- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-15-2010 08:09 AM
The Firefox 3.6.9 downloads from any of the mirros is being classified as Trojan-Downloader/Win32.banload.aumr, threat ID 2549505. Problem on Mozilla's end?
Here's the data from the PCAP:
fox/releases/3.6.9/win32/en-US/
-Type: application/octet-stream
MZ......................@...............................................!..L.!This program cannot be run in DOS mode.
$........H...)u..)u..)u...~..)u.75{..)u......)u...q..)u..)t. )u.w&(..)u...~..)u.s/s..)u.Rich.)u.........PE..L...fJ.D.....................p...p........... ....@.................................O.......................................\...p.... ..\l...........5..............................................................................................UPX0.....p..............................UPX1................................@....rsrc....p... ...n..................@..............................................................................................................................................................................................................................................................................................................................................................................................................2.03.UPX!
..
.....e2.............&.......V...N.....13..Fx.Nt.H.........@.......AA..Fh.....^......41V3..F`.".FT.Xo..-\.P.,&.$.j....mSZN.P.J.Bj....o
$^..k.. ..|/..A.,0.4.p8.P(m..-L.@.DH.<....T.."${.
....xS..VW.....M.....E.lS.E.3.P.}..w.......@..u.#..E..'.G..w..ut}..F0;....E.}.j....fk....Yt..`..\....3.....m..u.t...VV.].+.....,.E........
.O...d.a..M.I.M.....L.E....e.V..y...
.S.P.Q..w..M.=..7V+w....e..P....X.m..1.;.........E.E.?....;;..Vh..1..........as.i..
P....;.W......Pt
09-15-2010 03:21 PM
Hello,
thanks for the heads up. This is actually good information. Can you send in an email to support@paloaltonetworks.com with this same information. This can then be forwarded to our content team and we can fix this in about 1 week.
Can you include the following in your email:
serial number of your device
software version
content version
virus version if applicable
the pcap
the threat id
the name of the threat
thanks again,
Stephen
09-16-2010 06:20 AM
Just sent it. Thank you very much!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!