查看: 3381|回复: 15
收起左侧

[可疑文件] 一个神奇的文件~~

[复制链接]
New_Start.
发表于 2015-8-29 17:25:53 | 显示全部楼层 |阅读模式
偶尔发现的一东西,360压缩提示风险,第一次看到有这么多的签名,除了sha384那个被吊销之外,其他都是有效的,话说sha512又是神马东西,要这么高的强度干嘛~~ ,一开始还以为是没毒的呢,毕竟有这么多的签名嘛,但是我又觉得不保险就沙箱一下,结果这货在沙箱内表现得人畜无害,于是再试试企鹅的哈勃,结果无风险,嗯嗯,无风险,还88分,出于对企鹅的信任  。。。于是我就实机双击了。。事实证明企鹅的技术不咋的,这货表现得和沙箱时的截然不同,界面几秒后就消失了。。。 我知道坏事了~~TM的中标了~~~关键时刻还是sonar靠得住。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
MXCERILYF!
发表于 2015-8-29 17:31:55 | 显示全部楼层
本帖最后由 MXCERILYF! 于 2015-8-29 17:33 编辑

360TS

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
New_Start.
 楼主| 发表于 2015-8-29 17:33:26 | 显示全部楼层

为什么我的360不报
ELOHIM
发表于 2015-8-29 17:33:44 | 显示全部楼层
本帖最后由 ELOHIM 于 2015-8-29 17:35 编辑

signtool GUI.zip.exe  found no threats.
上报ing...不过,不知道双击会是什么样的party.
New_Start.
 楼主| 发表于 2015-8-29 17:36:49 | 显示全部楼层
ELOHIM 发表于 2015-8-29 17:33
signtool GUI.zip.exe  found no threats.
上报ing...不过,不知道双击会是什么样的party.

界面几秒后消失,病毒标配~~
电脑发烧友
发表于 2015-8-29 17:53:48 | 显示全部楼层
COMODO云端查询结果为需要提交的
水墨静音
发表于 2015-8-29 18:15:19 | 显示全部楼层
过ESS,过腾讯管家
aboringman
发表于 2015-8-29 18:25:18 | 显示全部楼层
NS:信誉不良,IPS也直接击杀
[mw_shl_code=css,true]Filename: signtool GUI.zip.exe
Full Path: C:\Documents and Settings\Administrator\桌面\signtool GUI.zip.exe

____________________________

____________________________


Developers 
Open Source Developer, 鏄撳彲绫

Version 
1.8.0.2

Identified 
2015-8-29 at 18:23:26

Last Used 
Not Available

Startup Item 
No


____________________________


Very Few Users
Fewer than 5 users in the Norton Community have used this file.

Very New
This file was released less than 1 week  ago.

Poor
There are some indications that this file is untrustworthy.


____________________________


Source File:
winrar.exe

File Created:
signtool gui.zip.exe

____________________________


File Thumbprint - SHA:
9bcb6531799b11e732c2da51fcf9c1afad26db55d1fec85e08f50134ac5cdaf2
File Thumbprint - MD5:
34c46ecb669b1f2b1a49fb03ecde5958
[/mw_shl_code]

[mw_shl_code=css,true]Filename: signtool gui.zip.exe
Threat name: WS.Reputation.1Full Path: c:\documents and settings\administrator\桌面\signtool gui.zip.exe

____________________________

____________________________


On computers as of 
2015-8-29 at 18:23:26

Last Used 
2015-8-29 at 18:24:37

Startup Item 
No

Launched 
No

Threat type: Insight Network Threat. There are many indications that this file is untrustworthy and therefore not safe


____________________________


signtool gui.zip.exe Threat name: WS.Reputation.1
Locate


Very Few Users
Fewer than 5 users in the Norton Community have used this file.

Very New
This file was released less than 1 week  ago.

Medium
This file risk is medium.


____________________________


Source: External Media

Source File:
winrar.exe

File Created:
signtool gui.zip.exe

____________________________

File Actions

File: c:\documents and settings\administrator\桌面\ signtool gui.zip.exe Removed
____________________________


File Thumbprint - SHA:
9bcb6531799b11e732c2da51fcf9c1afad26db55d1fec85e08f50134ac5cdaf2
File Thumbprint - MD5:
Not available
[/mw_shl_code]
paul_guo
发表于 2015-8-29 19:55:56 | 显示全部楼层
发给卡巴了
Luca.l
发表于 2015-8-29 20:12:20 | 显示全部楼层
FSCS12 MISS
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-21 16:44 , Processed in 0.152089 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表