楼主: Jerry.Lin
收起左侧

[病毒样本] 【03.29】#VirusPackage 9x

[复制链接]
dongwenqi
发表于 2018-3-29 21:41:35 | 显示全部楼层

已经上报了
230f4
发表于 2018-3-29 21:45:46 | 显示全部楼层
bitdefender
(7).exe Trojan.GenericKD.30493380
(8).exe Gen:Suspicious.Cloud.1.gu0@aOrMNIei
(9).exe Gen:Suspicious.Cloud.1.gC0@aaWFMHoi
(1).exe Trojan.GenericKD.30487375
(2).exe Trojan.GenericKD.30485709
URL剩余
http://briandswings.com/98yuhGF??xhHeMKfxdT=xhHeMKfxdT


月影天心
发表于 2018-3-29 22:47:41 | 显示全部楼层
ELOHIM 发表于 2018-3-29 20:54
9个文件,8杀,剩下两个,多出来那个是什么啊?

我这儿WD还剩下2、3、4、6,怎么会杀掉8个?
欧阳宣
头像被屏蔽
发表于 2018-3-29 22:48:49 | 显示全部楼层
avira

链接拦截3x,其余右键全部检测
样本包解压后剩余45679,其他右键全部检测
  1. 03/29/2018,10-46-13        [INFO]        FP reports status 'NO False Positive' for file 'e:\virus\virus9x 0329\(4).exe'
  2. 03/29/2018,10-46-13        [INFO]        The file 'e:\virus\virus9x 0329\(4).exe' was scanned with the Protection Cloud. SHA256 = 64376EE88C462E518EFD8804AA5B35C445110944578F1F5C6291538C2FC812B0
  3. 03/29/2018,10-46-13        [INFO]        e:\virus\virus9x 0329\(4).exe
  4. 03/29/2018,10-46-13        [INFO]        [DETECTION] file contains 'TR/Dropper.MSIL.64376e'
  5. 03/29/2018,10-46-13        [INFO]        FP reports status 'NO False Positive' for file 'e:\virus\virus9x 0329\(5).exe'
  6. 03/29/2018,10-46-13        [INFO]        The file 'e:\virus\virus9x 0329\(5).exe' was scanned with the Protection Cloud. SHA256 = 5C16A23DCB92BD9DFA23315AA65F3FF3B29EDDF1D7B595158E9CC495EADA9F48
  7. 03/29/2018,10-46-13        [INFO]        e:\virus\virus9x 0329\(5).exe
  8. 03/29/2018,10-46-13        [INFO]        [DETECTION] file contains 'TR/AD.Sagonaire.5c16a2'
  9. 03/29/2018,10-46-14        [INFO]        FP reports status 'NO False Positive' for file 'e:\virus\virus9x 0329\(6).exe'
  10. 03/29/2018,10-46-14        [INFO]        The file 'e:\virus\virus9x 0329\(6).exe' was scanned with the Protection Cloud. SHA256 = 7A4101178ACCEC8DC269942DDC5F7048B2C1A925FBD2AFE15CD1CB21AD9D6B81
  11. 03/29/2018,10-46-14        [INFO]        AUC reports URL: http://briandswings.com/98yuhgf??xhhemkfxdt=xhhemkfxdt as 'Safe'.
  12. 03/29/2018,10-46-14        [INFO]        e:\virus\virus9x 0329\(6).exe
  13. 03/29/2018,10-46-14        [INFO]        [DETECTION] file contains 'TR/Spy.Nutrino.A'
  14. 03/29/2018,10-46-14        [INFO]        FP reports status 'NO False Positive' for file 'e:\virus\virus9x 0329\(7).exe'
  15. 03/29/2018,10-46-14        [INFO]        The file 'e:\virus\virus9x 0329\(7).exe' was scanned with the Protection Cloud. SHA256 = 5630E54E14F2A42FEAC50F07C4D00D6FB567F24B1C45B263AC6FE95F5B04802B
  16. 03/29/2018,10-46-14        [INFO]        e:\virus\virus9x 0329\(7).exe
  17. 03/29/2018,10-46-14        [INFO]        [DETECTION] file contains 'TR/AD.Emotet.B'
  18. 03/29/2018,10-46-15        [INFO]        FP reports status 'NO False Positive' for file 'e:\virus\virus9x 0329\(9).exe'
  19. 03/29/2018,10-46-15        [INFO]        The file 'e:\virus\virus9x 0329\(9).exe' was scanned with the Protection Cloud. SHA256 = 03CB2275A13861C5882CBD4E39C5B6234B5048FA65CE11EEB82278377A65DF43
  20. 03/29/2018,10-46-15        [INFO]        e:\virus\virus9x 0329\(9).exe
  21. 03/29/2018,10-46-15        [INFO]        [DETECTION] file contains 'HEUR/APC'

  22. 3/29/2018,10:42:16 [INFO] FP reports status 'NO False Positive' for file 'E:\virus\Virus9x 0329\(8).exe'
  23. 3/29/2018,10:42:16 [DETECTION] Is the TR/Crypt.Xpack.ryydf Trojan!
  24.   E:\virus\Virus9x 0329\(8).exe
  25. 3/29/2018,10:42:16 [INFO] FP reports status 'NO False Positive' for file 'E:\virus\Virus9x 0329\(3).exe'
  26. 3/29/2018,10:42:16 [DETECTION] Is the TR/Dropper.VB.updpm Trojan!
  27.   E:\virus\Virus9x 0329\(3).exe
  28.       [INFO] The file will be copied to quarantine!
  29. 3/29/2018,10:42:16 [INFO] FP reports status 'NO False Positive' for file 'E:\virus\Virus9x 0329\(1).exe'
  30. 3/29/2018,10:42:16 [DETECTION] Is the TR/AD.Ursnif.sgcmf Trojan!
  31.   E:\virus\Virus9x 0329\(1).exe
  32. 3/29/2018,10:42:16 [INFO] FP reports status 'NO False Positive' for file 'E:\virus\Virus9x 0329\(2).exe'
  33. 3/29/2018,10:42:16 [DETECTION] Is the TR/RedCap.ulxil Trojan!

  34. 3/29/2018,10:39:30 [DETECTION] Malware found.
  35.          URL: http://paowoeqkwenksdqwd.com/NOIT/testv.php?l=eneken7.class
  36.          Is the TR/AD.Ursnif.sgcmf Trojan
  37.          Executed action: Blocked file
  38. 3/29/2018,10:39:38 [DETECTION] [18508085] The URL (http://78.128.92.109/order.exe) was detected as Malware(c). It was blocked
  39. 3/29/2018,10:39:49 [DETECTION] [18508094] The URL (http://www.speeltuingeenhoven.nl/gs0CKwR/) was detected as Malware(c). It was blocked
复制代码


chengleok
发表于 2018-3-29 23:12:16 | 显示全部楼层
ELOHIM 发表于 2018-3-29 20:54
9个文件,8杀,剩下两个,多出来那个是什么啊?

可能是我表达错了,我的意思是剩下文件名为2的文件
Jerry.Lin
 楼主| 发表于 2018-3-29 23:14:20 | 显示全部楼层
本帖最后由 191196846 于 2018-3-29 23:18 编辑
月影天心 发表于 2018-3-29 22:47
我这儿WD还剩下2、3、4、6,怎么会杀掉8个?

我这边WD还剩下3,4,6

(2)PUA:Win32/Creprote
(5)Trojan:Win32/Cloxer.D!cl  
(7)Trojan:Win32/Woreflint.A!cl
(9)Trojan:Win32/Fuerboos.A!cl
(1)(8)Trojan:Win32/Tiggre!plock

@驭龙 WD的云有参与文件监控吗?我发现我解压后没有云杀(有本地),右键扫描后就有云杀了。
@ELOHIM



月影天心
发表于 2018-3-29 23:20:57 | 显示全部楼层
本帖最后由 月影天心 于 2018-3-29 23:22 编辑
191196846 发表于 2018-3-29 23:14
我这边WD还剩下3,4,6

(2)PUA:Win32/Creprote

监控有云杀的
好奇怪,我这边第2个,WD无论是监控还是扫描,都不报
看你的报毒名,PUA,是不是你改过WD组策略了?
WCMS
发表于 2018-3-29 23:21:14 | 显示全部楼层
SEP 9/9
Jerry.Lin
 楼主| 发表于 2018-3-29 23:24:41 | 显示全部楼层
月影天心 发表于 2018-3-29 23:20
监控有云杀的
好奇怪,我这边第2个,WD无论是监控还是扫描,都不报
看你的报毒名,PUA,是不是你改过WD ...

是的呢……

我的WD要右键扫描才有云杀……好烦
月影天心
发表于 2018-3-29 23:37:33 | 显示全部楼层
191196846 发表于 2018-3-29 23:24
是的呢……

我的WD要右键扫描才有云杀……好烦

我这边PUA WD很少报。。。
凑合着用吧,马上RS4要来了,WD 4.14要登场了,变化很大,到时候再看看
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-1 21:05 , Processed in 0.104226 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表