查看: 4144|回复: 48
收起左侧

[病毒样本] 10S+10M(18.06.07)

  [复制链接]
petr0vic
发表于 2018-6-7 19:56:34 | 显示全部楼层 |阅读模式
天使的愤怒
发表于 2018-6-7 20:01:26 | 显示全部楼层
金山毒霸无法查杀
Jirehlov1234
发表于 2018-6-7 20:02:06 | 显示全部楼层
本帖最后由 Jirehlov1234 于 2018-6-8 06:46 编辑

kis18

9/10+m3/10=12/20

1.exe UDS:DangerousObject.Multi.Generic
2.exe UDS:DangerousObject.Multi.Generic
3.exe//# UDS:Trojan.Win32.Inject.sb
3.exe UDS:Trojan.Win32.Inject.sb
5.exe UDS:Trojan-Banker.Win32.Emotet.sb
6.exe UDS:DangerousObject.Multi.Generic
7.exe HEUR:Trojan.MSIL.Agent.gen
8.scr UDS:DangerousObject.Multi.Generic
9.exe Trojan-PSW.Win32.Fareit.ecjl
10.exe Backdoor.Win32.Androm.pzgv

m7.exe HEUR:Trojan.MSIL.Agent.gen
m9.exe HEUR:Trojan.Win32.Agent.gen
m10.exe HEUR:Trojan.Win32.Agent.gen

UDS全军覆没

===================
20:51
4.exe UDS:Trojan-Banker.Win32.Gozi.sb
21:34
m5.exe UDS:Trojan-Banker.Win32.Emotet.sb
4:18
m1.exe UDS:Trojan-Spy.Win32.Ursnif.sb
m4.exe UDS:Trojan-Banker.Win32.Gozi.sb
m6.exe UDS:Trojan-Ransom.Win32.GandCrypt.a6:19
m3.exe UDS:DangerousObject.Multi.Generic
m2.exe UDS:Trojan.Win32.Yakes.sb
m8.scr Trojan-PSW.Win32.Fareit.eclj







评分

参与人数 1人气 +1 收起 理由
dongwenqi + 1 版区有你更精彩: )

查看全部评分

petr0vic
 楼主| 发表于 2018-6-7 20:06:28 | 显示全部楼层
Bitdefender
S(3/10)+M(2/10)=5/20
杰伦J时代
发表于 2018-6-7 20:12:55 | 显示全部楼层

查杀一直这样,防御还行
天使的愤怒
发表于 2018-6-7 20:14:50 | 显示全部楼层
杰伦J时代 发表于 2018-6-7 20:12
查杀一直这样,防御还行

嗯,蛮扎心的,目前云响应了三个样本。
歌德塔大蜘蛛
发表于 2018-6-7 20:21:40 | 显示全部楼层
天使的愤怒 发表于 2018-6-7 20:14
嗯,蛮扎心的,目前云响应了三个样本。


看4楼,Bitdefender也是3个
cloud01
头像被屏蔽
发表于 2018-6-7 20:24:07 | 显示全部楼层
ESET
S(9/10)+M(8/10)=17/20
聆听落雨
发表于 2018-6-7 20:29:14 | 显示全部楼层
诺顿NS

S(2/10)+M(3/10)=5/20

Jerry.Lin
发表于 2018-6-7 20:35:01 | 显示全部楼层
本帖最后由 191196846 于 2018-6-7 20:47 编辑

  06 07 20:42

Samples(10/10) + M(10/10) = Total(20/20) 100%

几乎都是云报法,少有几个启发

谁敢与伞伞一战
  1. 2018/6/7, 20:39:51 [Real-Time Protection] Malware found
  2.         The pattern of 'TR/Injector.ee8829 (Cloud) [TR/Injector.ee8829]'
  3.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\10.exe'.
  4.         Action performed: Delete file
  5.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  6. 2018/6/7, 20:39:45 [Real-Time Protection] Malware found
  7.         The pattern of 'TR/Injector.15a700 (Cloud) [TR/Injector.15a700]'
  8.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\9.exe'.
  9.         Action performed: Delete file
  10.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  11. 2018/6/7, 20:39:41 [Real-Time Protection] Malware found
  12.         The pattern of 'TR/Crypt.ZPACK.Gen [trojan]'
  13.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\8.scr'.
  14.         Action performed: Delete file
  15.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  16. 2018/6/7, 20:39:36 [Real-Time Protection] Malware found
  17.         The pattern of 'TR/ATRAPS.Gen [trojan]'
  18.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\7.exe'.
  19.         Action performed: Delete file
  20.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  21. 2018/6/7, 20:39:30 [Real-Time Protection] Malware found
  22.         The pattern of 'TR/Crypt.ZPACK.d39803 (Cloud) [TR/Crypt.ZPACK.d39803]'
  23.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\6.exe'.
  24.         Action performed: Delete file
  25.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  26. 2018/6/7, 20:39:25 [Real-Time Protection] Malware found
  27.         The pattern of 'TR/Crypt.ZPACK.3297b5 (Cloud) [TR/Crypt.ZPACK.3297b5]'
  28.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\5.exe'.
  29.         Action performed: Delete file
  30.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  31. 2018/6/7, 20:39:18 [Real-Time Protection] Malware found
  32.         The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
  33.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\4.exe'.
  34.         Action performed: Delete file
  35.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  36. 2018/6/7, 20:39:12 [Real-Time Protection] Malware found
  37.         The pattern of 'TR/AD.Inject.Y (Cloud) [TR/AD.Inject.Y]'
  38.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\3.exe'.
  39.         Action performed: Delete file
  40.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  41. 2018/6/7, 20:39:06 [Real-Time Protection] Malware found
  42.         The pattern of 'TR/Dldr.Zurgop.170797 (Cloud) [TR/Dldr.Zurgop.170797]'
  43.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\2.exe'.
  44.         Action performed: Delete file
  45.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  46. 2018/6/7, 20:38:59 [Real-Time Protection] Malware found
  47.         The pattern of 'TR/Crypt.XPACK.75c53b (Cloud) [TR/Crypt.XPACK.75c53b]'
  48.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\10.exe'.
  49.         Action performed: Delete file
  50.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  51. 2018/6/7, 20:38:54 [Real-Time Protection] Malware found
  52.         The pattern of 'TR/Crypt.XPACK.3e3f46 (Cloud) [TR/Crypt.XPACK.3e3f46]'
  53.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\9.exe'.
  54.         Action performed: Delete file
  55.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  56. 2018/6/7, 20:38:49 [Real-Time Protection] Malware found
  57.         The pattern of 'TR/Dropper.VB.ab8cfb (Cloud) [TR/Dropper.VB.ab8cfb]'
  58.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\8.scr'.
  59.         Action performed: Delete file
  60.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  61. 2018/6/7, 20:38:42 [Real-Time Protection] Malware found
  62.         The pattern of 'TR/Dropper.MSIL.6124ee (Cloud) [TR/Dropper.MSIL.6124ee]'
  63.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\7.exe'.
  64.         Action performed: Delete file
  65.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  66. 2018/6/7, 20:38:36 [Real-Time Protection] Malware found
  67.         The pattern of 'TR/Crypt.ZPACK.6fa211 (Cloud) [TR/Crypt.ZPACK.6fa211]'
  68.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\6.exe'.
  69.         Action performed: Delete file
  70.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  71. 2018/6/7, 20:38:31 [Real-Time Protection] Malware found
  72.         The pattern of 'TR/Crypt.ZPACK.AF (Cloud) [TR/Crypt.ZPACK.AF]'
  73.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\5.exe'.
  74.         Action performed: Delete file
  75.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  76. 2018/6/7, 20:38:25 [Real-Time Protection] Malware found
  77.         The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
  78.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\4.exe'.
  79.         Action performed: Delete file
  80.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  81. 2018/6/7, 20:38:18 [Real-Time Protection] Malware found
  82.         The pattern of 'TR/Injector.5a5665 (Cloud) [TR/Injector.5a5665]'
  83.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\3.exe'.
  84.         Action performed: Delete file
  85.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  86. 2018/6/7, 20:38:12 [Real-Time Protection] Malware found
  87.         The pattern of 'TR/AD.SmokeLoader.35a532 (Cloud) [TR/AD.SmokeLoader.35a532]'
  88.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\2.exe'.
  89.         Action performed: Delete file
  90.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  91. 2018/6/7, 20:37:54 [Real-Time Protection] Malware found
  92.         The pattern of 'TR/AD.Ursnif.tbkts [trojan]'
  93.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\Modifed\1.exe'.
  94.         Action performed: Delete file
  95.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  96. 2018/6/7, 20:37:53 [Real-Time Protection] Malware found
  97.         The pattern of 'TR/AD.Ursnif.tbkts [trojan]'
  98.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\1.exe'.
  99.         Action performed: Delete file
  100.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  101. 2018/6/7, 20:37:53 [Real-Time Protection] Malware found
  102.         The pattern of 'TR/AD.Ursnif.tbkts [trojan]'
  103.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\topvcq\10\1.exe'.
  104.         Action performed: Delete file
  105.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

复制代码


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-24 20:58 , Processed in 0.141194 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表