楼主: Jerry.Lin
收起左侧

[病毒样本] #PACKAGE 0618

  [复制链接]
ELOHIM
发表于 2018-6-18 22:27:37 | 显示全部楼层
不测了,打不开。。
无法显示此网页
错误代码: ERR_CONNECTION_TIMED_OUT

反正微软也就是那N样。
Jerry.Lin
 楼主| 发表于 2018-6-18 22:33:43 | 显示全部楼层
本帖最后由 191196846 于 2018-6-18 22:38 编辑

22:34

26/26  100%


  1. 2018/6/18, 22:37:13 [Real-Time Protection] Malware found
  2.         The pattern of 'TR/Crypt.Agent.856e75 (Cloud) [TR/Crypt.Agent.856e75]'
  3.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(26).exe'.
  4.         Action performed: Delete file
  5.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  6. 2018/6/18, 22:36:55 [Real-Time Protection] Malware found
  7.         The pattern of 'TR/Dropper.VB.Gen (Cloud) [TR/Dropper.VB.Gen]'
  8.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(22).exe'.
  9.         Action performed: Delete file
  10.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  11. 2018/6/18, 22:36:41 [Real-Time Protection] Malware found
  12.         The pattern of 'TR/Dropper.VB.dd585b (Cloud) [TR/Dropper.VB.dd585b]'
  13.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(21).exe'.
  14.         Action performed: Delete file
  15.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  16. 2018/6/18, 22:33:19 [Real-Time Protection] Malware found
  17.         The pattern of 'TR/Dropper.Gen [trojan]'
  18.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(24).exe'.
  19.         Action performed: Delete file
  20.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  21. 2018/6/18, 22:33:14 [Real-Time Protection] Malware found
  22.         The pattern of 'TR/Crypt.XPACK.Gen [trojan]'
  23.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(23).exe'.
  24.         Action performed: Delete file
  25.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  26. 2018/6/18, 22:33:01 [Real-Time Protection] Malware found
  27.         The pattern of 'TR/Dropper.MSIL.5a5c53 (Cloud) [TR/Dropper.MSIL.5a5c53]'
  28.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(20).exe'.
  29.         Action performed: Delete file
  30.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  31. 2018/6/18, 22:32:45 [Real-Time Protection] Malware found
  32.         The pattern of 'TR/Dropper.Gen [trojan]'
  33.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(19).exe'.
  34.         Action performed: Delete file
  35.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  36. 2018/6/18, 22:32:40 [Real-Time Protection] Malware found
  37.         The pattern of 'DR/AutoIt.Gen (Cloud) [DR/AutoIt.Gen]'
  38.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(18).exe'.
  39.         Action performed: Delete file
  40.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  41. 2018/6/18, 22:32:18 [Real-Time Protection] Malware found
  42.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  43.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(17).exe'.
  44.         Action performed: Delete file
  45.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  46. 2018/6/18, 22:32:02 [Real-Time Protection] Malware found
  47.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  48.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(16).exe'.
  49.         Action performed: Delete file
  50.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  51. 2018/6/18, 22:31:43 [Real-Time Protection] Malware found
  52.         The pattern of 'TR/Crypt.EPACK.Gen8 (Cloud) [TR/Crypt.EPACK.Gen8]'
  53.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(15).exe'.
  54.         Action performed: Delete file
  55.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  56. 2018/6/18, 22:31:27 [Real-Time Protection] Malware found
  57.         The pattern of 'TR/Dropper.Gen [trojan]'
  58.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(14).exe'.
  59.         Action performed: Delete file
  60.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  61. 2018/6/18, 22:31:21 [Real-Time Protection] Malware found
  62.         The pattern of 'TR/Dropper.MSIL.Gen [trojan]'
  63.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(13).exe'.
  64.         Action performed: Delete file
  65.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  66. 2018/6/18, 22:31:17 [Real-Time Protection] Malware found
  67.         The pattern of 'TR/Crypt.XPACK.Gen [trojan]'
  68.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(12).exe'.
  69.         Action performed: Delete file
  70.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  71. 2018/6/18, 22:31:12 [Real-Time Protection] Malware found
  72.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  73.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(11).exe'.
  74.         Action performed: Delete file
  75.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  76. 2018/6/18, 22:30:56 [Real-Time Protection] Malware found
  77.         The pattern of 'TR/Dropper.Gen [trojan]'
  78.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(9).exe'.
  79.         Action performed: Delete file
  80.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  81. 2018/6/18, 22:30:49 [Real-Time Protection] Malware found
  82.         The pattern of 'TR/Dropper.VB.b70691 (Cloud) [TR/Dropper.VB.b70691]'
  83.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(8).exe'.
  84.         Action performed: Delete file
  85.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  86. 2018/6/18, 22:30:30 [Real-Time Protection] Malware found
  87.         The pattern of 'TR/Crypt.EPACK.Gen8 (Cloud) [TR/Crypt.EPACK.Gen8]'
  88.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(7).exe'.
  89.         Action performed: Delete file
  90.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  91. 2018/6/18, 22:30:13 [Real-Time Protection] Malware found
  92.         The pattern of 'DR/Delphi.Gen (Cloud) [DR/Delphi.Gen]'
  93.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(6).exe'.
  94.         Action performed: Delete file
  95.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  96. 2018/6/18, 22:29:56 [Real-Time Protection] Malware found
  97.         The pattern of 'HEUR/AGEN.1006332 [heuristic]'
  98.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(5).exe'.
  99.         Action performed: Delete file
  100.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  101. 2018/6/18, 22:29:50 [Real-Time Protection] Malware found
  102.         The pattern of 'TR/Crypt.XPACK.113879 (Cloud) [TR/Crypt.XPACK.113879]'
  103.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(3).exe'.
  104.         Action performed: Delete file
  105.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  106. 2018/6/18, 22:29:28 [Real-Time Protection] Malware found
  107.         The pattern of 'HEUR/AGEN.1022244 [heuristic]'
  108.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(1).exe'.
  109.         Action performed: Delete file
  110.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  111. 2018/6/18, 22:29:18 [Real-Time Protection] Malware found
  112.         The pattern of 'TR/Hijacker.A.31 [trojan]'
  113.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(4).exe'.
  114.         Action performed: Delete file
  115.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  116. 2018/6/18, 22:29:17 [Real-Time Protection] Malware found
  117.         The pattern of 'TR/Hijacker.A.31 [trojan]'
  118.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(4).exe'.
  119.         Action performed: Delete file
  120.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  121. 2018/6/18, 22:29:17 [Real-Time Protection] Malware found
  122.         The pattern of 'TR/Crypt.Agent.xmyxf [trojan]'
  123.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(25).exe'.
  124.         Action performed: Delete file
  125.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  126. 2018/6/18, 22:29:17 [Real-Time Protection] Malware found
  127.         The pattern of 'TR/Crypt.Agent.xmyxf [trojan]'
  128.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(25).exe'.
  129.         Action performed: Delete file
  130.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  131. 2018/6/18, 22:29:16 [Real-Time Protection] Malware found
  132.         The pattern of 'TR/AD.Nanocore.lpmcs [trojan]'
  133.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(2).exe'.
  134.         Action performed: Delete file
  135.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  136. 2018/6/18, 22:29:16 [Real-Time Protection] Malware found
  137.         The pattern of 'TR/AD.Nanocore.lpmcs [trojan]'
  138.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(2).exe'.
  139.         Action performed: Delete file
  140.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  141. 2018/6/18, 22:29:16 [Real-Time Protection] Malware found
  142.         The pattern of 'TR/Agent.bzigz [trojan]'
  143.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(10).exe'.
  144.         Action performed: Delete file
  145.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  146. 2018/6/18, 22:29:15 [Real-Time Protection] Malware found
  147.         The pattern of 'TR/Agent.bzigz [trojan]'
  148.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 0618\(10).exe'.
  149.         Action performed: Delete file
  150.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

复制代码

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
星猫
发表于 2018-6-18 22:42:48 | 显示全部楼层
WD 2018/06/18 22:42
23/26

评分

参与人数 1人气 +1 收起 理由
ELOHIM + 1 感谢解答: )

查看全部评分

aice7837
发表于 2018-6-18 22:52:19 | 显示全部楼层
kis18
扫描之后剩7、11、12、15、16、17、19、23
双击杀12、16、17、23
15重启后本体还在
momng
发表于 2018-6-18 22:54:33 | 显示全部楼层

楼主,附件的是什么类型的毒?基本没出现什么异常,都是防火墙在拦截,什么样的现象才是被过了。




www-tekeze
发表于 2018-6-18 23:01:56 | 显示全部楼层
火绒  06/18  23:00
Samples(7/26)   27%
  

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
cnDaming
发表于 2018-6-18 23:06:22 | 显示全部楼层
这毒猛的一批啊。。。。
Avira Pro右键扫直接当场去世,自动防护全关,难道是小红伞的bug?
Jerry.Lin
 楼主| 发表于 2018-6-18 23:12:19 | 显示全部楼层
momng 发表于 2018-6-18 22:54
楼主,附件的是什么类型的毒?基本没出现什么异常,都是防火墙在拦截,什么样的现象才是被过了。
...

一般都是Inject,downloader, backdoor 之类 隐蔽性极高的Mal


挺常见的,要不然现在病毒还跟你明摆跟你说“中毒”了?都是玩暗的,没有ARK工具很难看出异常
Jerry.Lin
 楼主| 发表于 2018-6-18 23:13:18 | 显示全部楼层
cnDaming 发表于 2018-6-18 23:06
这毒猛的一批啊。。。。
Avira Pro右键扫直接当场去世,自动防护全关,难道是小红伞的bug?

一般不会吧

我都是双击的

云不稳定?
=================
如果是中文版的话,挺正常的

建议用Eng
aice7837
发表于 2018-6-18 23:14:40 | 显示全部楼层

eis双击剩余4个样本之后,杀了18衍生物

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-25 14:01 , Processed in 0.097876 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表