4.26样本和报告往下看
十几分钟前扫描报告卡巴还不能杀,现在可以杀了,不过红伞依旧无反应!
可以说这是阴险的有预谋的针对红伞和卡巴在本论坛的高使用率的阴谋挂马行为。
这是病毒行为分析地址:http://www.threatexpert.com/report.aspx?md5=68e277490e883bcd420ae9cb8d685524
样本:
扫描报告:
文件 Actvev_1_.exe 接收于 2009.04.25 14:37:33 (CET)
当前状态: 完成
结果: 23/40 (57.50%)
反病毒引擎 | 版本 | 最后更新 | 扫描结果 | a-squared | 4.0.0.101 | 2009.04.25 | Trojan-PWS.Win32.Agent.jp!IK | AhnLab-V3 | 5.0.0.2 | 2009.04.24 | - | AntiVir | 7.9.0.156 | 2009.04.24 | - | Antiy-AVL | 2.0.3.1 | 2009.04.24 | - | Authentium | 5.1.2.4 | 2009.04.24 | W32/Rootkit-PX!Eldorado | Avast | 4.8.1335.0 | 2009.04.25 | Win32:Rootkit-gen | AVG | 8.5.0.287 | 2009.04.25 | Win32/Heur | BitDefender | 7.2 | 2009.04.25 | Trojan.KillAV.PT | CAT-QuickHeal | 10.00 | 2009.04.25 | - | ClamAV | 0.94.1 | 2009.04.25 | - | Comodo | 1135 | 2009.04.25 | - | DrWeb | 4.44.0.09170 | 2009.04.25 | - | eSafe | 7.0.17.0 | 2009.04.23 | Suspicious File | eTrust-Vet | 31.6.6475 | 2009.04.24 | - | F-Prot | 4.4.4.56 | 2009.04.24 | W32/Rootkit-PX!Eldorado | F-Secure | 8.0.14470.0 | 2009.04.25 | - | Fortinet | 3.117.0.0 | 2009.04.25 | W32/Dropper.Q!tr | GData | 19 | 2009.04.25 | Trojan.KillAV.PT | Ikarus | T3.1.1.49.0 | 2009.04.25 | Trojan-PWS.Win32.Agent.jp | K7AntiVirus | 7.10.716 | 2009.04.25 | - | Kaspersky | 7.0.0.125 | 2009.04.25 | Trojan-Downloader.Win32.Geral.eu | McAfee | 5595 | 2009.04.24 | Generic Dropper.q | McAfee+Artemis | 5595 | 2009.04.24 | Generic!Artemis | McAfee-GW-Edition | 6.7.6 | 2009.04.25 | - | Microsoft | 1.4602 | 2009.04.25 | Trojan:Win32/Dogrobot.F | NOD32 | 4035 | 2009.04.25 | a variant of Win32/AntiAV.AZQ | Norman | 6.00.06 | 2009.04.24 | W32/Rootkit.XDV.dropper | nProtect | 2009.1.8.0 | 2009.04.25 | - | Panda | 10.0.0.14 | 2009.04.25 | Suspicious file | PCTools | 4.4.2.0 | 2009.04.25 | - | Prevx1 | 3.0 | 2009.04.25 | - | Rising | 21.26.52.00 | 2009.04.25 | Trojan.Win32.KillAV.bau | Sophos | 4.41.0 | 2009.04.25 | Mal/PWS-Fam | Sunbelt | 3.2.1858.2 | 2009.04.24 | Trojan.Rootkit.GEN | Symantec | 1.4.4.12 | 2009.04.25 | Infostealer.Gampass | TheHacker | 6.3.4.1.314 | 2009.04.25 | - | TrendMicro | 8.700.0.1004 | 2009.04.24 | Possible_Mlwr-13 | VBA32 | 3.12.10.3 | 2009.04.24 | suspected of Win32.BrokenEmbeddedSignature (paranoid heuristics) | ViRobot | 2009.4.24.1708 | 2009.04.24 | - | VirusBuster | 4.6.5.0 | 2009.04.24 | - |
附加信息 | File size: 42504 bytes | MD5...: 68e277490e883bcd420ae9cb8d685524 | SHA1..: f289b20a8f581b2f14c7367c59c0cdd4f2636caa | SHA256: b380b64d36ada386a062a626d744ca257e006906cf58b4e5b2f14fce2902b5b6 | SHA512: 5f23979aae9e9a4d1ebb5cf3000fe189e8b66fdb9e55a4873ea31f1943572354
86c4ad256b11b5dd0ae227fec669bd2931f91974641f35e74e5fb55118d68257 | ssdeep: 768:5qDBa85DYmUqNLMAlHswFKuiJTudHoFHpIcz6UYLiiwTw0PI:oYoYmUSLMOs
cKDJCdHCH/69YTe
| PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser | TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%) | PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1be90
timedatestamp.....: 0x49f1b77d (Fri Apr 24 12:58:37 2009)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x12000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x13000 0xa000 0x9200 7.88 bd86cdfe6f82dac0d89620f74bece3ef
.rsrc 0x1d000 0x1000 0x600 3.09 52ea5891c8b2ad2f4e8b5d77cf5248fe
( 4 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: OpenServiceA
> SHELL32.dll: ShellExecuteA
> USER32.dll: wsprintfA
( 0 exports )
| PDFiD.: - | RDS...: NSRL Reference Data Set
- | packers (Avast): UPX | packers (F-Prot): UPX |
最新消息红伞也可以杀了,大蜘蛛依然无视。
文件 Actvev.rar 接收于 2009.04.25 16:22:55 (CET)
当前状态: 正在读取 ... 队列中 等待中 扫描中 完成 未发现 停止
结果: 23/40 (57.5%)
正在读取服务器信息中...
您的文件所排队列位置: 1.
预计开始时间为 38 和 54 秒之间.
扫描完成前请勿关闭窗口.
目前针对您的文件所进行的扫描进程已停止, 我们将会在稍后恢复.
如果您的等候时间超过 5 分钟, 请重新发送文件.
您的文件目前正在被 VirusTotal 扫描中,
结果将会稍后完成时生成.
您的文件已过期或不存在.
目前服务已停止, 您的文件将会稍后的未知时间内进行扫描 (位置:
). 您可以继续等待回应 (自动读取) 或者在下面的表单内输入您的电子邮件地址, 并按下 "获取", 当扫描完成时, 系统会自动给您发送电子邮件通知.
反病毒引擎 | 版本 | 最后更新 | 扫描结果 | a-squared | 4.0.0.101 | 2009.04.25 | Trojan-PWS.Win32.Agent.jp!IK | AhnLab-V3 | 5.0.0.2 | 2009.04.24 | - | AntiVir | 7.9.0.156 | 2009.04.25 | TR/Dldr.Geral.EU | Antiy-AVL | 2.0.3.1 | 2009.04.24 | - | Authentium | 5.1.2.4 | 2009.04.24 | W32/Rootkit-PX!Eldorado | Avast | 4.8.1335.0 | 2009.04.25 | Win32:Rootkit-gen | AVG | 8.5.0.287 | 2009.04.25 | Win32/Heur | BitDefender | 7.2 | 2009.04.25 | Trojan.KillAV.PT | CAT-QuickHeal | 10.00 | 2009.04.25 | - | ClamAV | 0.94.1 | 2009.04.25 | - | Comodo | 1135 | 2009.04.25 | - | DrWeb | 4.44.0.09170 | 2009.04.25 | - | eSafe | 7.0.17.0 | 2009.04.23 | Suspicious File | eTrust-Vet | 31.6.6475 | 2009.04.24 | - | F-Prot | 4.4.4.56 | 2009.04.24 | W32/Rootkit-PX!Eldorado | F-Secure | 8.0.14470.0 | 2009.04.25 | - | Fortinet | 3.117.0.0 | 2009.04.25 | W32/Dropper.Q!tr | GData | 19 | 2009.04.25 | Trojan.KillAV.PT | Ikarus | T3.1.1.49.0 | 2009.04.25 | Trojan-PWS.Win32.Agent.jp | K7AntiVirus | 7.10.716 | 2009.04.25 | - | Kaspersky | 7.0.0.125 | 2009.04.25 | Trojan-Downloader.Win32.Geral.eu | McAfee | 5595 | 2009.04.24 | Generic Dropper.q | McAfee+Artemis | 5595 | 2009.04.24 | Generic!Artemis | McAfee-GW-Edition | 6.7.6 | 2009.04.25 | Trojan.Dldr.Geral.EU | Microsoft | 1.4602 | 2009.04.25 | Trojan:Win32/Dogrobot.F | NOD32 | 4035 | 2009.04.25 | a variant of Win32/AntiAV.AZQ | Norman | 6.00.06 | 2009.04.24 | W32/Rootkit.XDV.dropper | nProtect | 2009.1.8.0 | 2009.04.25 | - | Panda | 10.0.0.14 | 2009.04.25 | Suspicious file | PCTools | 4.4.2.0 | 2009.04.25 | - | Prevx1 | 3.0 | 2009.04.25 | - | Rising | 21.26.52.00 | 2009.04.25 | Trojan.Win32.KillAV.bau | Sophos | 4.41.0 | 2009.04.25 | Mal/PWS-Fam | Sunbelt | 3.2.1858.2 | 2009.04.24 | - | Symantec | 1.4.4.12 | 2009.04.25 | Infostealer.Gampass | TheHacker | 6.3.4.1.314 | 2009.04.25 | - | TrendMicro | 8.700.0.1004 | 2009.04.24 | Possible_Mlwr-13 | VBA32 | 3.12.10.3 | 2009.04.24 | - | ViRobot | 2009.4.24.1708 | 2009.04.24 | - | VirusBuster | 4.6.5.0 | 2009.04.25 | - |
4.26日样本依然卡巴、红伞免杀、大蜘蛛也没戏
文件 new.exe 接收于 2009.04.26 15:46:19 (CET)
当前状态: 完成
结果: 19/40 (47.50%)
反病毒引擎 | 版本 | 最后更新 | 扫描结果 | a-squared | 4.0.0.101 | 2009.04.26 | Trojan-PWS.Win32.Agent.jp!IK | AhnLab-V3 | 5.0.0.2 | 2009.04.26 | - | AntiVir | 7.9.0.156 | 2009.04.25 | - | Antiy-AVL | 2.0.3.1 | 2009.04.24 | - | Authentium | 5.1.2.4 | 2009.04.25 | W32/Rootkit-PX!Eldorado | Avast | 4.8.1335.0 | 2009.04.25 | Win32:Rootkit-gen | AVG | 8.5.0.287 | 2009.04.26 | Win32/Heur | BitDefender | 7.2 | 2009.04.26 | Trojan.KillAV.PT | CAT-QuickHeal | 10.00 | 2009.04.25 | - | ClamAV | 0.94.1 | 2009.04.26 | - | Comodo | 1135 | 2009.04.25 | - | DrWeb | 4.44.0.09170 | 2009.04.26 | - | eSafe | 7.0.17.0 | 2009.04.23 | Suspicious File | eTrust-Vet | 31.6.6475 | 2009.04.24 | - | F-Prot | 4.4.4.56 | 2009.04.25 | W32/Rootkit-PX!Eldorado | F-Secure | 8.0.14470.0 | 2009.04.25 | - | Fortinet | 3.117.0.0 | 2009.04.26 | - | GData | 19 | 2009.04.26 | Trojan.KillAV.PT | Ikarus | T3.1.1.49.0 | 2009.04.26 | Trojan-PWS.Win32.Agent.jp | K7AntiVirus | 7.10.716 | 2009.04.25 | - | Kaspersky | 7.0.0.125 | 2009.04.26 | - | McAfee | 5596 | 2009.04.25 | Generic Dropper.q | McAfee+Artemis | 5596 | 2009.04.25 | Generic!Artemis | McAfee-GW-Edition | 6.7.6 | 2009.04.26 | - | Microsoft | 1.4602 | 2009.04.26 | Trojan:Win32/Dogrobot.F | NOD32 | 4035 | 2009.04.25 | a variant of Win32/AntiAV.AZQ | Norman | 6.00.06 | 2009.04.24 | W32/Rootkit.XDV.dropper | nProtect | 2009.1.8.0 | 2009.04.26 | - | Panda | 10.0.0.14 | 2009.04.26 | - | PCTools | 4.4.2.0 | 2009.04.26 | - | Prevx1 | 3.0 | 2009.04.26 | - | Rising | 21.26.62.00 | 2009.04.26 | Trojan.Win32.KillAV.bau | Sophos | 4.41.0 | 2009.04.26 | - | Sunbelt | 3.2.1858.2 | 2009.04.24 | Trojan.Rootkit.GEN | Symantec | 1.4.4.12 | 2009.04.26 | Infostealer.Gampass | TheHacker | 6.3.4.1.314 | 2009.04.26 | - | TrendMicro | 8.700.0.1004 | 2009.04.25 | Possible_Mlwr-13 | VBA32 | 3.12.10.3 | 2009.04.25 | suspected of Win32.BrokenEmbeddedSignature (paranoid heuristics) | ViRobot | 2009.4.24.1708 | 2009.04.24 | - | VirusBuster | 4.6.5.0 | 2009.04.25 | - |
附加信息 | File size: 42504 bytes | MD5...: 4f1f91928052bebdc010663f3151952f | SHA1..: a0def9660ad0ac5441d5fa3fba18d13dadf9fd8f | SHA256: f9233921a0b8aa2791f584cd81bbbc09c5c20bb47ed27c7c1f64bbe35842f76a | SHA512: 29e9645124aa42d16388df965f9c28174143ec208e96dfa4e94dd2b34e250bc5
08779c009434c47b22774e7f269bb487a3157db834d4f435efbc5dc0d8455598 | ssdeep: 768:NqDBa85DYmUqNLMAlHswFKuiJTudHoFHpIcz6UYLi2TT4w0Pj6:UYoYmUSLM
OscKDJCdHCH/69ZT4I
| PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser | TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%) | PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1be80
timedatestamp.....: 0x49f1b77d (Fri Apr 24 12:58:37 2009)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x12000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x13000 0xa000 0x9200 7.88 bc904694ccdce0e79ecaf920102e7c1a
.rsrc 0x1d000 0x1000 0x600 3.09 52ea5891c8b2ad2f4e8b5d77cf5248fe
( 4 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: OpenServiceA
> SHELL32.dll: ShellExecuteA
> USER32.dll: wsprintfA
( 0 exports )
| PDFiD.: - | RDS...: NSRL Reference Data Set
- | packers (Kaspersky): PE_Patch.UPX, UPX | packers (Avast): UPX | packers (F-Prot): UPX |
[ 本帖最后由 yhjtj 于 2009-4-26 22:34 编辑 ] |