Another Massive ID theft ring



It looks like Sunbelt has found ANOTHER massive Identity theft ring. They suspect it’s a trojan from the Dumaru family that is contentedly logging the infromation and promise more details.


They did get a hold of the trojan and passed it through virustotal to see what it was. Very FEW antivirus vendors have definitions for it at this point. The file in question is winldra.exe
Here’s the summary they got.

This is a report processed by VirusTotal on 08/19/2005 at 23:45:42 (CET) after scanning the file “winldra.exe” file.
Antivirus Version Update Result
AntiVir 6.31.1.0 08.19.2005 no virus found
Avast 4.6.695.0 08.19.2005 no virus found
AVG 718 08.19.2005 no virus found
Avira 6.31.1.0 08.19.2005 no virus found
BitDefender 7.0 08.19.2005 no virus found
CAT-QuickHeal 7.03 08.19.2005 no virus found
ClamAV devel-20050725 08.18.2005 no virus found
DrWeb 4.32b 08.19.2005 no virus found
eTrust-Iris 7.1.194.0 08.18.2005 no virus found
eTrust-Vet 11.9.1.0 08.19.2005 Win32.Bambo
Fortinet 2.41.0.0 08.18.2005 suspicious
F-Prot 3.16c 08.19.2005 no virus found
Ikarus 0.2.59.0 08.19.2005 no virus found
Kaspersky 4.0.2.24 08.19.2005 no virus found
McAfee 4563 08.19.2005 BackDoor-CCT
NOD32v2 1.1198 08.19.2005 no virus found
Norman 5.70.10 08.18.2005 no virus found
Panda 8.02.00 08.19.2005 no virus found
Sophos 3.96.0 08.19.2005 no virus found
Sybari 7.5.1314 08.19.2005 no virus found
Symantec 8.0 08.19.2005 no virus found
TheHacker 5.8.2.091 08.18.2005 no virus found
VBA32 3.10.4 08.19.2005 suspected of Embedded.Backdoor.Win32.Dumador.dd

(It looks as though 3 of the antivirus vendors recognize this so far.)

They’re working with the vendors to get signature updates.

Related Posts

Blog Traffic Exchange Related Posts
  • Qemu 0.8.1 (with kqemu 1.3.0pre7) While I was testing out the "single cut and paste" linux vnc remote desktop sharing script and x11vnc binary.... I spent a fair amount of time booting up livecd's n qemu to test various distributions/ages of linux setups to see how compatible things were. I had not checked in at......
  • New Beagle/Bagle variant? So, I submitted the suspicious attachment I received to virustotal (scan@virustotal.com with SCAN in the subject and suspicious file as attachment.) What follows below is the report I received. It looks like some of the big names (Symantec, McAfee are not finding anything wrong with it at this point, with......
  • Clamav 0.88.1 for Mandrake 10.0 Since, I've still got a few older Mandrake 10 installs that I'm maintaining as mailservers, there aren't supported security fixes for various things anymore... Friday there was news of a new clamantivirus to fix some security flaws with 0.88, new version is 0.88.1 I've taken the cooker srpm and recompiled......
Blog Traffic Exchange Related Websites
  • Weight Tracking (Last Attempt) Total Weight Lost: 58lbs Here is my weight tracking page... It will evolve as I get more accustomed to my new lifestyle, but for starters if you want to know about the Jumpstart Medicine weight loss program that I am following read this post WeightLadder Reset — 390lbs and Starting......
  • New Loan Funded — Too Much Business / Need to Expand — $9,500 at 20% — AA Credit — DTI 45% A new loan funded (Too Much Business / Need to Expand — $9,500 at 20%).  I participated via a 2 standing orders (Low Amt Extreme DTI and Low Amt Any DTI) and a manual bid the loan was Autofunding.  The borrower had AA credit and 45% DTI.  As a reminder my standing orders......
  • 1000cc Supersports Bikes of 2010 Compared Lately I've been viewing videos and specs of some superbikes after receiving an email from Yamaha about their new 2010 YZF-R1. My interest with superbikes started when I was 10 years old when my brother bought some magazines about superbikes and he was a motorcycle mechanics at that time. It......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

One Response to “Another Massive ID theft ring”

  1. Avery J. Parker - Web site hosting and computer service Says:


    [...] The other day I did a post about Sunbelt mentioning another big identity theft ring. That post that I referred to has been pulled from their site. [...]


Switch to our mobile site