查看: 4538|回复: 10
收起左侧

[可疑文件] 每日樣本

[复制链接]
东方妖妖梦
发表于 2016-4-20 04:47:18 | 显示全部楼层 |阅读模式

密碼:infected
已上報至AVIRA LAB

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
欧阳宣
头像被屏蔽
发表于 2016-4-20 05:03:25 | 显示全部楼层
norton miss
wjy19800315
发表于 2016-4-20 07:26:51 | 显示全部楼层
WD早晨07.26未报

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
数字无名
发表于 2016-4-20 08:22:32 | 显示全部楼层
本帖最后由 数字无名 于 2016-4-20 16:50 编辑

KFA miss
哈勃分析:

基本信息
文件名称:       
Jameco Electronics.doc
MD5:        c72c5265060460edf72711fcce1a52f0
文件类型:        Word
上传时间:        2016-04-20 16:48:47
出品公司:        N/A
版本:        N/A
壳或编译器信息:        N/A
子文件信息:       
Data /  bc84edc06f3c06e4fefca1c6e0d3d391 /  Unknown
WordDocument /  04d13753e74420efb244071ea07c37e3 /  Unknown
1Table /  2fd958533ee31dabc335bec3a9d6436d /  zip
ThisDocument /  486bc611520717e56151411dd1c038c2 /  Unknown
_VBA_PROJECT /  77708c58fa9cc8587dfade999607f6bb /  Unknown
WAvINgcc /  03d6e36911bd50961af9f5990672e83e /  Unknown
uExJnunD /  51cf49b9e38dd1b08297bac099e062fb /  Unknown
QnFEjE /  0838ba822cd404a66c70ce9ce343600b /  Unknown
[5]SummaryInformation /  595f7e024e1a8eb720317b9deaa04536 /  Unknown
[5]DocumentSummaryInformation /  c5e76327413ab128b716ba4b7515f7dd /  Unknown
__SRP_0 /  1247b268e02cfce08eeab5ee6c728f2e /  Unknown
__SRP_2 /  7ee1169fd06f7848092ec8777a200176 /  Unknown
__SRP_3 /  aa684a72bfd5edad86c66bf0f7acfa5d /  Unknown
o /  3fe0d6ab0f3b42c6ccfa8ac2065e8bdb /  Unknown
LTZERnOQeJWJH /  2aac6a1951f25e1deeab4759ed0b8a79 /  Unknown
mSKXHNusxP /  97d9c9c8e04fd56e0c17c72ac6978845 /  Unknown
cxolzW /  0df0e14ce9353643f324b01abbf23081 /  Unknown
dir /  fba5c1a93af9add08f1bde8e7eb78cc9 /  Unknown
f /  42645aea6e9b7785f87bc53b2b6f1bce /  Unknown
关键行为
行为描述:        检测自身是否被调试
详情信息:       
N/A
行为描述:        获取窗口截图信息
详情信息:       
Foreground window Info: HWND = 0x00000000, DC = 0x1601089f.
文件行为
行为描述:        创建文件
详情信息:       
C:\Users\Administrator\AppData\Local\Temp\~DF2BEF4ACCD4964334.TMP
C:\Users\Administrator\AppData\Roaming\Microsoft\Templates\~$Normal.dot
C:\Users\Administrator\AppData\Local\Temp\~DF7F024AFF2A76AFF5.TMP
C:\Users\Administrator\AppData\Local\%temp%\1461098693.792367.doc
C:\Users\Administrator\AppData\Local\Temp\~WRF0000.tmp
C:\Users\Administrator\AppData\Local\Temp\~DFD75B495CFB9A0065.TMP
C:\Users\Administrator\AppData\Local\Temp\VBE\MSForms.exd
C:\Users\Administrator\AppData\Roaming\Microsoft\Forms\WINWORD.box
C:\Users\Administrator\AppData\Local\Temp\~DFE26CB27B542A6AFF.TMP
C:\Users\Administrator\AppData\Local\Temp\~DF2F034893696073A5.TMP
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\b70c.LNK
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\EB93A6.LNK
C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\CUSTOM.DIC
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\~$CUSTOM.DIC
行为描述:        覆盖已有文件
详情信息:       
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Word11.pip
行为描述:        复制文件
详情信息:       
C:\PROGRA~2\MICROS~1\OFFICE\DATA\OPA11.BAK ---> C:\PROGRA~2\MICROS~1\OFFICE\DATA\opa11.dat
行为描述:        删除文件
详情信息:       
C:\Users\Administrator\AppData\Local\Temp\~DF2BEF4ACCD4964334.TMP
C:\Users\Administrator\AppData\Local\Temp\~DF7F024AFF2A76AFF5.TMP
C:\Users\Administrator\AppData\Local\Temp\~DFD75B495CFB9A0065.TMP
C:\Users\Administrator\AppData\Roaming\Microsoft\Forms\WINWORD.box
C:\Users\Administrator\AppData\Local\Temp\~DF2F034893696073A5.TMP
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\~$CUSTOM.DIC
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\CUSTOM.DIC
C:\Users\Administrator\AppData\Local\Temp\~DFE26CB27B542A6AFF.TMP
C:\Users\Administrator\AppData\Local\%temp%\1461098693.830001.doc
C:\Users\Administrator\AppData\Roaming\Microsoft\Templates\~$Normal.dot
C:\Users\Administrator\AppData\Local\Temp\~WRF0000.tmp
行为描述:        重命名文件
详情信息:       
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\~WRI0001 ---> C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\CUSTOM.DIC
行为描述:        修改文件内容
详情信息:       
C:\Users\Administrator\AppData\Roaming\Microsoft\Templates\~$Normal.dot ---> Offset = 0
C:\Users\Administrator\AppData\Roaming\Microsoft\Templates\~$Normal.dot ---> Offset = 54
C:\Users\Administrator\AppData\Local\%temp%\1461098693.820904.doc ---> Offset = 0
C:\Users\Administrator\AppData\Local\%temp%\1461098693.821228.doc ---> Offset = 54
C:\Users\Administrator\AppData\Local\Temp\VBE\MSForms.exd ---> Offset = 0
C:\Users\Administrator\AppData\Local\Temp\VBE\MSForms.exd ---> Offset = 4
C:\Users\Administrator\AppData\Local\Temp\VBE\MSForms.exd ---> Offset = 8
C:\Users\Administrator\AppData\Local\Temp\VBE\MSForms.exd ---> Offset = 12
C:\Users\Administrator\AppData\Local\Temp\VBE\MSForms.exd ---> Offset = 16
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\b70c.LNK ---> Offset = 0
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\index.dat ---> Offset = 28
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\EB93A6.LNK ---> Offset = 0
C:\Users\Administrator\AppData\Local\%temp%\1461098693.823838.doc ---> Offset = 0
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\~$CUSTOM.DIC ---> Offset = 0
C:\Users\Administrator\AppData\Roaming\Microsoft\Proof\~$CUSTOM.DIC ---> Offset = 54
注册表行为
行为描述:        修改注册表
详情信息:       
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\ki
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\MTTT
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\yj
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4080110900063D11C8EF10054038389C\Usage\WORDFiles
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4080110900063D11C8EF10054038389C\Usage\ProductFiles
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\1k
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4080110900063D11C8EF10054038389C\Usage\VBAFiles
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Common\ReviewCycle\ReviewToken
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery\26CDA\26CDA
\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{2080F232-A413-4CB3-82EE-7D4927004BF5}\2.0\
\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{2080F232-A413-4CB3-82EE-7D4927004BF5}\2.0\FLAGS\
\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{2080F232-A413-4CB3-82EE-7D4927004BF5}\2.0\0\win32\
\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{2080F232-A413-4CB3-82EE-7D4927004BF5}\2.0\HELPDIR\
\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}\
\REGISTRY\USER\S-*\Software\Microsoft\GDIPlus\FontCachePath
行为描述:        删除注册表键值
详情信息:       
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\yj
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\1k
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\ki
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery\26CDA\26CDA
\REGISTRY\USER\S-*\Software\Microsoft\Office\Common\Assistant\CurrAsstState
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\MTTT
行为描述:        删除注册表键
详情信息:       
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems\
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery\26CDA\
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery\
\REGISTRY\USER\S-*\Software\Microsoft\Office\11.0\Word\Resiliency\
其他行为
行为描述:        检测自身是否被调试
详情信息:       
N/A
行为描述:        创建互斥体
详情信息:       
Local\Mutex_MSOSharedMem
Local\Mso97SharedDg19211105606Mutex
Local\Mso97SharedDg20321105606Mutex
Global\MTX_MSO_Formal1_S-*
Global\MTX_MSO_AdHoc1_S-*
Local\Mso97SharedDg19521105606Mutex
Local\Mso97SharedDg19531105606Mutex
Local\Mso97SharedDg19541105606Mutex
Skd5yLHImeSCMutextCfgPersist_H_S-*
Local\Mso97SharedDg19551105606Mutex
OfficeAssistantStateMutex
KYIMEShareCachedData.MutexObject.Administrator
KYTransactionServer.MutexObject.Administrator
Local\SqmSysTray
DBWinMutex
行为描述:        隐藏指定窗口
详情信息:       
[Window,Class] = [,_WwB]
[Window,Class] = [,ComboLBox]
[Window,Class] = [iFazWZfOQHJ,ThunderDFrame]
[Window,Class] = [,DesignerWindow]
[Window,Class] = [UserForm1,ThunderDFrame]
[Window,Class] = [,Edit]
[Window,Class] = [,Button]
行为描述:        查找指定窗口
详情信息:       
NtUserFindWindowEx: [Class,Window] = [MSOBALLOON,]
NtUserFindWindowEx: [Class,Window] = [MsoHelp10,]
NtUserFindWindowEx: [Class,Window] = [AgentAnim,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [MsoHelp11,]
行为描述:        窗口信息
详情信息:       
Pid = 2520, Hwnd=0x11016e, Text = MsoDockTop, ClassName = MsoCommandBarDock.
行为描述:        获取窗口截图信息
详情信息:       
Foreground window Info: HWND = 0x00000000, DC = 0x1601089f.
行为描述:        创建事件对象
详情信息:       
EventName = OleDfRootCD12207E9FB6BA18
EventName = OleDfRoot1C6F4F599CEE5F78
EventName = OleDfRoot768C87A8AC4B170A
EventName = OleDfRootB0E25A5670E1D1D2
轩夏
发表于 2016-4-20 09:15:27 | 显示全部楼层
ESET MIss
狐狸糊涂
发表于 2016-4-20 09:24:40 | 显示全部楼层
BD显示安全

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
cfhdrty
发表于 2016-4-20 09:46:05 | 显示全部楼层
essmiss数字杀
pal家族
发表于 2016-4-20 13:14:50 | 显示全部楼层
Kaspersky
Scan result        File is infected
Found threats        HEUR:Trojan-Downloader.Script.Generic
File size        130.50KB
File type        OLE2/DOCUMENT
Date of scan        2016-04-20 13:14:01
Bases release date        2016-04-20 05:11:14 UTC
MD5        c72c5265060460edf72711fcce1a52f0
SHA1        047a726b04596db619258da90b4face86003aca2
SHA256
6e683b692360b3e333b57cf77429a23b0915e8dd4d1d20fed90e275918d23ae2
数字无名
发表于 2016-4-20 17:00:13 | 显示全部楼层
pal家族 发表于 2016-4-20 13:14
Kaspersky
Scan result        File is infected
Found threats        HEUR:Trojan-Downloader.Script.Generic

为什么我的卡巴没有报
pal家族
发表于 2016-4-20 17:59:31 | 显示全部楼层
数字无名 发表于 2016-4-20 17:00
为什么我的卡巴没有报

不是不报,只是时机未到
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 08:07 , Processed in 0.125468 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表