查看: 3809|回复: 39
收起左侧

[病毒样本] #PACKAGE 0607

  [复制链接]
Jerry.Lin
发表于 2018-6-7 21:15:31 | 显示全部楼层 |阅读模式
OneDrive
蓝奏


Total : 40 (20+20)

#勿传VT
#在样本有效期内(24小时),建议无需手动上报样本至厂商,便于其他人测试行为拦截,响应速度等
#样本序号以收集时间顺序排序,越大代表越接近现在时间


如 Modified Samples 报毒名与原样本有较大出入,则不计算在内。
行为防御检测计算在内
鼓励双击,结果置顶


回帖格式建议

杀软名称 + 时间

Samples查杀率 + M_Samples查杀率 = Total



例如:

XXXX  05 22 21:27

Samples(5/10) + M(3/10) = Total(8/20)  40%


----------------------------------------------
Second Scan 05 22 21:29

Samples(7/10) + M(3/10) = Total(10/20) 50%

评分

参与人数 1人气 +1 收起 理由
petr0vic + 1 赞一个!

查看全部评分

ELOHIM
发表于 2018-6-7 21:16:36 | 显示全部楼层
本帖最后由 ELOHIM 于 2018-6-7 21:32 编辑

SCEP  06/07  21:22
Samples(4/20) + M(3/20) = Total(7/40)  17.5%

丢人。
——————————————————————
SCEP  06/07  21:30

Samples(5/20) + M(3/20) = Total(7/40)  20%



Dust-;羅錠
发表于 2018-6-7 21:23:28 | 显示全部楼层
ESET
18/20+17/20=35/40

C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(10).exe - Win32/Kryptik.GHNP 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(11).exe > UPX v13_m8 > AUTOIT > script.bin - Win32/Injector.Autoit.DID 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(11).exe > AUTOIT > script.bin - Win32/Injector.Autoit.DID 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(12).exe - Win32/GenKryptik.CBWM 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(13).exe - Win32/Injector.CLNQ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(14).exe - Win32/Kryptik.GHNF 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(15).exe - Win32/Kryptik.GHNL 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(16).exe - Suspicious Object
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(19).exe - Win32/Emotet.BK 特洛伊木马
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(2).exe - Win32/Emotet.BK 特洛伊木马
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(20).exe - MSIL/Kryptik.OKJ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(3).exe - Win32/GenKryptik.BZRS 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(4).exe - MSIL/Kryptik.KPP 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(5).exe - Win32/Spy.Bebloh.O 特洛伊木马
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(6).exe - Win32/Spy.KeyLogger.QFB 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(7).exe - Win32/Injector.DYNC 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(8).exe - Win32/Kryptik.GHMZ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Modified Samples\(9).exe - Win32/Spy.KeyLogger.QFB 特洛伊木马 的变种


C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(1).exe - Generik.PWBELV 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(10).exe - Win32/Kryptik.GHNP 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(11).exe > UPX v13_m8 > AUTOIT > script.bin - Win32/Injector.Autoit.DID 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(11).exe > AUTOIT > script.bin - Win32/Injector.Autoit.DID 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(12).exe - Generik.DICZVSQ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(13).exe - Win32/Injector.CLNQ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(14).exe - Win32/Kryptik.GHNF 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(15).exe - Win32/Kryptik.GHNL 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(16).exe - Suspicious Object
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(19).exe - Win32/Emotet.BK 特洛伊木马
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(2).exe - Win32/Emotet.BK 特洛伊木马
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(20).exe - MSIL/Kryptik.OKJ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(3).exe - Win32/GenKryptik.BZRS 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(4).exe - MSIL/Kryptik.KPP 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(5).exe - Win32/Spy.Bebloh.O 特洛伊木马
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(6).exe - Win32/Spy.KeyLogger.QFB 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(7).exe - Win32/Injector.DYNC 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(8).exe - Win32/Kryptik.GHMZ 特洛伊木马 的变种
C:\Users\yilan\Downloads\PACKAGE 0607\Samples\(9).exe - Win32/Spy.KeyLogger.QFB 特洛伊木马 的变种


dongwenqi
发表于 2018-6-7 21:25:04 | 显示全部楼层
卡巴斯基
Samples(13/20) + M(2/20) = Total(15/40) 38%
Jerry.Lin
 楼主| 发表于 2018-6-7 21:26:54 | 显示全部楼层
dongwenqi 发表于 2018-6-7 21:25
卡巴斯基
Samples(13/20) + M(2/20) = Total(15/40) 38%

测双击吗
dongwenqi
发表于 2018-6-7 21:27:13 | 显示全部楼层

实机不测试双击
Jerry.Lin
 楼主| 发表于 2018-6-7 21:27:25 | 显示全部楼层
本帖最后由 191196846 于 2018-6-7 21:49 编辑

06 07 21:35

Samples(19/20) + M(20/20) = Total(39/40)

17号 有效数签,正在分析中
=======================
初步分析结果:Backdoor


  1. 2018/6/7, 21:34:31 [Real-Time Protection] Malware found
  2.         The pattern of 'TR/Dropper.Gen [trojan]'
  3.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(20).exe'.
  4.         Action performed: Delete file
  5.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  6. 2018/6/7, 21:34:26 [Real-Time Protection] Malware found
  7.         The pattern of 'TR/AD.Emotet.B (Cloud) [TR/AD.Emotet.B]'
  8.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(19).exe'.
  9.         Action performed: Delete file
  10.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  11. 2018/6/7, 21:34:20 [Real-Time Protection] Malware found
  12.         The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
  13.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(18).exe'.
  14.         Action performed: Delete file
  15.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  16. 2018/6/7, 21:34:16 [Real-Time Protection] Malware found
  17.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  18.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(17).exe'.
  19.         Action performed: Delete file
  20.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  21. 2018/6/7, 21:34:09 [Real-Time Protection] Malware found
  22.         The pattern of 'TR/AD.LockyC.Y (Cloud) [TR/AD.LockyC.Y]'
  23.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(16).exe'.
  24.         Action performed: Delete file
  25.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  26. 2018/6/7, 21:34:02 [Real-Time Protection] Malware found
  27.         The pattern of 'TR/Crypt.XPACK.04918b (Cloud) [TR/Crypt.XPACK.04918b]'
  28.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(15).exe'.
  29.         Action performed: Delete file
  30.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  31. 2018/6/7, 21:33:56 [Real-Time Protection] Malware found
  32.         The pattern of 'TR/Crypt.Agent.14b672 (Cloud) [TR/Crypt.Agent.14b672]'
  33.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(14).exe'.
  34.         Action performed: Delete file
  35.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  36. 2018/6/7, 21:33:53 [Real-Time Protection] Malware found
  37.         The pattern of 'TR/Injector.664dc6 (Cloud) [TR/Injector.664dc6]'
  38.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(13).exe'.
  39.         Action performed: Delete file
  40.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  41. 2018/6/7, 21:33:47 [Real-Time Protection] Malware found
  42.         The pattern of 'TR/Crypt.ZPACK.9103b0 (Cloud) [TR/Crypt.ZPACK.9103b0]'
  43.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(12).exe'.
  44.         Action performed: Delete file
  45.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  46. 2018/6/7, 21:33:43 [Real-Time Protection] Malware found
  47.         The pattern of 'HEUR/AGEN.1026215 [heuristic]'
  48.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(11).exe'.
  49.         Action performed: Delete file
  50.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  51. 2018/6/7, 21:33:35 [Real-Time Protection] Malware found
  52.         The pattern of 'TR/Spy.KeyLogger.b1a309 (Cloud) [TR/Spy.KeyLogger.b1a309]'
  53.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(9).exe'.
  54.         Action performed: Delete file
  55.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  56. 2018/6/7, 21:33:29 [Real-Time Protection] Malware found
  57.         The pattern of 'TR/Crypt.XPACK.468373 (Cloud) [TR/Crypt.XPACK.468373]'
  58.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(8).exe'.
  59.         Action performed: Delete file
  60.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  61. 2018/6/7, 21:33:25 [Real-Time Protection] Malware found
  62.         The pattern of 'TR/Crypt.ZPACK.Gen [trojan]'
  63.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(7).exe'.
  64.         Action performed: Delete file
  65.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  66. 2018/6/7, 21:33:19 [Real-Time Protection] Malware found
  67.         The pattern of 'TR/Spy.KeyLogger.5ad16b (Cloud) [TR/Spy.KeyLogger.5ad16b]'
  68.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(6).exe'.
  69.         Action performed: Delete file
  70.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  71. 2018/6/7, 21:32:59 [Real-Time Protection] Malware found
  72.         The pattern of 'HEUR/AGEN.1006442 [heuristic]'
  73.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(4).exe'.
  74.         Action performed: Delete file
  75.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  76. 2018/6/7, 21:32:55 [Real-Time Protection] Malware found
  77.         The pattern of 'TR/Crypt.ZPACK.Gen [trojan]'
  78.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(3).exe'.
  79.         Action performed: Delete file
  80.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  81. 2018/6/7, 21:32:52 [Real-Time Protection] Malware found
  82.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  83.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(1).exe'.
  84.         Action performed: Delete file
  85.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  86. 2018/6/7, 21:32:45 [Real-Time Protection] Malware found
  87.         The pattern of 'TR/Dropper.MSIL.8f561d (Cloud) [TR/Dropper.MSIL.8f561d]'
  88.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(20).exe'.
  89.         Action performed: Delete file
  90.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  91. 2018/6/7, 21:32:38 [Real-Time Protection] Malware found
  92.         The pattern of 'TR/Crypt.ZPACK.AF (Cloud) [TR/Crypt.ZPACK.AF]'
  93.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(19).exe'.
  94.         Action performed: Delete file
  95.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  96. 2018/6/7, 21:32:33 [Real-Time Protection] Malware found
  97.         The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
  98.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(18).exe'.
  99.         Action performed: Delete file
  100.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  101. 2018/6/7, 21:30:27 [Real-Time Protection] Malware found
  102.         The pattern of 'TR/Crypt.XPACK.7f9ced (Cloud) [TR/Crypt.XPACK.7f9ced]'
  103.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(16).exe'.
  104.         Action performed: Delete file
  105.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  106. 2018/6/7, 21:30:21 [Real-Time Protection] Malware found
  107.         The pattern of 'TR/Crypt.XPACK.KV (Cloud) [TR/Crypt.XPACK.KV]'
  108.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(15).exe'.
  109.         Action performed: Delete file
  110.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  111. 2018/6/7, 21:30:15 [Real-Time Protection] Malware found
  112.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  113.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(14).exe'.
  114.         Action performed: Delete file
  115.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  116. 2018/6/7, 21:30:08 [Real-Time Protection] Malware found
  117.         The pattern of 'TR/Injector.5a5665 (Cloud) [TR/Injector.5a5665]'
  118.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(13).exe'.
  119.         Action performed: Delete file
  120.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  121. 2018/6/7, 21:30:02 [Real-Time Protection] Malware found
  122.         The pattern of 'TR/AD.Ursnif.Y (Cloud) [TR/AD.Ursnif.Y]'
  123.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(12).exe'.
  124.         Action performed: Delete file
  125.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  126. 2018/6/7, 21:29:56 [Real-Time Protection] Malware found
  127.         The pattern of 'HEUR/AGEN.1026215 [heuristic]'
  128.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(11).exe'.
  129.         Action performed: Delete file
  130.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  131. 2018/6/7, 21:29:50 [Real-Time Protection] Malware found
  132.         The pattern of 'HEUR/APC.Griffin (Cloud) [HEUR/APC.Griffin]'
  133.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(9).exe'.
  134.         Action performed: Delete file
  135.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  136. 2018/6/7, 21:29:21 [Real-Time Protection] Malware found
  137.         The pattern of 'TR/Crypt.XPACK.47d194 (Cloud) [TR/Crypt.XPACK.47d194]'
  138.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(8).exe'.
  139.         Action performed: Delete file
  140.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  141. 2018/6/7, 21:29:14 [Real-Time Protection] Malware found
  142.         The pattern of 'TR/Dropper.VB.6c8f72 (Cloud) [TR/Dropper.VB.6c8f72]'
  143.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(7).exe'.
  144.         Action performed: Delete file
  145.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  146. 2018/6/7, 21:29:08 [Real-Time Protection] Malware found
  147.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  148.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(6).exe'.
  149.         Action performed: Delete file
  150.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  151. 2018/6/7, 21:29:02 [Real-Time Protection] Malware found
  152.         The pattern of 'HEUR/AGEN.1006442 [heuristic]'
  153.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(4).exe'.
  154.         Action performed: Delete file
  155.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  156. 2018/6/7, 21:28:56 [Real-Time Protection] Malware found
  157.         The pattern of 'HEUR/AGEN.1004819 [heuristic]'
  158.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(3).exe'.
  159.         Action performed: Delete file
  160.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  161. 2018/6/7, 21:28:52 [Real-Time Protection] Malware found
  162.         The pattern of 'PUA/BitcoinMiner (Cloud) [PUA/BitcoinMiner]'
  163.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(1).exe'.
  164.         Action performed: Delete file
  165.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  166. 2018/6/7, 21:28:26 [Real-Time Protection] Malware found
  167.         The pattern of 'TR/AD.Emotet.P [trojan]'
  168.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(2).exe'.
  169.         Action performed: Delete file
  170.         User SID: S-1-5-18

  171. 2018/6/7, 21:28:25 [Real-Time Protection] Malware found
  172.         The pattern of 'TR/AD.MalwareCrypter.szlbt [trojan]'
  173.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(5).exe'.
  174.         Action performed: Delete file
  175.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  176. 2018/6/7, 21:28:25 [Real-Time Protection] Malware found
  177.         The pattern of 'TR/AD.Emotet.P [trojan]'
  178.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(2).exe'.
  179.         Action performed: Delete file
  180.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  181. 2018/6/7, 21:28:23 [Real-Time Protection] Malware found
  182.         The pattern of 'TR/AD.MalwareCrypter.hoplm [trojan]'
  183.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(10).exe'.
  184.         Action performed: Delete file
  185.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  186. 2018/6/7, 21:28:23 [Real-Time Protection] Malware found
  187.         The pattern of 'TR/AD.MalwareCrypter.szlbt [trojan]'
  188.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Modified Samples\(5).exe'.
  189.         Action performed: Delete file
  190.         User SID: S-1-5-18

  191. 2018/6/7, 21:28:22 [Real-Time Protection] Malware found
  192.         The pattern of 'TR/AD.Emotet.P [trojan]'
  193.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(2).exe'.
  194.         Action performed: Delete file
  195.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  196. 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
  197.         The pattern of 'TR/AD.MalwareCrypter.hoplm [trojan]'
  198.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(10).exe'.
  199.         Action performed: Delete file
  200.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  201. 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
  202.         The pattern of 'TR/AD.MalwareCrypter.hoplm [trojan]'
  203.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(10).exe'.
  204.         Action performed: Delete file
  205.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  206. 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
  207.         The pattern of 'TR/AD.Emotet.P [trojan]'
  208.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(2).exe'.
  209.         Action performed: Delete file
  210.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  211. 2018/6/7, 21:28:21 [Real-Time Protection] Malware found
  212.         The pattern of 'TR/AD.MalwareCrypter.szlbt [trojan]'
  213.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0607\Samples\(5).exe'.
  214.         Action performed: Delete file
  215.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001
复制代码



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
B100D1E55
发表于 2018-6-7 21:50:40 | 显示全部楼层
补充3楼ESET的检出
Samples剩余17和18,双击,其中17 AMS检出meterpreter,18是Ursnif

话说modified的17和原始的17是怎么回事,原始的17是漏洞文档然后modified 17是修改的衍生物?
www-tekeze
发表于 2018-6-7 21:54:23 | 显示全部楼层
火绒  06/07 21:55
Samples(4/20) + M(4/20) = Total(8/40)  
20%   


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Jerry.Lin
 楼主| 发表于 2018-6-7 22:00:22 | 显示全部楼层
B100D1E55 发表于 2018-6-7 21:50
补充3楼ESET的检出
Samples剩余17和18,双击,其中17 AMS检出meterpreter,18是Ursnif

是同一个样本呐……不是衍生物
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-26 21:37 , Processed in 0.134043 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表