Norton Internet Security / Norton AntiVirus
Register  ·  Sign In  ·  Help
Jump to Page:   1
Kudos to Symantec for a fast response.   [ Edited ]
Options    Options  
mijcar
Super Phishing Phryer
Posts: 2568
Registered: 08-01-2008


mijcar

Message 1 of 8

Viewed 2,128 times


I got an email from "DHL-delivery.com" informing me that a package I had sent back in June had been misaddressed and I needed to send in the correct address.  The incorrect form was in a zip file and I was supposed to correct it.

 

Unfortunately, that was a real possibility.  Fortunately, I checked the website and found that it was an undeveloped quickie with name only thrown up on a free MS webhosting site.

 

I scanned the zip file using both Malwarebytes and Norton.  Both found it was clean.  Well, no way was I going to open it.  So I uploaded it to the Symantec security site.

 

A few hours later I got my response.  It was indeed a high security threat, containing a new trojan.  The signature file against it has already been put together and I suppose it is being delivered as I speak -- but in case it isn't, it is available via the Intelligent Updater; and you now know the form of delivery.

 

And, yes, when I scanned it now, it was detected and cleaned.

 

I think Symantec can be proud of how fast it responded in this instance.

Message Edited by mijcar on 09-24-2009 10:10 PM

 

mij
[XP3 and Vista2, IE 8, Firefox 3.5.5 and 3.6.2, NSW 12 Basic, NIS2010 (17.1.0.19); No other active securityware]
From Dictionary.com: Update: to incorporate new or more accurate information; Upgrade: a new versionviz
11
Kudos!
09-24-2009 09:05 PM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
Phil_D Super Trojan Terminator
Super Trojan Terminator
Posts: 3645
Registered: 06-10-2008


Phil_D

Message 2 of 8

Viewed 2,107 times


And Kudos to you, mijcar for the way you approached this and for submitting it to Symantec.

 

By your actions and those of Symantec, we have all benefited.

 

Thank you!


 

Phil_D

NIS 2010 • 360 v4 Beta

XP SP3 • Vista SP2 • IE8

Kudos!
09-24-2009 09:29 PM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
SendOfJive Super Virus Trouncer
Super Virus Trouncer
Posts: 871
Registered: 02-07-2009


SendOfJive

Message 3 of 8

Viewed 2,088 times


Good catch, mijcar,

 

I have seen reports that these fake shipping confirmation emails have recently become a growing trend in malware delivery.  Your experience and the way you handled it should be a lesson to all of us to treat any unexpected email attachment as highly suspicious.

Kudos!
09-24-2009 10:05 PM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
Quads Phishing Phryer
Phishing Phryer
Posts: 4192
Registered: 07-21-2008


Quads

Message 4 of 8

Viewed 2,083 times



SendOfJive wrote:

Good catch, mijcar,

 

I have seen reports that these fake shipping confirmation emails have recently become a growing trend in malware delivery.  Your experience and the way you handled it should be a lesson to all of us to treat any unexpected email attachment as highly suspicious.


 
Yep I have had Fedex ones.
Quads 

 

Kudos!
09-24-2009 10:13 PM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
mdturner
Rootkit Eradicator
Posts: 2348
Registered: 04-11-2008



Message 5 of 8

Viewed 2,056 times


mij

 

Terrific catch but also a good read and lesson for those people who are less experienced than you about what to do and not to do in these circumstances.

Kudos!
09-25-2009 12:01 AM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
Rohit1gupta
Super Keylogger Crusher
Posts: 627
Registered: 09-30-2008


Rohit1gupta

Message 6 of 8

Viewed 2,019 times


mijcar

 

Did u submit the file via symantec webpage or threatfire page?

 

B'coz whenever i submit on threatfire, definitions do not get added till a very long time. 


 

----------------------------------------------------------------

NIS 2010 final 17.0.0.136 Win 7 7600 32-bit
Kudos!
09-25-2009 02:01 AM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
mijcar
Super Phishing Phryer
Posts: 2568
Registered: 08-01-2008


mijcar

Message 7 of 8

Viewed 1,960 times



Rohit1gupta wrote:

mijcar

 

Did u submit the file via symantec webpage or threatfire page?

 

B'coz whenever i submit on threatfire, definitions do not get added till a very long time. 


I used the standard Symantec webpage:  websubmit: https://submit.symantec.com/websubmit/retail.cgi


 

mij
[XP3 and Vista2, IE 8, Firefox 3.5.5 and 3.6.2, NSW 12 Basic, NIS2010 (17.1.0.19); No other active securityware]
From Dictionary.com: Update: to incorporate new or more accurate information; Upgrade: a new versionviz
Kudos!
09-25-2009 07:29 AM
 
Re: Kudos to Symantec for a fast response.
Options    Options  
Yaso_Kuuhl Super Virus Trouncer
Super Virus Trouncer
Posts: 2228
Registered: 02-19-2009


Yaso_Kuuhl

Message 8 of 8

Viewed 1,919 times


Thanks for the great post, mijcar ;-) It also underlines how careful one has to be around such sneaky mails and attachments *shudders*.
 

A L I E N

Kudos!
09-25-2009 08:58 AM
 
Jump to Page:   1