查看: 9442|回复: 71
收起左侧

[病毒样本] (0904.24-25)卡饭论坛被挂—样本及下载物+分析(9日更新38X-Update6)

[复制链接]
Sherry.ai
发表于 2009-4-24 20:12:16 | 显示全部楼层 |阅读模式
首先是一个htm...
因为当时没有开监控,且至今电脑没发现其样本
接下来在temp目下下载一个*.exe(不知道是啥名地址http://bbs.kafan.cn/thread-467953-1-1.html
然后下载ok.exe,借助bat终止杀软进程
并用病毒文件替换杀毒软件....很XE
最后.....就是最终目的
下载木马群[:26:]
http://u2.d7n9.com/la/L1.exe
http://u2.d7n9.com/la/L3.exe
http://u2.d7n9.com/la/L4.exe
http://u2.d7n9.com/la/L5.exe
http://u2.d7n9.com/la/L6.exe
http://u2.d7n9.com/la/L7.exe
http://u3.d7n9.com/lm/S10.exe
http://u3.d7n9.com/lm/S1.exe
http://u3.d7n9.com/lm/S8.exe
http://u3.d7n9.com/lm/S2.exe
http://u3.d7n9.com/lm/S12.exe
http://u3.d7n9.com/lm/S14.exe
http://u3.d7n9.com/lm/S01.exe
http://u2.d7n9.com/lm/M5.exe
http://u2.d7n9.com/lm/M39.exe
http://u2.d7n9.com/lm/M25.exe
http://u2.d7n9.com/lm/M4.exe
http://u2.d7n9.com/lm/M35.exe
http://u2.d7n9.com/lm/M33.exe
http://u2.d7n9.com/lm/M01.exe
http://u3.d7n9.com/lm/S15.exe
http://u3.d7n9.com/lm/S16.exe
http://u3.d7n9.com/lm/S21.exe
http://u2.d7n9.com/lm/M37.exe
http://u2.d7n9.com/lm/M15.exe
http://u2.d7n9.com/lm/M24.exe
http://u2.d7n9.com/lm/M38.exe
http://u2.d7n9.com/lm/M23.exe
http://u2.d7n9.com/lm/M02.exe
http://u3.d7n9.com/lm/S13.exe
http://u3.d7n9.com/lm/S17.exe
http://u3.d7n9.com/lm/S20.exe
http://u3.d7n9.com/lm/S21.exe
http://u3.d7n9.com/lm/S11.exe
http://u7.d7n9.com/cj/a1.exe
http://u9.d7n9.com/cj/a2.exe
http://u9.d7n9.com/cj/a10.exe
http://u9.d7n9.com/cj/a6.exe
http://u7.d7n9.com/cj/a9.exe
http://u7.d7n9.com/cj/csj.exe
http://u0.d7n9.com/cj/a8.exe
http://u0.d7n9.com/cj/sb.exe
25日新增的:
http://u0.d7n9.com/cj/a8.exe
http://u8.d7n9.com/sb/01.exe
http://u0.d7n9.com/cj/sb1.exe
一个为失效的
28日更新
http://u1.ed3t.com/la/L1.exe
http://u1.ed3t.com/la/L3.exe
http://u1.ed3t.com/la/L4.exe
http://u1.ed3t.com/la/L5.exe
http://u1.ed3t.com/la/L6.exe
http://u1.ed3t.com/la/L7.exe
http://u2.ed3t.com/lm/S10.exe
http://u2.ed3t.com/lm/S1.exe
http://u2.ed3t.com/lm/S8.exe
http://u2.ed3t.com/lm/S2.exe
http://u2.ed3t.com/lm/S12.exe
http://u2.ed3t.com/lm/S14.exe
http://u2.ed3t.com/lm/S01.exe
http://u3.ed3t.com/lm/M5.exe
http://u3.ed3t.com/lm/M39.exe
http://u3.ed3t.com/lm/M25.exe
http://u3.ed3t.com/lm/M4.exe
http://u3.ed3t.com/lm/M35.exe
http://u3.ed3t.com/lm/M33.exe
http://u3.ed3t.com/lm/M01.exe
http://u2.ed3t.com/lm/S15.exe
http://u2.ed3t.com/lm/S16.exe
http://u2.ed3t.com/lm/S21.exe
http://u3.ed3t.com/lm/M37.exe
http://u3.ed3t.com/lm/M15.exe
http://u3.ed3t.com/lm/M24.exe
http://u3.ed3t.com/lm/M38.exe
http://u3.ed3t.com/lm/M23.exe
http://u3.ed3t.com/lm/M02.exe
http://u2.ed3t.com/lm/S13.exe
http://u2.ed3t.com/lm/S17.exe
http://u2.ed3t.com/lm/S20.exe
http://u2.ed3t.com/lm/S21.exe
http://u2.ed3t.com/lm/S11.exe
http://u9.ed3t.com/cj/1a.exe
http://u9.ed3t.com/cj/a2.exe
http://u9.ed3t.com/cj/a10.exe
http://u9.ed3t.com/cj/a6.exe
http://u9.ed3t.com/cj/a9.exe
http://u9.ed3t.com/cj/csj.exe
http://u9.ed3t.com/cj/a8.exe
http://u9.ed3t.com/cj/sb.exe
4日更新
http://u1.s8f3.com/la/L1.exe
http://u1.s8f3.com/la/L3.exe
http://u1.s8f3.com/la/L4.exe
http://u1.s8f3.com/la/L2.exe
http://u9.s8f3.com/cj/a1.exe
http://u3.s8f3.com/lm/M39.exe
http://u3.s8f3.com/lm/M38.exe
http://u3.s8f3.com/lm/M23.exe
http://u3.s8f3.com/lm/M5.exe
http://u3.s8f3.com/lm/M25.exe
http://u3.s8f3.com/lm/M4.exe
http://u3.s8f3.com/lm/M01.exe
http://u2.s8f3.com/lm/S10.exe
http://u2.s8f3.com/lm/S8.exe
http://u2.s8f3.com/lm/S1.exe
http://u2.s8f3.com/lm/S2.exe
http://u2.s8f3.com/lm/S12.exe
http://u2.s8f3.com/lm/S14.exe
http://u2.s8f3.com/lm/S15.exe
http://u2.s8f3.com/lm/S16.exe
http://u2.s8f3.com/lm/S21.exe
http://u2.s8f3.com/lm/S01.exe
http://u3.s8f3.com/lm/M33.exe
http://u3.s8f3.com/lm/M37.exe
http://u3.s8f3.com/lm/M15.exe
http://u3.s8f3.com/lm/M24.exe
http://u3.s8f3.com/lm/M02.exe
http://u2.s8f3.com/lm/S13.exe
http://u2.s8f3.com/lm/S17.exe
http://u2.s8f3.com/lm/S20.exe
http://u2.s8f3.com/lm/S11.exe
http://u2.s8f3.com/lm/S02.exe
http://u1.s8f3.com/la/L5.exe
http://u1.s8f3.com/la/L6.exe
http://u1.s8f3.com/la/L7.exe
http://u1.s8f3.com/la/L8.exe
http://u1.s8f3.com/la/L9.exe
http://u9.s8f3.com/cj/a2.exe
http://u9.s8f3.com/cj/a8.exe
http://u9.s8f3.com/cj/a6.exe
http://u9.s8f3.com/cj/a9.exe
http://u9.s8f3.com/cj/a10.exe
http://u9.s8f3.com/cj/sb.exe
9日更新
http://u1.ovfr6.com/laa/L1.exe
http://u1.ovfr6.com/laa/L3.exe
http://u1.ovfr6.com/laa/L7.exe
http://u1.ovfr6.com/laa/L8.exe
http://u1.ovfr6.com/laa/L9.exe
http://u1.ovfr6.com/laa/L2.exe
http://u3.ovfr6.com/lmm/M39.exe
http://u3.ovfr6.com/lmm/M38.exe
http://u3.ovfr6.com/lmm/M23.exe
http://u3.ovfr6.com/lmm/M5.exe
http://u3.ovfr6.com/lmm/M25.exe
http://u3.ovfr6.com/lmm/M4.exe
http://u3.ovfr6.com/lmm/M01.exe
http://u2.ovfr6.com/lmm/S10.exe
http://u2.ovfr6.com/lmm/S8.exe
http://u2.ovfr6.com/lmm/S1.exe
http://u2.ovfr6.com/lmm/S2.exe
http://u2.ovfr6.com/lmm/S12.exe
http://u2.ovfr6.com/lmm/S14.exe
http://u2.ovfr6.com/lmm/S15.exe
http://u2.ovfr6.com/lmm/S16.exe
http://u2.ovfr6.com/lmm/S21.exe
http://u2.ovfr6.com/lmm/S01.exe
http://u3.ovfr6.com/lmm/M33.exe
http://u3.ovfr6.com/lmm/M37.exe
http://u3.ovfr6.com/lmm/M15.exe
http://u3.ovfr6.com/lmm/M24.exe
http://u3.ovfr6.com/lmm/M02.exe
http://u2.ovfr6.com/lmm/S13.exe
http://u2.ovfr6.com/lmm/S17.exe
http://u2.ovfr6.com/lmm/S20.exe
http://u2.ovfr6.com/lmm/S11.exe
http://u2.ovfr6.com/lmm/S02.exe
http://u9.ovfr6.com/cjj/a1.exe
http://u9.ovfr6.com/cjj/a2.exe
http://u9.ovfr6.com/cjj/a8.exe
http://u9.ovfr6.com/cjj/a6.exe
http://u9.ovfr6.com/cjj/a9.exe
http://u9.ovfr6.com/cjj/a10.exe
http://u9.ovfr6.com/cjj/sb.exe

[ 本帖最后由 935623508 于 2009-5-9 15:42 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Sherry.ai
 楼主| 发表于 2009-4-24 20:18:52 | 显示全部楼层
MS就这些
llzy3575
发表于 2009-4-24 20:19:43 | 显示全部楼层
下载测试~~~~~
小红伞全歼

[ 本帖最后由 llzy3575 于 2009-4-24 20:41 编辑 ]
悠柚
发表于 2009-4-24 20:22:04 | 显示全部楼层
AVG 第一个 Worm/Generic.WJJ
悠柚
发表于 2009-4-24 20:26:44 | 显示全部楼层
AVG 第二包
"Infections"
"File";"Infection";"Result"
"D:\TDDownload\木马群\122B901E.dll";"Trojan horse PSW.Generic7.DQR";"Infected"
"D:\TDDownload\木马群\12days.dll";"Trojan horse PSW.Generic7.EGG";"Infected"
"D:\TDDownload\木马群\12days.exe";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\2742513_xeex.exe";"Trojan horse Downloader.Generic8.AGLJ";"Infected"
"D:\TDDownload\木马群\56BC86C7.dll";"Trojan horse PSW.OnlineGames3.BQI";"Infected"
"D:\TDDownload\木马群\704C3595.dll";"Trojan horse PSW.Generic7.DQX";"Infected"
"D:\TDDownload\木马群\a8.exe";"Trojan horse BackDoor.Generic9.VNG";"Infected"
"D:\TDDownload\木马群\efc0c52cc1.dll";"Trojan horse PSW.Generic7.DIK";"Infected"
"D:\TDDownload\木马群\GrTZqH5SnRhAt.dll";"Trojan horse PSW.Generic7.DIG";"Infected"
"D:\TDDownload\木马群\JBn2ypqY23vWX.dll";"Trojan horse PSW.OnlineGames3.BSJ";"Infected"
"D:\TDDownload\木马群\jxsystem.gif";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\L1.exe";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\L3.exe";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\L4.exe";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\L5.exe";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\L6.exe";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\M15.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M23.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M24.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M25.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M33.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M35.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M37.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M39.exe";"Trojan horse PSW.Generic7.EGR.dropper";"Infected"
"D:\TDDownload\木马群\M4.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\M5.exe";"Trojan horse PSW.Generic7.EEZ.dropper";"Infected"
"D:\TDDownload\木马群\Nj4gYd3rUbJ57.dll";"Trojan horse PSW.Generic7.DQL";"Infected"
"D:\TDDownload\木马群\peV7mS4gcukR.dll";"Trojan horse PSW.Generic7.DQU";"Infected"
"D:\TDDownload\木马群\PkVyCX5kHnftC7BXjt.dll";"Trojan horse PSW.Generic7.EEZ";"Infected"
"D:\TDDownload\木马群\S1.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S10.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S12.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S13.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S14.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S11.exe";"Trojan horse PSW.Generic7.EDY.dropper";"Infected"
"D:\TDDownload\木马群\S15.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S16.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S17.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S2.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S20.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S21.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\S8.exe";"Trojan horse Downloader.Zlob_r.FK";"Infected"
"D:\TDDownload\木马群\scvhost.exe";"Virus found Win32/Heur";"Infected"
"D:\TDDownload\木马群\xcsystem.gif";"Virus identified Win32/Cryptor";"Infected"
"D:\TDDownload\木马群\zxsystem.gif";"Virus identified Win32/Cryptor";"Infected"

"Spyware"
"File";"Infection";"Result"
"D:\TDDownload\木马群\a2.exe";"Adware Generic4.BFF.dropper";"Potentially dangerous object"
"D:\TDDownload\木马群\a2.exe:\$KA\15.exe";"Adware Generic4.BFF";"Potentially dangerous object"

miss one
上报中
Sherry.ai
 楼主| 发表于 2009-4-24 20:28:55 | 显示全部楼层

回复 5楼 悠柚 的帖子

还有Zlob么
qigang
发表于 2009-4-24 20:29:00 | 显示全部楼层
死牛。
luxiao200888
发表于 2009-4-24 20:30:56 | 显示全部楼层
avira kill all

全启发..

评分

参与人数 1人气 +1 收起 理由
935623508 + 1 发现乃了~~~

查看全部评分

cc56cc56
发表于 2009-4-24 20:33:50 | 显示全部楼层
我的红伞怎么没反应,一直开着监控和防火墙~~~也没什么提示啊

让我扫了一遍电脑~~~~
醉一生爱妍
发表于 2009-4-24 20:36:26 | 显示全部楼层

回复 1楼 935623508 的帖子

压缩壳 咔嚓 飘过

00002298   00404098      0   http://wll.6d2n.com/list.txt
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 10:29 , Processed in 0.133762 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表