查看: 2572|回复: 18
收起左侧

[病毒样本] #PACKAGE 0620

[复制链接]
Jerry.Lin
发表于 2018-6-20 21:24:21 | 显示全部楼层 |阅读模式
本帖最后由 191196846 于 2018-6-20 21:59 编辑

蓝奏


Total : 27

========================================
These products were tested before package released:

Products                        Pre-execute    Advanced block     Miss         Status

Windows Defender           20                        3                        4           Infected
Qihoo 360 SD                    21                        3                        3           Infected


Note: Pre-execute includes On-Access scan or exeute scan before malware is running on memory.
          Advanced block includes behavior block or other techiques that successufully terminate running malware.
          Miss includes situations: no any Alert or warning from AV software.
          Status means if there are any malicious items, including processes, images, drivers, autoruns, regs etc., on the current system, the system is infected; otherwise it is clean.

========================================


#勿传VT
#在样本有效期内(24小时),建议无需手动上报样本至厂商,便于其他人测试行为拦截,响应速度等
#样本序号以收集时间顺序排序,越大代表越接近现在时间


回帖格式建议

杀软名称 + 时间
查杀数量+查杀率


例如:
XXX 20:39
Samples(5/10) 50%



评分

参与人数 1人气 +1 收起 理由
petr0vic + 1 版区有你更精彩: )

查看全部评分

YU2711
发表于 2018-6-20 22:10:23 | 显示全部楼层
本帖最后由 YU2711 于 2018-6-20 22:49 编辑

Norton Security   22:09
22/27 双击
1C:\Users\User\AppData\Local\Temp\is-5VNV8.tmp里的衍生物机器B杀
11Miss
13SONAR.Heuristic.170
18SONAR.SuspLaunch!g12
20SONAR.Heuristic.170
1双击第2次SONAR.Heuristic.170

ATP_synthase
发表于 2018-6-20 22:28:24 | 显示全部楼层
本帖最后由 wusiyuanjh 于 2018-6-20 22:33 编辑

卡巴扫描杀14个,双击测试,2号阻止危险网址,4、7、11、13、15、20、24、25号主防杀
22/27

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
B100D1E55
发表于 2018-6-20 22:44:00 | 显示全部楼层
本帖最后由 B100D1E55 于 2018-6-20 23:10 编辑

ESET剩余6,20两个文件,其中20杀vbe衍生物,6被AMS杀injector
,就一个.
发表于 2018-6-20 23:06:56 | 显示全部楼层
迈克菲扫描7/27 2018年6月20日22:54:15

双击
1 不报
2 报Real Protect-LS!049cedad8275
3 报DAC/Suspect.0:0:3eb!24075858b86a
4 报Real Protect-LS!7c631b2c975e
5 不报
6 报DAC/Suspect.0:0:3eb!dbe5b23fcd94
7 报Real Protect-EC!18D497C9F08B
9 报Real Protect-LS!798f646cc38b
10 报Real Protect-LS!3189a6e7f59c
12 报Real Protect-LS!2098632942f0
13 不报
15 报Real Protect-EC!0E5E9AD6B349
17 报Real Protect-LS!954aa2ceb943
18 报Real Protect-LS!c93d77e073de
19 报Real Protect-LS!beb38b76a4ee
20 报Real Protect-EC!35DB5309D751
21 报Real Protect-LS!1988b9cc50f0
22 报Real Protect-LS!01db05781b1e
24 报Real Protect-LS!13b9ed052cc4
25 报Real Protect-LS!75ab4f9f2785
27 报Real Protect-EC!72D63A589DC4

最后成绩 24/27 88%

ELOHIM
发表于 2018-6-20 21:37:29 | 显示全部楼层
本帖最后由 ELOHIM 于 2018-6-20 21:46 编辑

SCEP KILL 10   21:38 37%
星猫
发表于 2018-6-20 21:40:18 | 显示全部楼层
WD 2018/06/20 21:40
24/27
petr0vic
发表于 2018-6-20 21:55:29 | 显示全部楼层
KIS 19 KSN-off
14/27




瑞星RDM+社区版
8/27



瑞星ML社区版
11/27





本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lambggy
发表于 2018-6-20 22:10:38 | 显示全部楼层
瑞星V17   20:39
Samples(4/27)
运行7.exe,瑞星之剑拦截成功


19.exe触发注册表保护,拦截成功

剩下的均运行成功。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Jerry.Lin
 楼主| 发表于 2018-6-20 22:14:49 | 显示全部楼层
本帖最后由 191196846 于 2018-6-20 22:18 编辑

22:13

27/27 100%


炒鸡多次出现上传的弹窗……Uploading... Analyzing... Infected!

  1. 2018/6/20, 22:12:41 [Real-Time Protection] Malware found
  2.         The pattern of 'TR/Injector.vkkla (Cloud) [TR/Injector.vkkla]'
  3.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(27).exe'.
  4.         Action performed: Delete file
  5.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  6. 2018/6/20, 22:12:35 [Real-Time Protection] Malware found
  7.         The pattern of 'DR/Delphi.47fc88 (Cloud) [DR/Delphi.47fc88]'
  8.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(26).exe'.
  9.         Action performed: Delete file
  10.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  11. 2018/6/20, 22:12:30 [Real-Time Protection] Malware found
  12.         The pattern of 'TR/Crypt.XPACK.7973cf (Cloud) [TR/Crypt.XPACK.7973cf]'
  13.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(25).exe'.
  14.         Action performed: Delete file
  15.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  16. 2018/6/20, 22:12:26 [Real-Time Protection] Malware found
  17.         The pattern of 'DR/Delphi.4cc805 (Cloud) [DR/Delphi.4cc805]'
  18.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(23).exe'.
  19.         Action performed: Delete file
  20.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  21. 2018/6/20, 22:11:57 [Real-Time Protection] Malware found
  22.         The pattern of 'TR/Crypt.XPACK.3379db (Cloud) [TR/Crypt.XPACK.3379db]'
  23.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(22).exe'.
  24.         Action performed: Delete file
  25.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  26. 2018/6/20, 22:11:52 [Real-Time Protection] Malware found
  27.         The pattern of 'TR/ATRAPS.Gen [trojan]'
  28.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(21).exe'.
  29.         Action performed: Delete file
  30.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  31. 2018/6/20, 22:11:49 [Real-Time Protection] Malware found
  32.         The pattern of 'HEUR/AGEN.1029336 [heuristic]'
  33.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(19).exe'.
  34.         Action performed: Delete file
  35.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  36. 2018/6/20, 22:11:46 [Real-Time Protection] Malware found
  37.         The pattern of 'HEUR/AGEN.1019180 [heuristic]'
  38.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(18).exe'.
  39.         Action performed: Delete file
  40.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  41. 2018/6/20, 22:11:42 [Real-Time Protection] Malware found
  42.         The pattern of 'TR/Dropper.MSIL.ef14de (Cloud) [TR/Dropper.MSIL.ef14de]'
  43.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(17).exe'.
  44.         Action performed: Delete file
  45.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  46. 2018/6/20, 22:11:33 [Real-Time Protection] Malware found
  47.         The pattern of 'DR/Delphi.Gen (Cloud) [DR/Delphi.Gen]'
  48.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(16).exe'.
  49.         Action performed: Delete file
  50.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  51. 2018/6/20, 22:11:13 [Real-Time Protection] Malware found
  52.         The pattern of 'TR/Crypt.Agent.9a4333 (Cloud) [TR/Crypt.Agent.9a4333]'
  53.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(15).exe'.
  54.         Action performed: Delete file
  55.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  56. 2018/6/20, 22:10:55 [Real-Time Protection] Malware found
  57.         The pattern of 'TR/AD.njLogger.Y (Cloud) [TR/AD.njLogger.Y]'
  58.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(14).exe'.
  59.         Action performed: Delete file
  60.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  61. 2018/6/20, 22:10:49 [Real-Time Protection] Malware found
  62.         The pattern of 'TR/Crypt.EPACK.083369 (Cloud) [TR/Crypt.EPACK.083369]'
  63.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(13).exe'.
  64.         Action performed: Delete file
  65.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  66. 2018/6/20, 22:10:43 [Real-Time Protection] Malware found
  67.         The pattern of 'TR/Crypt.XPACK.ea3057 (Cloud) [TR/Crypt.XPACK.ea3057]'
  68.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(12).exe'.
  69.         Action performed: Delete file
  70.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  71. 2018/6/20, 22:10:37 [Real-Time Protection] Malware found
  72.         The pattern of 'TR/AD.Sagonaire.Y (Cloud) [TR/AD.Sagonaire.Y]'
  73.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(11).exe'.
  74.         Action performed: Delete file
  75.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  76. 2018/6/20, 22:10:31 [Real-Time Protection] Malware found
  77.         The pattern of 'TR/Crypt.XPACK.2f6299 (Cloud) [TR/Crypt.XPACK.2f6299]'
  78.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(10).exe'.
  79.         Action performed: Delete file
  80.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  81. 2018/6/20, 22:10:26 [Real-Time Protection] Malware found
  82.         The pattern of 'TR/Dropper.MSIL.286650 (Cloud) [TR/Dropper.MSIL.286650]'
  83.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(9).exe'.
  84.         Action performed: Delete file
  85.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  86. 2018/6/20, 22:10:09 [Real-Time Protection] Malware found
  87.         The pattern of 'TR/Crypt.XPACK.Gen [trojan]'
  88.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(8).exe'.
  89.         Action performed: Delete file
  90.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  91. 2018/6/20, 22:09:59 [Real-Time Protection] Malware found
  92.         The pattern of 'TR/Kryptik.b8d772 (Cloud) [TR/Kryptik.b8d772]'
  93.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(7).exe'.
  94.         Action performed: Delete file
  95.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  96. 2018/6/20, 22:09:40 [Real-Time Protection] Malware found
  97.         The pattern of 'TR/Dropper.VB.e5ca91 (Cloud) [TR/Dropper.VB.e5ca91]'
  98.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(6).exe'.
  99.         Action performed: Delete file
  100.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  101. 2018/6/20, 22:09:37 [Real-Time Protection] Malware found
  102.         The pattern of 'TR/Injector.ba1c9d (Cloud) [TR/Injector.ba1c9d]'
  103.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(5).exe'.
  104.         Action performed: Delete file
  105.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  106. 2018/6/20, 22:09:31 [Real-Time Protection] Malware found
  107.         The pattern of 'TR/Dropper.VB.eafe26 (Cloud) [TR/Dropper.VB.eafe26]'
  108.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(3).exe'.
  109.         Action performed: Delete file
  110.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  111. 2018/6/20, 22:09:15 [Real-Time Protection] Malware found
  112.         The pattern of 'TR/Kryptik.19522d (Cloud) [TR/Kryptik.19522d]'
  113.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(2).exe'.
  114.         Action performed: Delete file
  115.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  116. 2018/6/20, 22:09:04 [Real-Time Protection] Malware found
  117.         The pattern of 'TR/Crypt.Agent.c2a297 (Cloud) [TR/Crypt.Agent.c2a297]'
  118.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(1).exe'.
  119.         Action performed: Delete file
  120.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  121. 2018/6/20, 22:07:47 [Real-Time Protection] Malware found
  122.         The pattern of 'TR/Kryptik.ncsrs [trojan]'
  123.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(24).exe'.
  124.         Action performed: Delete file
  125.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  126. 2018/6/20, 22:07:45 [Real-Time Protection] Malware found
  127.         The pattern of 'TR/Kryptik.ncsrs [trojan]'
  128.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(24).exe'.
  129.         Action performed: Delete file
  130.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  131. 2018/6/20, 22:07:45 [Real-Time Protection] Malware found
  132.         The pattern of 'TR/Bicololo.sfpjv [trojan]'
  133.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(20).exe'.
  134.         Action performed: Delete file
  135.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  136. 2018/6/20, 22:07:44 [Real-Time Protection] Malware found
  137.         The pattern of 'TR/AD.Emotet.kjtmf [trojan]'
  138.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE0620\(4).exe'.
  139.         Action performed: Delete file
  140.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

复制代码



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
ELOHIM + 1 大棒棒哦!错了错了,太棒棒哦!

查看全部评分

wangyuhe
发表于 2018-6-20 22:34:35 | 显示全部楼层
FS纯扫描kill13
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 09:02 , Processed in 0.126566 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表