Undetected Rogue Videocodec + Undected Zlob Variants

Hello


I've attached some undectected malcious videocodecs+ more zlob variants. The password is infected.


Regards


Niels

/applications/core/interface/file/attachment.php?id=594" data-fileid="594" rel="">samples.rar

Comments

  • One of the samples is already detected as Trojan.Zlob.BTO. The other (popcodec*) doesn't actually do anything malicious. It's not really clear why it was created (maybe as a bait), but in it current form it's perfecly harmless, so it won't be signed.


    Best regards.

  • Hello Cd-MaN


    I also send the samples to virus_submission@bitdefender.com that could be the reason why it was already detected. Did you also take a look at the hosting sites for zlob variants?


    Thanks for your very quick reply.


    Regards


    Niels

  • The suspicious domains we know of are continously monitored, however there might be (in fact there surely are :) ) such sites we don't know of, so keep them coming :)

  • Hello Cd-MaN


    I will just keep posting them. Thanks for your explanation. I really appreciated it.


    Regards


    Niels