楼主: 驭龙
收起左侧

[病毒样本] 呼唤双击敢死队,谁来双击玩这个Zbot!GO 变种,切记,请不要实机测试

[复制链接]
a445441
发表于 2015-12-1 17:28:34 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aboringman
发表于 2015-12-1 18:47:14 | 显示全部楼层
AVG:

扫描:kill it.

"";"Trojan horse PSW.Generic12.TCT, c:\Users\Killer\Desktop\pdf.exe";"Healed, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:27:01"


双击:关闭监控,保留IDP,实机不入沙,等到行为差不多都出来后(Windows防火墙已提示时),IDP瞬间击杀。

"";"Unknown, C:\Users\Killer\AppData\Roaming\Ovrays\hyba.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\USERS\KILLER\DESKTOP\新建文件夹\PDF.EXE";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\taskhost.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\dwm.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Framework\Common\avguix.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\sandboxie\SbieCtrl.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\Advanced SystemCare\ASCTray.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\GWX\GWX.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\ctfmon.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\taskmgr.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\rundll32.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\dllhost.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\sandboxie\Start.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\7.1.1.812\360bdoctor.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\sandboxie\Start.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgui.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgcomdlgx.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgcomdlgx.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgcfgex.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\USERS\KILLER\APPDATA\LOCAL\TEMP\EBH2643.BAT";"Deleted";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\User Data\v3update\download\~TA516E.cab";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\User Data\v3update\download\~520A.cab";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\User Data\safemon\urllib.dat";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\dwm.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\Ovrays\hyba.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\HYBA";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/1, 18:30:33"


目测AVG没有被成功入侵(详见IDP拦截和回滚的行为列表),用PC Hunter看了一下,没有可疑启动项或驱动存在,防御成功。

@驭龙 上次测试清毒时关闭了所有防护,可能是因为这样AVG的UI被入侵成功的吧。。。。。。

评分

参与人数 2经验 +5 人气 +1 收起 理由
nick20010117 + 1 版区有你更精彩: )
wjy19800315 + 5 版区有你更精彩: )

查看全部评分

驭龙
 楼主| 发表于 2015-12-1 19:33:52 | 显示全部楼层

理论上AVG的主防驱动属于上等,确实是没那么容易漏,不过我个人还是不喜欢3A
aboringman
发表于 2015-12-1 19:35:36 | 显示全部楼层
驭龙 发表于 2015-12-1 19:33
理论上AVG的主防驱动属于上等,确实是没那么容易漏,不过我个人还是不喜欢3A

如果有选择的话,我也不想选。。。。。。
只是选择太少,稍后部署NS看看感不感冒。。。。。。
驭龙
 楼主| 发表于 2015-12-1 19:38:19 | 显示全部楼层
aboringman 发表于 2015-12-1 19:35
如果有选择的话,我也不想选。。。。。。
只是选择太少,稍后部署NS看看感不感冒。。。。。。

是NIS,不要安装NS,要不然无试用期

我还是继续ESS+Katana
aboringman
发表于 2015-12-1 19:40:40 | 显示全部楼层
驭龙 发表于 2015-12-1 19:38
是NIS,不要安装NS,要不然无试用期

我还是继续ESS+Katana

配合不错,已经足够,哈哈。
又得重下个安装包了。。。。。。
nick20010117
发表于 2015-12-1 22:02:18 | 显示全部楼层
aboringman 发表于 2015-12-1 19:40
配合不错,已经足够,哈哈。
又得重下个安装包了。。。。。。

其实NS有90天的安装包的
nick20010117
发表于 2015-12-1 22:03:18 | 显示全部楼层
本帖最后由 nick20010117 于 2015-12-1 22:10 编辑

@aboringman
FS的双击实在是比AVG无聊多了
修改MD5后双击

报毒名相当准确 @驭龙 @230f4

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
230f4 + 1 版区有你更精彩: )

查看全部评分

230f4
发表于 2015-12-1 22:05:44 | 显示全部楼层




双击,监控软件并未监控到衍生物的释放,防火墙无拦截日志,看来是ATC光速拦截了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
nick20010117 + 1 版区有你更精彩: )

查看全部评分

275751198
发表于 2015-12-1 22:23:18 | 显示全部楼层
类型:
感染型病毒(Win32/Trojan.Spy.ffc)

描述:
木马通常利用系统的漏洞,绕过系统防御,达到:盗取账号、窃取资料、篡改文件、破坏数据的目的。
经过360安全中心检验,此文件是木马,建议您立即处理。

扫描引擎:
360云查杀引擎

文件指纹(MD5):
c0473ce3fdffd109c3ffa6a97badcfcb
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-19 22:04 , Processed in 0.101522 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表