查看: 4895|回复: 22
收起左侧

[病毒样本] 精睿样本中找出来的敲诈类的病毒

[复制链接]
微光丶
发表于 2015-8-25 10:46:59 | 显示全部楼层 |阅读模式
本帖最后由 微光丶 于 2015-8-25 11:21 编辑

这俩都是母体文件
运行后释放出这个东西 名字是随机的 在c盘根目录
据说是2048算法加密

火眼连接:http://fireeye.ijinshan.com/anal ... 894&type=1#full

哈勃没查出来233333

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
微光丶
 楼主| 发表于 2015-8-25 10:49:37 | 显示全部楼层
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
What happened to your files ?
All of your files were protected by a strong encryption with RSA-2048.
More information about the encryption keys using RSA-2048 can be found here: http://en.wikipedia.org/wiki/RSA_(cryptosystem)

What does this mean ?
This means that the structure and data within your files have been irrevocably changed, you will not be able to work with them, read them or see them,
it is the same thing as losing them forever, but with our help, you can restore them.

How did this happen ?
Especially for you, on our server was generated the secret key pair RSA-2048 - public and private.
All your files were encrypted with the public key, which has been transferred to your computer via the Internet.
Decrypting of your files is only possible with the help of the private key and decrypt program, which is on our secret server.

What do I do ?
Alas, if you do not take the necessary measures for the specified time then the conditions for obtaining the private key will be changed.
If you really value your data, then we suggest you do not waste valuable time searching for other solutions because they do not exist.

For more specific instructions, please visit your personal home page, there are a few different addresses pointing to your page below:
1. http://awoeinf832as.wo49i277rnw.com/AAF4525D92B83331
2. http://nasdki39dawk.oj998fh4txkjh.com/AAF4525D92B83331
3. https://zpr5huq4bgmutfnf.onion.to/AAF4525D92B83331

If for some reasons the addresses are not available, follow these steps:
1. Download and install tor-browser: http://www.torproject.org/projects/torbrowser.html.en
2. After a successful installation, run the browser and wait for initialization.
3. Type in the address bar: zpr5huq4bgmutfnf.onion/AAF4525D92B83331
4. Follow the instructions on the site.

IMPORTANT INFORMATION:
Your personal pages:
http://awoeinf832as.wo49i277rnw.com/AAF4525D92B83331
http://nasdki39dawk.oj998fh4txkjh.com/AAF4525D92B83331
https://zpr5huq4bgmutfnf.onion.to/AAF4525D92B83331  
Your personal page (using TOR): zpr5huq4bgmutfnf.onion/AAF4525D92B83331
Your personal identification number (if you open the site (or TOR 's) directly): AAF4525D92B83331
steven_lzs
发表于 2015-8-25 10:50:14 | 显示全部楼层
EAV KILL
救命稻草
发表于 2015-8-25 10:53:20 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
pal家族
发表于 2015-8-25 10:54:35 | 显示全部楼层
本帖最后由 pal家族 于 2015-8-25 10:58 编辑

两个backdoor
一个p2p worm
我这里卡巴报毒不是ransom类的啊!!怎么回事???有用wd,eset的,发下报毒名好嘛?

[mw_shl_code=css,true]25.08.2015 10.53.42;Detected object (file) was deleted.;C:\Users\yingzhi\Downloads\yangben\09.exe;C:\Users\yingzhi\Downloads\yangben\09.exe;Backdoor.Win32.Farfli.zkf;Trojan program;08/25/2015 10:53:42
25.08.2015 10.53.42;Detected object (file) was deleted.;C:\Users\yingzhi\Downloads\yangben\17.exe;C:\Users\yingzhi\Downloads\yangben\17.exe;Backdoor.Win32.Farfli.zkf;Trojan program;08/25/2015 10:53:42
25.08.2015 10.54.58;Detected object (file) cannot be disinfected.;https://att.kafan.cn/forum.php?mo ... nk;Virus;08/25/2015 10:54:58
[/mw_shl_code]
断簪
发表于 2015-8-25 10:55:07 | 显示全部楼层
CryptWall
ericdj
发表于 2015-8-25 10:57:01 | 显示全部楼层
BD阻止下载

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
XywCloud
发表于 2015-8-25 10:58:34 | 显示全部楼层
BAV Kill all
Luca.l
发表于 2015-8-25 11:18:55 | 显示全部楼层
AVG MISS
aboringman
发表于 2015-8-25 11:20:13 | 显示全部楼层
NS 解压杀17.exe 和09.exe
释放出来的程序bmblzrtu.exe是安全的(信誉良好)
[mw_shl_code=css,true]Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2015-8-25 11:17:08,High,17.exe (Trojan.Dropper) detected by Auto-Protect,Blocked,Resolved - No Action Required
2015-8-25 11:17:08,High,09.exe (Trojan.Dropper) detected by Auto-Protect,Blocked,Resolved - No Action Required

[/mw_shl_code]

[mw_shl_code=css,true]Filename: bmblizrtu.exe
Full Path: C:\Documents and Settings\Administrator\桌面\bmblizrtu.exe

____________________________

____________________________


Developers 
Microsoft Corporation

Version 
5.1.2600.5512

Identified 
2015-8-25 at 11:16:48

Last Used 
2015-8-25 at 11:14:52

Startup Item 
No


____________________________


Many Users
Millions of users in the Norton Community have used this file.

Mature
This file was released 6 years ago.

Trusted
Norton has given this file a trusted rating.


____________________________


Source File:
winrar.exe

File Created:
bmblizrtu.exe

____________________________

Performance

____________________________

Avg. Resource Usage: Low
Avg. CPU Usage: Low
Avg. Memory Usage: Low

____________________________


File Thumbprint - SHA:
a26f4219815c297c705060b77595ef76e35e9e2bedbeb5afb3357cdc5ba2717f
File Thumbprint - MD5:
a5dd94434c702493d4577e966134b303
[/mw_shl_code]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-22 01:30 , Processed in 0.134989 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表