本帖最后由 191196846 于 2018-6-7 21:49 编辑
06 07 21:35
Samples(19/20) + M(20/20) = Total(39/40)
17号 有效数签,正在分析中
=======================
初步分析结果:Backdoor
- 2018/6/7, 21:34:31 [Real-Time Protection] Malware found
- The pattern of 'TR/Dropper.Gen [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(20).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:34:26 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Emotet.B (Cloud) [TR/AD.Emotet.B]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(19).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:34:20 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(18).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:34:16 [Real-Time Protection] Malware found
- The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(17).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:34:09 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.LockyC.Y (Cloud) [TR/AD.LockyC.Y]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(16).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:34:02 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.XPACK.04918b (Cloud) [TR/Crypt.XPACK.04918b]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(15).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:56 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.Agent.14b672 (Cloud) [TR/Crypt.Agent.14b672]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(14).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:53 [Real-Time Protection] Malware found
- The pattern of 'TR/Injector.664dc6 (Cloud) [TR/Injector.664dc6]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(13).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:47 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.ZPACK.9103b0 (Cloud) [TR/Crypt.ZPACK.9103b0]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(12).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:43 [Real-Time Protection] Malware found
- The pattern of 'HEUR/AGEN.1026215 [heuristic]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(11).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:35 [Real-Time Protection] Malware found
- The pattern of 'TR/Spy.KeyLogger.b1a309 (Cloud) [TR/Spy.KeyLogger.b1a309]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(9).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:29 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.XPACK.468373 (Cloud) [TR/Crypt.XPACK.468373]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(8).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:25 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.ZPACK.Gen [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(7).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:33:19 [Real-Time Protection] Malware found
- The pattern of 'TR/Spy.KeyLogger.5ad16b (Cloud) [TR/Spy.KeyLogger.5ad16b]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(6).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:32:59 [Real-Time Protection] Malware found
- The pattern of 'HEUR/AGEN.1006442 [heuristic]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(4).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:32:55 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.ZPACK.Gen [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(3).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:32:52 [Real-Time Protection] Malware found
- The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(1).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:32:45 [Real-Time Protection] Malware found
- The pattern of 'TR/Dropper.MSIL.8f561d (Cloud) [TR/Dropper.MSIL.8f561d]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(20).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:32:38 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.ZPACK.AF (Cloud) [TR/Crypt.ZPACK.AF]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(19).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:32:33 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(18).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:30:27 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.XPACK.7f9ced (Cloud) [TR/Crypt.XPACK.7f9ced]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(16).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:30:21 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.XPACK.KV (Cloud) [TR/Crypt.XPACK.KV]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(15).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:30:15 [Real-Time Protection] Malware found
- The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(14).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:30:08 [Real-Time Protection] Malware found
- The pattern of 'TR/Injector.5a5665 (Cloud) [TR/Injector.5a5665]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(13).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:30:02 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(12).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:29:56 [Real-Time Protection] Malware found
- The pattern of 'HEUR/AGEN.1026215 [heuristic]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(11).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:29:50 [Real-Time Protection] Malware found
- The pattern of 'HEUR/APC.Griffin (Cloud) [HEUR/APC.Griffin]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(9).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:29:21 [Real-Time Protection] Malware found
- The pattern of 'TR/Crypt.XPACK.47d194 (Cloud) [TR/Crypt.XPACK.47d194]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(8).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:29:14 [Real-Time Protection] Malware found
- The pattern of 'TR/Dropper.VB.6c8f72 (Cloud) [TR/Dropper.VB.6c8f72]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(7).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:29:08 [Real-Time Protection] Malware found
- The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(6).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:29:02 [Real-Time Protection] Malware found
- The pattern of 'HEUR/AGEN.1006442 [heuristic]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(4).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:56 [Real-Time Protection] Malware found
- The pattern of 'HEUR/AGEN.1004819 [heuristic]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(3).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:52 [Real-Time Protection] Malware found
- The pattern of 'PUA/BitcoinMiner (Cloud) [PUA/BitcoinMiner]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(1).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:26 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Emotet.P [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(2).exe'.
- Action performed: Delete file
- User SID: S-1-5-18
- 2018/6/7, 21:28:25 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.MalwareCrypter.szlbt [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(5).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:25 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Emotet.P [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(2).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:23 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.MalwareCrypter.hoplm [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(10).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:23 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.MalwareCrypter.szlbt [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(5).exe'.
- Action performed: Delete file
- User SID: S-1-5-18
- 2018/6/7, 21:28:22 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Emotet.P [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(2).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.MalwareCrypter.hoplm [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(10).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.MalwareCrypter.hoplm [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(10).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.Emotet.P [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(2).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
- 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
- The pattern of 'TR/AD.MalwareCrypter.szlbt [trojan]'
- detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(5).exe'.
- Action performed: Delete file
- User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
复制代码
|