotal:
https://www.virustotal.com/en/file/DF83A0D6940600E4C4954F4874FCD4DD73E781E6690C3BF56F51C95285484A3C/analysis/

Typical Filename: ygrqpx.exe
Claimed Product: W32.Sality
Claimed Publisher: None

Previous post

Ransomware - AVM Technology on NBC12 News

Next post

Vulnerabilities For Which Exploits Are Available - November 2013

The Author

ForensicsVirginia

ForensicsVirginia