Skip to content

Comment on Root access to MySQL.com sold for $3k - now serving malware

Comments

I went to mysql.com this morning and Symantec popped up with a "malware detected" message. Do we know which browsers are vulnerable, and how to tell whether I'm infected?

Have a look at the movie that's embedded in the blog post. He's explaining which piece of malware is downloaded.

This link lists the AV packages that can currently detect the installed malware:

https://www.virustotal.com/file-scan/report.html?id=d761babc...

Well, currently the malware itself is not detected. OK, some anti-virus solutions detect the piece of malware as suspicious or as a packed executable (which is suspicious of course). But those detections are just based on the inner working of the executable or how it behaves. It's not being detected by anti-virus definitions, that will be a matter of time before anti-virus providers will add definitions for this piece of malware.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.