楼主: rest1min
收起左侧

[病毒样本] 一个过卡巴等多数杀软的病毒

[复制链接]
woai_jolin
发表于 2008-2-16 13:09:45 | 显示全部楼层
终于看见多引擎上norman sandbox found
woai_jolin
发表于 2008-2-16 13:10:23 | 显示全部楼层
2008/2/16 13:07:50        Real-time file system protection        file        G:\v\mf.exe        probably unknown NewHeur_PE virus        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
woai_jolin
发表于 2008-2-16 13:15:45 | 显示全部楼层
Hello,

Thanks for taking the time to submit your samples to the Norman
Sandbox Information Center.  Customer delight is our top priority at
Norman.  With that in mind we have developed Sandbox Solutions for
organizations that are committed to speedy analysis and debugging.

Norman Sandbox Solutions give your organization the opportunity to
analyze files immediately in your own environment.

To find out how to bring the power of Norman Sandbox into your test
environments follow the links below.

Norman Sandbox Solutions
http://www.norman.com/Product/Sandbox-products/

Norman Sandbox Analyzer
http://www.norman.com/Product/Sandbox-products/Analyzer/

Norman Sandbox Analyzer Pro
http://www.norman.com/Product/Sandbox-products/Analyzer-pro/

Norman SandBox Reporter
http://www.norman.com/Product/Sandbox-products/Reporter/

mf.exe : INFECTED with W32/Downloader (Signature: NO_VIRUS)


[ DetectionInfo ]
    * Sandbox name: W32/Downloader
    * Signature name: NO_VIRUS
    * Compressed: NO
    * TLS hooks: YES
    * Executable type: Application
    * Executable file structure: OK

[ General information ]
    * Creating several executable files on hard-drive.
    * File length:        35298 bytes.
    * MD5 hash: 2f38e50f5d8a2f5cf12e8b08df58b809.

[ Changes to filesystem ]
    * Creates file C:\down.txt.
    * Creates file C:\new.exe.
    * Deletes file C:\new.exe.

[ Network services ]
    * Downloads file from http://www.hjiuy.com/j.txt as C:\down.txt.
    * Connects to "www.hjiuy.com" on port 80.
    * Opens URL: www.hjiuy.com/j.txt.
    * Downloads file from MZP as C:\new.exe.
    * Connects to "MZP" on port 80.
    * Opens URL: MZP/.
    * Downloads file from $7 as C:\new.exe.
    * Connects to "$7" on port 80.
    * Opens URL: $7/.
    * Downloads file from  as C:\new.exe.
    * Connects to "" on port 80.
    * Opens URL: /.
    * Downloads file from ñ* Á «±UÉ£(#4s?s3í¶ as C:\new.exe.
    * Connects to "ñ* Á «±UÉ£(#4s?s3í¶" on port 80.
    * Opens URL: ñ* Á «±UÉ£(#4s?s3í¶/.
    * Downloads file from &Aring;&Ntilde;+|"<&frac12; &macr;T.&cent;-R,'Iù&pound;?"B~.&frac34;. q&icirc;F~&Igrave;&Aacute;&cent;&Ograve;&aring;j>ùa$&Igrave; U&frac12;&laquo;&Euml;<á&ccedil;y&Ecirc;;+&acirc;E9&AElig;o&Uuml;&ouml;>&Agrave;&Ccedil;&Oslash; T:&aring;B&Egrave;h as C:\new.exe.
    * Connects to "&Aring;&Ntilde;+|"<&frac12; &macr;T.&cent;-R,'Iù&pound;?"B~.&frac34;. q&icirc;F~&Igrave;&Aacute;&cent;&Ograve;&aring;j>ùa$&Igrave; U&frac12;&laquo;&Euml;<á&ccedil;y&Ecirc;;+&acirc;E9&AElig;o&Uuml;&ouml;>&Agrave;&Ccedil;&Oslash; T:&aring;B&Egrave;h" on port 80.
    * Opens URL: &Aring;&Ntilde;+|"<&frac12; &macr;T.&cent;-R,'Iù&pound;?"B~.&frac34;. q&icirc;F~&Igrave;&Aacute;&cent;&Ograve;&aring;j>ùa$&Igrave; U&frac12;&laquo;&Euml;<á&ccedil;y&Ecirc;;+&acirc;E9&AElig;o&Uuml;&ouml;>&Agrave;&Ccedil;&Oslash; T:&aring;B&Egrave;h/.

[ Security issues ]
    * Starting downloaded file - potential security problem.

[ Process/window information ]
    * Creates process "C:\new.exe".

[ Signature Scanning ]
    * C:\down.txt (4096 bytes) : no signature detection.
    * C:\new.exe (8192 bytes) : no signature detection.



(C) 2004-2006 Norman ASA. All Rights Reserved.

The material presented is distributed by Norman ASA as an information source only.


************************************
Sent from an unmonitored email address.
Please DO NOT reply.
************************************
gho
发表于 2008-2-16 13:20:19 | 显示全部楼层
卡巴报了,咖啡miss
gho
发表于 2008-2-16 13:21:27 | 显示全部楼层
原帖由 woai_jolin 于 2008-2-16 13:09 发表
终于看见多引擎上norman sandbox found

支持哦,我只用过FS
啊弥陀佛
发表于 2008-2-16 13:27:01 | 显示全部楼层
啥都没做
woai_jolin
发表于 2008-2-16 13:32:48 | 显示全部楼层

回复 17楼 啊弥陀佛 的帖子

哪个网站估计要用代理才可以上
所以运行后这个病毒无法下载其他的病毒
said411f
发表于 2008-2-16 14:22:41 | 显示全部楼层
AVG 8.0 有报阿~~

"Scan started:";"2008年2月16日 星期六, 下午 02:18:17"
"Total object scanned:";"2"
"Time needed:";"less than one second"
"Errors encountered:";"0"

"Infections"
"File";"Infection";"Result"
"F:\mf.rar:\mf.exe";"Trojan horse Generic9.BBRD";"Moved to Virus Vault"
"F:\mf.rar";"Trojan horse Generic9.BBRD";"Moved to Virus Vault"
allinwonderi
发表于 2008-2-16 20:56:21 | 显示全部楼层
ArcaMicroScan 的确没报!
hlx98007
发表于 2008-2-16 22:13:39 | 显示全部楼层
deleted: Trojan program Trojan-Downloader.Win32.Delf.esm        File: C:\Virus\mf.rar/mf.exe//NeoLite
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-8 04:47 , Processed in 0.095507 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表