楼主: www-tekeze
收起左侧

[病毒样本] 样本集奉上_17

  [复制链接]
www-tekeze
 楼主| 发表于 2018-7-10 16:57:25 | 显示全部楼层
Jirehlov1234 发表于 2018-7-10 16:50
最好再把水分挤挤,你看那么多卡巴判白的。。。。。。

上千的样本,你来帮我挤吧。。。我没装卡巴,他是什么反应我怎么清楚? 难道让我再装上BD、NS、ESET、红伞等等,然后都去挤一挤?   
Dolby123
发表于 2018-7-10 17:00:15 | 显示全部楼层
Malwarebytes
6/20


File: 6
Trojan.PasswordStealer, C:\USERS\ADMINISTRATOR\DESKTOP\VIRUSSAMPLES_17\SAMP (13).VIR, No Action By User, [3582], [522639],1.0.5847
Trojan.Downloader, C:\USERS\ADMINISTRATOR\DESKTOP\VIRUSSAMPLES_17\SAMP (15).VIR, No Action By User, [846], [394054],1.0.5847
PUP.Optional.Jawego, C:\USERS\ADMINISTRATOR\DESKTOP\VIRUSSAMPLES_17\SAMP (8).VIR, No Action By User, [516], [348975],1.0.5847
Generic.Malware/Suspicious, C:\USERS\ADMINISTRATOR\DESKTOP\VIRUSSAMPLES_17\SAMP (3).VIR, No Action By User, [0], [392686],1.0.5847
RiskWare.BitCoinMiner, C:\USERS\ADMINISTRATOR\DESKTOP\VIRUSSAMPLES_17\SAMP (18).VIR, No Action By User, [920], [508940],1.0.5847
RiskWare.Agent, C:\USERS\ADMINISTRATOR\DESKTOP\VIRUSSAMPLES_17\SAMP (5).VIR, No Action By User, [3846], [368524],1.0.5847




www-tekeze
 楼主| 发表于 2018-7-10 17:06:12 | 显示全部楼层
现在装智量做辅杀了,再上个智量的,只报3个,主贴已说过火绒不报,所以把样本发上来,请大家帮测一下。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
救命稻草
发表于 2018-7-10 17:50:35 | 显示全部楼层
瑞星安全云终端 11x
F:\VirusSamples_17\Samp (4).vir        Trojan.Agent.gdz
F:\VirusSamples_17\Samp (1).vir        Trojan.Indiloadz!8.E2E0
F:\VirusSamples_17\Samp (13).vir        Trojan.Tiggre!8.ED98
F:\VirusSamples_17\Samp (15).vir        Malware.Heuristic!ET#92%
F:\VirusSamples_17\Samp (17).vir        Malware.Heuristic!ET#92%
F:\VirusSamples_17\Samp (18).vir        PUA.CoinMiner!8.4639
F:\VirusSamples_17\Samp (2).vir        Exploit.CVE-2017-11882!8.EFC7
F:\VirusSamples_17\Samp (3).vir        Malware.Undefined!8.C
F:\VirusSamples_17\Samp (5).vir        Malware.Heuristic!ET#99%
F:\VirusSamples_17\Samp (8).vir        PUA.Jawego!8.DC9F
F:\VirusSamples_17\Samp (20).vir        Trojan.Turla!8.1C8
fzshot
发表于 2018-7-10 18:54:45 | 显示全部楼层
Avira 10/20 50%
  1. Start of the scan: 2018-07-10 06:53:48
  2. 07/10/2018,06-53-58        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (13).vir'
  3. 07/10/2018,06-53-58        [INFO]        c:\users\**\desktop\infected\Samp (13).vir
  4. 07/10/2018,06-53-58        [INFO]        [DETECTION] file contains 'TR/Drop.Agent.owatk'
  5. 07/10/2018,06-53-59        [INFO]        The file 'c:\users\**\desktop\infected\Samp (15).vir' was scanned with the Protection Cloud. SHA256 = F7B51550E7C90847F1A4BC1014EBFC116342FF5C140283DCA27526B77D0DB638
  6. 07/10/2018,06-54-00        [INFO]        The file 'c:\users\**\desktop\infected\Samp (16).vir' was scanned with the Protection Cloud. SHA256 = 58B73EC6A7812C6ACBB752E9E108C7E70A7938A5F9816847072D1AD7397215ED
  7. 07/10/2018,06-54-01        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (18).vir'
  8. 07/10/2018,06-54-02        [INFO]        The file 'c:\users\**\desktop\infected\Samp (18).vir' was scanned with the Protection Cloud. SHA256 = 7E59A187782BA97E0805092BED4420E774A7BF64FFAD312B95CB885656637FFE
  9. 07/10/2018,06-54-02        [INFO]        c:\users\**\desktop\infected\Samp (18).vir
  10. 07/10/2018,06-54-02        [INFO]        [DETECTION] file contains 'PUA/CoinMiner'
  11. 07/10/2018,06-54-02        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (2).vir'
  12. 07/10/2018,06-54-02        [INFO]        c:\users\**\desktop\infected\Samp (2).vir
  13. 07/10/2018,06-54-02        [INFO]        [DETECTION] file contains 'EXP/M97M.Agent.oiena'
  14. 07/10/2018,06-54-02        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (20).vir'
  15. 07/10/2018,06-54-02        [INFO]        c:\users\**\desktop\infected\Samp (20).vir
  16. 07/10/2018,06-54-02        [INFO]        [DETECTION] file contains 'TR/Turla.ghjml'
  17. 07/10/2018,06-54-02        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (3).vir'
  18. 07/10/2018,06-54-02        [INFO]        c:\users\**\desktop\infected\Samp (3).vir
  19. 07/10/2018,06-54-02        [INFO]        [DETECTION] file contains 'TR/Crypt.ASPM.Gen'
  20. 07/10/2018,06-54-02        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (4).vir'
  21. 07/10/2018,06-54-02        [INFO]        c:\users\**\desktop\infected\Samp (4).vir
  22. 07/10/2018,06-54-02        [INFO]        [DETECTION] file contains 'OSX/Wirenet.A.1'
  23. 07/10/2018,06-54-03        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (5).vir'
  24. 07/10/2018,06-54-03        [INFO]        The file 'c:\users\**\desktop\infected\Samp (5).vir' was scanned with the Protection Cloud. SHA256 = 8CBD16EB6AD744F0463991AFF04BBBB8CE7E51635DD68025788E9E63CA79D62B
  25. 07/10/2018,06-54-03        [INFO]        c:\users\**\desktop\infected\Samp (5).vir
  26. 07/10/2018,06-54-03        [INFO]        [DETECTION] file contains 'SPR/YouXun.8cbd16'
  27. 07/10/2018,06-54-04        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (6).vir'
  28. 07/10/2018,06-54-04        [INFO]        The file 'c:\users\**\desktop\infected\Samp (6).vir' was scanned with the Protection Cloud. SHA256 = 1F0FD700853B5DA9F0D9449FBAFF8D63B97B9F7F2C813BE7615CD514CB35684A
  29. 07/10/2018,06-54-04        [INFO]        c:\users\**\desktop\infected\Samp (6).vir
  30. 07/10/2018,06-54-04        [INFO]        [DETECTION] file contains 'Adware/Agent.1f0fd7'
  31. 07/10/2018,06-54-04        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (7).vir'
  32. 07/10/2018,06-54-04        [INFO]        c:\users\**\desktop\infected\Samp (7).vir
  33. 07/10/2018,06-54-04        [INFO]        [DETECTION] file contains 'TR/Dldr.Delphi.ladck'
  34. 07/10/2018,06-54-04        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\**\desktop\infected\Samp (8).vir'
  35. 07/10/2018,06-54-04        [INFO]        c:\users\**\desktop\infected\Samp (8).vir
  36. 07/10/2018,06-54-04        [INFO]        [DETECTION] file contains 'PUA/Systweak.EL.512342'
复制代码
帝辛
发表于 2018-7-10 19:21:27 | 显示全部楼层
eset开潜在 10/20
病毒探索者
发表于 2018-7-10 20:01:30 | 显示全部楼层
Norton 11/20 55%

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
病毒探索者
发表于 2018-7-10 20:03:33 | 显示全部楼层
www-tekeze 发表于 2018-7-10 16:49
照例来个安天的,11个 。。

安天这么厉害的吗?
病毒探索者
发表于 2018-7-10 20:04:49 | 显示全部楼层

朋友,你这个BD有点特别
www-tekeze
 楼主| 发表于 2018-7-10 20:33:05 | 显示全部楼层
本帖最后由 www-tekeze 于 2018-7-10 20:37 编辑

上一集安天报27个,检出率90%,是最高的,但今天火绒入库后只报10个,检出率33.3%,这要如何解释呢?
各家的入库策略不一样吧,不多评说。。   忘记点就回复了,艾特下。。@病毒探索者

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-1 02:30 , Processed in 0.120445 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表