查看: 4048|回复: 32
收起左侧

[病毒样本] #PACKAGE 0618

  [复制链接]
Jerry.Lin
发表于 2018-6-18 21:41:28 | 显示全部楼层 |阅读模式
本帖最后由 191196846 于 2018-6-18 22:05 编辑

蓝奏


Total : 26

========================================
These products were tested before package released:

Windows Defender    5/26     17/26              System is infected
Qihoo 360 SD            14/26    22/26              System is clean
========================================


#勿传VT
#在样本有效期内(24小时),建议无需手动上报样本至厂商,便于其他人测试行为拦截,响应速度等
#样本序号以收集时间顺序排序,越大代表越接近现在时间


回帖格式建议

杀软名称 + 时间
查杀数量+查杀率


例如:
XXX 20:39
Samples(5/10) 50%

评分

参与人数 2人气 +2 收起 理由
petr0vic + 1 版区有你更精彩: )
B100D1E55 + 1 版区有你更happy: )

查看全部评分

WhiteCruel
发表于 2018-6-18 22:13:38 | 显示全部楼层
本帖最后由 WhiteCruel 于 2018-6-19 06:53 编辑

ESET 22:12

Samples(22/26)
84.6%

双击
11 miss,提示一分钟内将自动注销,出现一堆弹窗,大量占用内存,虚拟机直接崩溃了。。。
17 miss,在ProgramData释放flvin.exe(随机文件名)并运行,Eset无反应。(7小时后入库)
18 打开了一个docx,报Win32/Injector.Autoit.CZQ,随后AMS检测到MSIL/Autorun.Spy.Agent.AU蠕虫的变种,删除出错。(见下图)
20 运行需要.net 4,懒得装了。(更新:运行5分钟后Eset还是没反应)


难道这就是传说中的Eset发现病毒清除不掉吗?


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
B100D1E55 + 1

查看全部评分

YU2711
发表于 2018-6-18 22:21:02 | 显示全部楼层
本帖最后由 YU2711 于 2018-6-18 22:48 编辑

Norton   22:20

(19/26)

11SONAR.Heur.RGC!g111
13SONAR.Heuristic.170
15SONAR.Heuristic.170
17SONAR.Heuristic.170
18SONAR.SuspPE!gen32
20SONAR.Heuristic.170
26SONAR.Heuristic.170
Jerry.Lin
 楼主| 发表于 2018-6-18 22:33:43 | 显示全部楼层
本帖最后由 191196846 于 2018-6-18 22:38 编辑

22:34

26/26  100%


  1. 2018/6/18, 22:37:13 [Real-Time Protection] Malware found
  2.         The pattern of 'TR/Crypt.Agent.856e75 (Cloud) [TR/Crypt.Agent.856e75]'
  3.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(26).exe'.
  4.         Action performed: Delete file
  5.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  6. 2018/6/18, 22:36:55 [Real-Time Protection] Malware found
  7.         The pattern of 'TR/Dropper.VB.Gen (Cloud) [TR/Dropper.VB.Gen]'
  8.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(22).exe'.
  9.         Action performed: Delete file
  10.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  11. 2018/6/18, 22:36:41 [Real-Time Protection] Malware found
  12.         The pattern of 'TR/Dropper.VB.dd585b (Cloud) [TR/Dropper.VB.dd585b]'
  13.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(21).exe'.
  14.         Action performed: Delete file
  15.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  16. 2018/6/18, 22:33:19 [Real-Time Protection] Malware found
  17.         The pattern of 'TR/Dropper.Gen [trojan]'
  18.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(24).exe'.
  19.         Action performed: Delete file
  20.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  21. 2018/6/18, 22:33:14 [Real-Time Protection] Malware found
  22.         The pattern of 'TR/Crypt.XPACK.Gen [trojan]'
  23.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(23).exe'.
  24.         Action performed: Delete file
  25.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  26. 2018/6/18, 22:33:01 [Real-Time Protection] Malware found
  27.         The pattern of 'TR/Dropper.MSIL.5a5c53 (Cloud) [TR/Dropper.MSIL.5a5c53]'
  28.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(20).exe'.
  29.         Action performed: Delete file
  30.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  31. 2018/6/18, 22:32:45 [Real-Time Protection] Malware found
  32.         The pattern of 'TR/Dropper.Gen [trojan]'
  33.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(19).exe'.
  34.         Action performed: Delete file
  35.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  36. 2018/6/18, 22:32:40 [Real-Time Protection] Malware found
  37.         The pattern of 'DR/AutoIt.Gen (Cloud) [DR/AutoIt.Gen]'
  38.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(18).exe'.
  39.         Action performed: Delete file
  40.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  41. 2018/6/18, 22:32:18 [Real-Time Protection] Malware found
  42.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  43.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(17).exe'.
  44.         Action performed: Delete file
  45.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  46. 2018/6/18, 22:32:02 [Real-Time Protection] Malware found
  47.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  48.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(16).exe'.
  49.         Action performed: Delete file
  50.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  51. 2018/6/18, 22:31:43 [Real-Time Protection] Malware found
  52.         The pattern of 'TR/Crypt.EPACK.Gen8 (Cloud) [TR/Crypt.EPACK.Gen8]'
  53.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(15).exe'.
  54.         Action performed: Delete file
  55.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  56. 2018/6/18, 22:31:27 [Real-Time Protection] Malware found
  57.         The pattern of 'TR/Dropper.Gen [trojan]'
  58.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(14).exe'.
  59.         Action performed: Delete file
  60.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  61. 2018/6/18, 22:31:21 [Real-Time Protection] Malware found
  62.         The pattern of 'TR/Dropper.MSIL.Gen [trojan]'
  63.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(13).exe'.
  64.         Action performed: Delete file
  65.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  66. 2018/6/18, 22:31:17 [Real-Time Protection] Malware found
  67.         The pattern of 'TR/Crypt.XPACK.Gen [trojan]'
  68.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(12).exe'.
  69.         Action performed: Delete file
  70.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  71. 2018/6/18, 22:31:12 [Real-Time Protection] Malware found
  72.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  73.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(11).exe'.
  74.         Action performed: Delete file
  75.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  76. 2018/6/18, 22:30:56 [Real-Time Protection] Malware found
  77.         The pattern of 'TR/Dropper.Gen [trojan]'
  78.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(9).exe'.
  79.         Action performed: Delete file
  80.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  81. 2018/6/18, 22:30:49 [Real-Time Protection] Malware found
  82.         The pattern of 'TR/Dropper.VB.b70691 (Cloud) [TR/Dropper.VB.b70691]'
  83.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(8).exe'.
  84.         Action performed: Delete file
  85.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  86. 2018/6/18, 22:30:30 [Real-Time Protection] Malware found
  87.         The pattern of 'TR/Crypt.EPACK.Gen8 (Cloud) [TR/Crypt.EPACK.Gen8]'
  88.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(7).exe'.
  89.         Action performed: Delete file
  90.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  91. 2018/6/18, 22:30:13 [Real-Time Protection] Malware found
  92.         The pattern of 'DR/Delphi.Gen (Cloud) [DR/Delphi.Gen]'
  93.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(6).exe'.
  94.         Action performed: Delete file
  95.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  96. 2018/6/18, 22:29:56 [Real-Time Protection] Malware found
  97.         The pattern of 'HEUR/AGEN.1006332 [heuristic]'
  98.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(5).exe'.
  99.         Action performed: Delete file
  100.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  101. 2018/6/18, 22:29:50 [Real-Time Protection] Malware found
  102.         The pattern of 'TR/Crypt.XPACK.113879 (Cloud) [TR/Crypt.XPACK.113879]'
  103.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(3).exe'.
  104.         Action performed: Delete file
  105.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  106. 2018/6/18, 22:29:28 [Real-Time Protection] Malware found
  107.         The pattern of 'HEUR/AGEN.1022244 [heuristic]'
  108.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(1).exe'.
  109.         Action performed: Delete file
  110.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  111. 2018/6/18, 22:29:18 [Real-Time Protection] Malware found
  112.         The pattern of 'TR/Hijacker.A.31 [trojan]'
  113.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(4).exe'.
  114.         Action performed: Delete file
  115.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  116. 2018/6/18, 22:29:17 [Real-Time Protection] Malware found
  117.         The pattern of 'TR/Hijacker.A.31 [trojan]'
  118.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(4).exe'.
  119.         Action performed: Delete file
  120.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  121. 2018/6/18, 22:29:17 [Real-Time Protection] Malware found
  122.         The pattern of 'TR/Crypt.Agent.xmyxf [trojan]'
  123.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(25).exe'.
  124.         Action performed: Delete file
  125.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  126. 2018/6/18, 22:29:17 [Real-Time Protection] Malware found
  127.         The pattern of 'TR/Crypt.Agent.xmyxf [trojan]'
  128.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(25).exe'.
  129.         Action performed: Delete file
  130.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  131. 2018/6/18, 22:29:16 [Real-Time Protection] Malware found
  132.         The pattern of 'TR/AD.Nanocore.lpmcs [trojan]'
  133.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(2).exe'.
  134.         Action performed: Delete file
  135.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  136. 2018/6/18, 22:29:16 [Real-Time Protection] Malware found
  137.         The pattern of 'TR/AD.Nanocore.lpmcs [trojan]'
  138.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(2).exe'.
  139.         Action performed: Delete file
  140.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  141. 2018/6/18, 22:29:16 [Real-Time Protection] Malware found
  142.         The pattern of 'TR/Agent.bzigz [trojan]'
  143.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(10).exe'.
  144.         Action performed: Delete file
  145.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  146. 2018/6/18, 22:29:15 [Real-Time Protection] Malware found
  147.         The pattern of 'TR/Agent.bzigz [trojan]'
  148.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(10).exe'.
  149.         Action performed: Delete file
  150.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

复制代码

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aice7837
发表于 2018-6-18 22:52:19 | 显示全部楼层
kis18
扫描之后剩7、11、12、15、16、17、19、23
双击杀12、16、17、23
15重启后本体还在
aice7837
发表于 2018-6-18 23:14:40 | 显示全部楼层

eis双击剩余4个样本之后,杀了18衍生物

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
WhiteCruel
发表于 2018-6-19 02:52:52 | 显示全部楼层
双击360剩下的4个样本

11 miss,提示一分钟内将自动关机,出现一堆弹窗,大量占用内存,虚拟机直接崩溃
17 拦截添加启动项,衍生物报 HEUR/QVM20.1.EE21.Malware.Gen
20 运行10分钟无反应
26 拦截注入,放行后,衍生物报 QVM20.1.23A5.Malware.Gen

,就一个.
发表于 2018-6-19 03:18:21 | 显示全部楼层
迈克菲扫描杀13/26  时间2018年6月19日03:18:11

双击
1 报Real Protect-LS!d903218d5b00
2 报Real Protect-LS!ccabf6faf611
11 报Real Protect-LS!57bd651de7b6
12 报Real Protect-LS!08c9112b01a2
14 报Real Protect-LS!692d80bcdeb7
15 不报
16 报Real Protect-EC!BAA1E2D63957
17 报Real Protect-LS!703d49cc79e6
19 报Real Protect-LS!03551eb6f1a9
20 报Real Protect-LS!1b82d29542db
21 报DAC/Suspect.0:0:3eb!30994a352de3
22 报DAC/Suspect.0:0:3eb!f4399923396a
23 报Real Protect-LS!49fdd6f527ba

ATP_synthase
发表于 2018-6-18 21:49:20 | 显示全部楼层
卡巴21:48
Samples(17/26)
挥泪斩情思
发表于 2018-6-18 21:52:08 | 显示全部楼层
本帖最后由 挥泪斩情思 于 2018-6-18 22:06 编辑

dr.web
11/26
zh7000047
发表于 2018-6-18 22:01:26 | 显示全部楼层
bd 扫描14/26
只求速度!
发表于 2018-6-18 22:08:13 | 显示全部楼层
趋势科技 22:08
4/26
只求速度!
发表于 2018-6-18 22:08:39 | 显示全部楼层
电脑管家 22:08
7/26
lambggy
发表于 2018-6-18 22:09:56 | 显示全部楼层
瑞星安全云 22:08
Samples(4/26) 15%

瑞星ML社区版 22:08
Samples(11/26) 42%

瑞星RDM+社区版 22:08
Samples(17/26) 65%
只求速度!
发表于 2018-6-18 22:19:52 | 显示全部楼层
本帖最后由 只求速度! 于 2018-6-18 22:23 编辑

360杀毒 22:19
19/26

金山 22:22
0/22



您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-27 13:34 , Processed in 0.152149 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表