Jump to content

Daedalus

Members
  • Posts

    98
  • Joined

  • Last visited

  • Days Won

    2

Posts posted by Daedalus

  1. 37 minutes ago, 0xDEADBEEF said:

    This originally comes from a potentially phishing mail (so social engineering wise, it is already suspicious enough)

    It is exhibiting some very suspicious behavior, like vbs drop, add autostart, query security products and UUID, and write files to sensitive paths... But I am not sure about if these are enough to be verdicted as "malicious". Most detections of this file on VT are either machine learning/heur and generated by auto pipeline, no concrete signature detections so far though.

    On VT, the first detection is by Kaspersky, Bitdefender and Cyren, and then followed by avast and avira. I was waiting ESET's verdict for two days and we will see.

    Thanks for the clarification!

  2. I think it is safe to say that the file is not clean:
    https://www.virustotal.com/en/file/67a241d4845bd929b6345059c030f9392477d2179bde86d2109bd5371ad1f004/analysis/

    Looks like ESET is running a bit behind on this one.

    If you got the file you can also upload it on the following site to see what is does:
    https://www.hybrid-analysis.com/ (P.S. website does not work in Chrome)

  3. 2 minutes ago, BALTAGY said:

    Maybe a mod can check the ticket with them and remind them only, is that a problem for you ?

    Maybe you could have been more clear about what you where expecting from someone in the opening post. 

    But beside that, it is an strange approach that you first contact support and the resolution they have given is not working that you don't re-open that ticket or contact them again.

    And instead you are just posting here. But this is just my personal opinion. 

  4. That website is serving advertisements so you probably get the alert with some of the Ads they are serving through other websites.

    I also can get to the website without problems (okay my Adblocker blocked the site first) httpx://moatads.com and at httpx://mb.moatads.com i get 404 not found.

     

     

  5. I created an ESI log and did the show action -> No issues the GUI loaded pretty fast. (20-30 sec)

    Created an second ESI log (so practically the same log ) did an compare -> I thought it was hanging on the "Performing loading sequence" but after 3-4 minutes the GUI showed up. No idea if it is normal that it takes this time to load.

  6. 43 minutes ago, gencer said:

    I cannot activate eis 11. It says Error Code: ACT.0... What is happening there?!

    https://support.eset.com/en_SG/kb2434/

    But i wouldn't be surprised if this issue is related to the "LiveGrid"  issues what is also happening: (should be resolved)

    I'd say try activating again, and if it fails see above KB article

     

×
×
  • Create New...