本帖最后由 静影沉璧 于 2018-8-20 22:18 编辑
BD2019:
实际:删除126+修复130=256/300 85.3%
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(99).vir Trojan.GenericKD.3790164 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(166).vir=>[Subject: uk_confirmation_ph690373679.pdf][Date: Thu, 30 Mar 2017 17:14:14 +0530]=>uk_confirmation_ph690373679.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(95).vir Trojan.GenericKD.4000018 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(122).vir Trojan.GenericKD.3789448 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(65).vir=>[Subject: Invoice INV0000980][Date: Tue, 31 Oct 2017 18:17:02 +0530]=>Invoice INV0000980.doc Trojan.GenericKD.6181923 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(94).vir=>[Subject: uk_confirmation_ph184650070.pdf][Date: Thu, 30 Mar 2017 14:28:24 +0200]=>uk_confirmation_ph184650070.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715278 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(124).vir=>[Subject: Please find attached a XLS Invoice 28697][Date: Tue, 29 Nov 2016 13:39:08 +0530]=>INVOICE.TAM_28697_20161129_1E4F735BA.xls Trojan.Doc.Downloader.WN Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(72).vir=>[Subject: 9346 [recipient]][Date: Thu, 27 Apr 2017 03:00:37 -0000]=>63043088778557.zip=>1.doc=>(objdata)=>(Embedded DocFile g) Exploit.CVE-2017-0199.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(255).vir=>[From: <jiggymovementbusiness@gmail.com>][Date: Thu, 19 Jan 2017 16:52:30 -0000]=>EMAIL_327120_[recipient].zip=>(dummy) Trojan.Oroles.Gen.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(62).vir=>[Subject: CC Confirmation]=>skm_c554e67954647183.7z=>SKM_C554e16098284038.vbs VB:Trojan.VBS.Agent.AQD Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(96).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(205).vir Trojan.GenericKD.4812613 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(102).vir VB:Trojan.Valyria.1125 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(272).vir=>[Subject: Receipt-70724][Date: Mon, 31 Jul 2017 16:02:29 +0430]=>P70724.zip=>19367.2017-07-31_31.97.09.vbs w97m.Agent.DG Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(89).vir W97m.Downloader.GMA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(90).vir=>[Subject: File COPY.29112016.7955.XLS Sent 29=>11=>2016][Date: Tue, 29 Nov 2016 14:21:45 -0300]=>COPY.29112016.7955.XLS=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(232).vir=>[Subject: Message from "RNP002673C28069"][Date: Tue, 08 Aug 2017 05:15:41 -0500]=>20170808051541.zip=>201708085655.js Trojan.GenericKD.5788559 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(253).vir=>[Subject: DEA3ADF1CC0BB6B7][Date: Tue, 26 Jul 2016 09:54:07 -0500]=>DEA3ADF1CC0BB6B7.docm=>word/vbaProject.bin W97M.Downloader.EAB Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(86).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(98).vir=>word/vbaProject.bin W97M.Downloader.EXH Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(210).vir=>[Subject: 45462 [recipient]][Date: Thu, 27 Apr 2017 07:15:20 -0000]=>993051853636.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(240).vir=>[Subject: Emailed Invoice - 635418]=>i_635418.7z=>I_362789.js=>(INFECTED_JS) JS:Trojan.JS.Agent.QYD Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(290).vir=>[Subject: ][Date: Wed, 02 Aug 2017 10:56:45 -0000]=>EMAIL_2990067725884_[recipient].zip=>134383275.zip=>7oSZHYt.js=>(INFECTED_JS) JS:Trojan.Cryxos.1223 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(92).vir VB:Trojan.Valyria.11 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(56).vir=>[Subject: Picture][Date: Mon, 12 Sep 2016 19:31:03 +0530]=>WP_20160830_11_61_3_Pro.zip=>14YQg739.wsf Gen:Heur.JS.Downloader.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(201).vir=>[Subject: Your Booking 0953541][Date: Thu, 30 Mar 2017 15:52:39 +0530]=>Direct-Documentation 0953541-1.zip=>Direct-Documentation 1530219.zip=>Direct-Documentation 1530219/Direct-Documentation 1530219.vbs VB:Trojan.Valyria.330 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(71).vir Trojan.GenericKD.6181525 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(69).vir=>[Subject: FW: Invoice][Date: Thu, 28 Apr 2016 16:16:07 +0300]=>413C2_scan-invoice_D08DA1.zip=>ee642.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HT Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(35).vir VB:Trojan.Valyria.1715 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(97).vir=>[Subject: Your Booking 43738143][Date: Thu, 30 Mar 2017 14:54:02 +0530]=>Direct-Documentation 43738143-1.zip=>Direct-Documentation 1530219.zip=>Direct-Documentation 1530219/Direct-Documentation 1530219.vbs VB:Trojan.Valyria.330 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(83).vir=>xl/vbaProject.bin X97M.Downloader.CL Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(197).vir=>[Subject: Your Booking 87091629][Date: Thu, 30 Mar 2017 05:29:15 -0500]=>Direct-Documentation 87091629-1.zip=>Direct-Documentation 1530219.zip=>Direct-Documentation 1530219/Direct-Documentation 1530219.vbs VB:Trojan.Valyria.330 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(88).vir=>[Subject: You have a new secure message waiting ][Date: Tue, 1 Aug 2017 15:08:17 -0400]=>SecureMessage.doc VB:Trojan.VBA.Agent.JW Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(1).vir=>[Subject: Website Job Application][Date: Thu, 16 Nov 2017 07:21:03 +0100]=>LINDA's Resume.doc W97m.Downloader.GMA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(93).vir Trojan.JS.RKN Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(198).vir VB:Trojan.Valyria.933 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(279).vir Trojan.GenericKD.4002740 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(210).vir=>[Subject: 45462 [recipient]][Date: Thu, 27 Apr 2017 07:15:20 -0000]=>993051853636.zip=>9826.js=>(INFECTED_JS) JS.Remucod.2.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(67).vir=>[Subject: eVoice Voicemail (Callback: 295-306-5228)][Date: Thu, 26 Apr 2018 12:29:15 -0500]=>wav445F.20180426726.zip=>wav213F.2018042652801.url Trojan.Downloader.URI.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(79).vir=>[Subject: Invoice INV0000089][Date: Tue, 31 Oct 2017 16:39:04 +0700]=>Invoice INV0000089.doc Trojan.GenericKD.6182080 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(158).vir=>[Subject: uk_confirmation_ph309931744.pdf][Date: Thu, 30 Mar 2017 17:07:45 +0530]=>uk_confirmation_ph309931744.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(81).vir=>[Subject: Envio de Boleto - URGENTE - GRUPO FREITAS][Date: Fri, 6 Oct 2017 08:09:44 +0200 (CEST)]=>1508201700016067882247230289631.pdf Trojan.PDF.Phishing.RL Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(250).vir=>[Subject: ][Date: Tue, 03 Oct 2017 19:30:12 -0000]=>04143368910.zip=>11150.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(87).vir=>[Subject: uk_confirmation_ph676423423.pdf][Date: Thu, 30 Mar 2017 14:50:53 +0300]=>uk_confirmation_ph676423423.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(78).vir=>[From: [recipient's email address]][Date: Thu, 20 Apr 2017 06:14:37 -0000]=>EMAIL_4546735537_[recipient].zip=>7755.zip=>7755.js=>(INFECTED_JS) JS:Trojan.Cryxos.620 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(256).vir=>[Subject: NatWest][Date: Mon, 21 Aug 2017 12:24:55 +0300]=>NatWest258345907_2243.doc W97M.Downloader.GCY Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(84).vir VB:Trojan.Valyria.1055 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(135).vir=>[Subject: File COPY.29112016.11089.XLS Sent 29/11/2016][Date: Tue, 29 Nov 2016 16:16:11 +0200]=>COPY.29112016.11089.XLS Trojan.GenericKD.3790164 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(125).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(206).vir VB:Trojan.Valyria.773 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(85).vir=>[Subject: Financial statement][Date: Fri, 22 Jul 2016 00:46:30 +0300]=>daniel_45914.zip=>INV000 5cbd.js Trojan.JS.Agent.MJD Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(80).vir=>[Subject: CCE28122017_009548][Date: Thu, 28 Dec 2017 11:32:59 +0200]=>CCE28122017_009548.7z=>CCE28122017_001978.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(267).vir=>[Subject: File COPY.29112016.6596.XLS Sent 29/11/2016][Date: Tue, 29 Nov 2016 23:25:35 +0700]=>COPY.29112016.6596.XLS X97M.Downloader.CD Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(82).vir=>[Subject: Please find attached invoice no: 7475458263][Date: Mon, 21 Nov 2016 14:25:13 +0500]=>pmED847.zip=>JVCKEE503541.js Trojan.RanSerKD.3737651 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(73).vir W97M.Downloader.LZ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(214).vir=>word/document.xml Trojan.Downloader.DDE.Gen.1 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(75).vir=>[Subject: Invoice INV0000736][Date: Thu, 07 Dec 2017 15:48:47 +0530]=>invoice inv0000736.7z=>Invoice INV0000699.vbs VB:Trojan.VBS.Agent.AQF Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(70).vir=>[Subject: uk_confirmation_ph441639703.pdf][Date: Thu, 30 Mar 2017 17:01:59 +0530]=>uk_confirmation_ph441639703.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(68).vir=>[Subject: Invoice_4819463][Date: Wed, 27 Dec 2017 17:24:33 +0530]=>invoice_4819463.7z=>Invoice_9616548.js Trojan.JS.Downloader.IGK Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(276).vir VB:Trojan.VBA.Agent.JW Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(78).vir=>[From: [recipient's email address]][Date: Thu, 20 Apr 2017 06:14:37 -0000]=>EMAIL_4546735537_[recipient].zip=>7755.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(66).vir=>[Subject: list of activities][Date: Tue, 26 Jul 2016 14:12:53 +0100]=>smith_92668.zip=>activities -74AD-..wsf Trojan.JS.Downloader.DRV Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(60).vir=>[Subject: Scan #CBAFC82B93_54EB5B04D5][Date: Thu, 19 May 2016 16:40:58 +0200]=>MSG000244771637272.docm=>word/vbaProject.bin W97M.Downloader.CUL Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(63).vir VB:Trojan.VBA.Agent.QV Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(72).vir=>[Subject: 9346 [recipient]][Date: Thu, 27 Apr 2017 03:00:37 -0000]=>63043088778557.zip=>1.doc=>(objdata)=>() Exploit.CVE-2017-0199.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(207).vir=>[Subject: Website Job Application][Date: Thu, 16 Nov 2017 13:43:50 +0100]=>Sally's Resume.doc W97m.Downloader.GMA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(244).vir=>(objdata)=>(Embedded DocFile g) Exploit.CVE-2017-0199.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(59).vir Trojan.AgentWDCR.MLM Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(129).vir=>[Subject: Please find attached a XLS Invoice 21078][Date: Tue, 29 Nov 2016 17:35:13 +0530]=>INVOICE.TAM_21078_20161129_E3DBB2719.xls Trojan.GenericKD.3789819 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(64).vir Trojan.GenericKD.3925861 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(53).vir=>[Subject: Order #59909][Date: Tue, 3 Apr 2018 13:06:45 +0600]=>DOC2182929709.zip=>DOC2182929709.js=>(INFECTED_JS) JS:Trojan.JS.Agent.SGP Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(176).vir=>[Subject: Budget report][Date: Mon, 12 Sep 2016 20:57:22 +0700]=>fb1fe573a08d.zip=>(dummy) JS.TeslaCrypt.4.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(40).vir=>[Subject: Courier was not able to deliver your parcel (ID07907895, U][Date: Fri, 30 Jun 2017 12:57:06 -0300]=>UPS-Package-07907895.zip=>UPS-Package-07907895=>UPS-Package-07907895.doc.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HZQ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(283).vir Trojan.GenericKD.6181923 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(77).vir=>[Subject: uk_confirmation_ph509169944.pdf][Date: Thu, 30 Mar 2017 16:42:36 +0530]=>uk_confirmation_ph509169944.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(54).vir Trojan.GenericKD.3790235 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(61).vir Trojan.Downloader.JS.SA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(21).vir=>[Subject: Your Amazon.com order has dispatched (#291-2608445-1000757][Date: Mon, 21 Nov 2016 15:07:48 +0530]=>ORDER-291-2608445-1000757.zip=>YHIOE303045.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HAZ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(55).vir=>[Subject: Message from KM_C224e][Date: Fri, 02 Jun 2017 15:42:21 +0530]=>skm_c224e47704213294.pdf=>810FY6KLZEW4739.docm=>word/vbaProject.bin VB:Trojan.VBA.Downloader.FI Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(49).vir=>[Subject: 018648 =?iso-2022-jp?B?GyRCIVo4eDYmTkE2YkBBNWE9cSVHITwlP0F][Date: Wed, 6 Sep 2017 09:09:47 +0200]=>=?iso-2022-jp?b?gyrco1lkj0vbstwhshsoqjiwmtcumdkumduplnhscw= VB:Trojan.VBA.Agent.LW Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(157).vir Trojan.GenericKD.5592324 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(48).vir=>[Subject: uk_confirmation_ph389067635.pdf][Date: Thu, 30 Mar 2017 17:24:37 +0530]=>uk_confirmation_ph389067635.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715278 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(50).vir=>[Subject: Payment Invoice #46607][Date: Tue, 3 Apr 2018 15:17:00 +0700]=>DOC2212438286.zip=>DOC2212438286.js=>(INFECTED_JS) JS:Trojan.JS.Agent.SGP Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(123).vir=>[Subject: File COPY.29112016.0076.XLS Sent 29/11/2016][Date: Tue, 29 Nov 2016 21:28:24 +0530]=>COPY.29112016.0076.XLS X97M.Downloader.CB Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(44).vir W97M.Downloader.LZ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(47).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(43).vir VB:Trojan.VBA.Agent.LW Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(41).vir=>[Subject: Message from "RNP002673C84902"][Date: Tue, 08 Aug 2017 19:38:14 +0530]=>20170808193814.zip=>201708084410.js Trojan.GenericKD.5788494 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(169).vir=>xl/vbaProject.bin W97M.Downloader.EVY Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(32).vir=>[Subject: Scan_130751][Date: Thu, 28 Dec 2017 19:51:51 +0300]=>Scan_130751.7z=>PDF_2457326.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(4).vir=>word/vbaProject.bin VB:Trojan.Valyria.543 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(190).vir Trojan.GenericKD.3934965 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(39).vir=>[Subject: Your Booking 14538307][Date: Thu, 30 Mar 2017 11:26:15 +0200]=>Direct-Documentation 14538307-1.zip=>Direct-Documentation 1530219.zip=>Direct-Documentation 1530219/Direct-Documentation 1530219.vbs VB:Trojan.Valyria.330 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(19).vir=>[Subject: Re: Enquiry][Date: Thu, 6 Aug 2015 02:38:03 -0700]=>P.O_001_UST-TRADE.jar=>c/CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class Trojan.Java.Adwind.P Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(38).vir VB:Trojan.VBA.Downloader.CQ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(231).vir=>word/vbaProject.bin VB:Trojan.Valyria.543 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(51).vir=>[Subject: Scanned document from HP ePrint user][Date: Mon, 30 Oct 2017 19:38:56 +0700]=>untitled-4.doc=>word/document.xml Trojan.Downloader.DDE.Gen.1 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(229).vir=>[Subject: Order 86173440 (Acknowledgement)][Date: Thu, 03 Nov 2016 20:32:59 +0300]=>Lx86173440.zip=>zMXDJX5248-1503.vbs Trojan.VBS.Downloader.ZC Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(121).vir=>[Subject: Document_88529849][Date: Wed, 27 Dec 2017 17:57:49 +0300]=>document_88529849.7z=>Scan_38097849.js Trojan.JS.Downloader.IGK Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(36).vir W97M.Downloader.GNO Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(37).vir=>[From: Hal <Hal@sabrilex.ru>][Date: Mon, 24 Jul 2017 13:14:23 +0200]=>IMG_1663.ZIP=>01258861149_20170411_826303.wsf Trojan.JS.Agent.QSM Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(45).vir=>[Subject: Scan #89F0667135_289DD861BC][Date: Tue, 24 May 2016 06:05:04 -0800]=>MSG00000449120194.zip=>XLYG-4006858.js Trojan.GenericKD.3264133 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(34).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(41).vir=>[Subject: Message from "RNP002673C84902"][Date: Tue, 08 Aug 2017 19:38:14 +0530]=>20170808193814.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(33).vir=>[Subject: CCE28122017_004413][Date: Thu, 28 Dec 2017 05:07:54 -0700]=>CCE28122017_004413.7z=>CCE28122017_002133.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(13).vir=>[Subject: 31172 [recipient]][Date: Thu, 27 Apr 2017 15:36:09 -0000]=>7668442274917.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(299).vir=>[Subject: uk_confirmation_ph492070771.pdf][Date: Thu, 30 Mar 2017 13:19:57 +0200]=>uk_confirmation_ph492070771.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(109).vir=>[Subject: Message from KM_C224e][Date: Tue, 19 Sep 2017 03:33:48 +0800]=>20171809_61562124834.7z=>20170918_84047158233.vbs VB:Trojan.VBS.Downloader.ADW Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(30).vir=>[Subject: Message from KM_C224e][Date: Fri, 02 Jun 2017 16:14:27 +0530]=>skm_c224e97135190699.pdf=>656NVMPNEQM829.docm=>word/vbaProject.bin VB:Trojan.VBA.Downloader.FI Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(138).vir=>word/vbaProject.bin W97M.Downloader.CDS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(216).vir W97m.Downloader.GNQ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(31).vir=>[Subject: Your Ticket #23428][Date: Fri, 16 Mar 2018 08:56:07 -1200]=>DOC4171785589-PDF.7z=>DOC4171785589-PDF.js=>(INFECTED_JS) JS:Trojan.JS.Agent.SFA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(224).vir=>[Subject: list of activities][Date: Tue, 26 Jul 2016 17:10:27 +0200]=>finn_2759.zip=>activities -CC7-..wsf Trojan.JS.Downloader.DRV Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(277).vir=>word/document.xml Trojan.Msword.NYT Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(298).vir=>[Subject: Status of invoice][Date: Mon, 18 Sep 2017 15:21:26 +0430]=>a2178960-44.7z=>44394795975.vbs Trojan.VBS.Downloader.ADV Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(3).vir W97M.Downloader.CUZ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(13).vir=>[Subject: 31172 [recipient]][Date: Thu, 27 Apr 2017 15:36:09 -0000]=>7668442274917.zip=>16324.js=>(INFECTED_JS) JS.Remucod.2.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(154).vir=>[Subject: PAYMENT][Date: Wed, 16 Aug 2017 16:26:03 +0530]=>20170816040630314.rar=>20170816715641217.js Trojan.JS.Agent.QVF Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(297).vir=>[Subject: ][Date: Tue, 27 Jun 2017 14:34:48 -0000]=>email_9530546474_[recipient's name].zip=>24703.zip=>24703.js=>(INFECTED_JS) JS:Trojan.Cryxos.960 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(295).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(291).vir=>(objdata) Exploit.RTF-ObfsStrm.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(251).vir=>[Subject: eVoice Voicemail (Callback: 381-381-5001)][Date: Thu, 26 Apr 2018 15:08:25 +0300]=>wav213F.2018042615021.zip=>wav213F.2018042615021.url Trojan.Downloader.URI.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(112).vir=>[From: <mathias.heinrich@web.de>][Date: Fri, 13 Jan 2017 14:28:10 -0000]=>6225549306381.zip=>5274.doc VB:Trojan.Valyria.80 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(29).vir Trojan.GenericKD.12555822 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(113).vir=>[Subject: ][Date: Tue, 03 Oct 2017 22:48:33 -0000]=>28275.zip=>17317.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(287).vir VB:Trojan.Valyria.62 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(285).vir=>[Subject: Scan_386530][Date: Wed, 27 Dec 2017 21:19:14 +0530]=>scan_386530.7z=>Document_22998278.js Trojan.JS.Downloader.IGK Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(233).vir=>[Subject: Your Amazon.com order has dispatched (#478-9353190-9763851][Date: Mon, 21 Nov 2016 15:05:30 +0530]=>ORDER-478-9353190-9763851.zip=>OBMFOR383123.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HAZ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(116).vir Trojan.Downloader.JS.SA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(292).vir=>[Subject: IMG_3679.JPEG][Date: Tue, 08 Aug 2017 21:42:44 +0100]=>img_3679.zip=>IMG_9456.js Trojan.JS.Downloader.IBF Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(282).vir=>[Subject: uk_confirmation_ph380268598.pdf][Date: Thu, 30 Mar 2017 16:50:56 +0500]=>uk_confirmation_ph380268598.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(286).vir=>[Subject: Website Job Application][Date: Thu, 16 Nov 2017 09:18:25 +0100]=>Ruth's Resume.doc W97m.Downloader.GMA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(297).vir=>[Subject: ][Date: Tue, 27 Jun 2017 14:34:48 -0000]=>email_9530546474_[recipient's name].zip=>24703.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(226).vir Trojan.GenericKD.3931190 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(280).vir=>[Subject: File COPY.29112016.94437.XLS Sent 29/11/2016][Date: Tue, 29 Nov 2016 21:13:10 +0530]=>COPY.29112016.94437.XLS X97M.Downloader.CE Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(100).vir=>[Subject: Please find attached invoice no: 8478912583][Date: Mon, 12 Sep 2016 20:32:18 +0800]=>pmBF2EE7B7.zip=>22P5R06.wsf Gen:Heur.JS.Downloader.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(293).vir W97m.Downloader.GMA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(281).vir=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(167).vir=>[Subject: Re:][Date: Tue, 24 May 2016 14:27:51 +0200]=>to_sign_inv_1D3A514A.zip=>customers 578.wsf Trojan.JS.Agent.LMB Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(278).vir W97M.Dropper.AE Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(196).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(28).vir Trojan.GenericKD.3789595 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(274).vir=>[Subject: 50138 [recipient]][Date: Thu, 27 Apr 2017 11:55:12 -0000]=>84296497.zip=>17779.zip=>17779.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HVH Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(193).vir Trojan.GenericKD.3994176 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(126).vir Trojan.GenericKD.12002525 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(177).vir=>[From: <info@snowandice.com>][Date: Wed, 18 Jan 2017 15:12:28 -0000]=>EMAIL_89868_[recipient].zip=>23079_ZIP.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(273).vir=>[Subject: Document invoice_205_sign_and_return.pdf is complete][Date: Tue, 10 Oct 2017 15:30:41 +0430]=>invoice_205_sign_and_return.7z=>invoice_64789_sign_and_return.vbs VB:Trojan.Agent.COFZ Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(136).vir=>[From: Emilia <Emilia@messerknecht.ch>][Date: Mon, 24 Jul 2017 18:55:13 +0700]=>IMG_4518.ZIP=>01258861149_20170411_402800.wsf Trojan.JS.Agent.QSM Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(271).vir=>[Subject: uk_confirmation_ph083380077.pdf][Date: Thu, 30 Mar 2017 19:39:30 +0530]=>uk_confirmation_ph083380077.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4716377 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(171).vir=>[Subject: avviso di pagamento 21/11/2017][Date: Tue, 21 Nov 2017 10:27:43 +0100]=>94134_[removed].xls VB:Trojan.VBA.Downloader.HT Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(270).vir=>(objdata)=>(Embedded DocFile g) Exploit.CVE-2017-0199.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(106).vir=>[Subject: FW: Invoice][Date: Thu, 28 Apr 2016 20:23:36 +0700]=>craig-forward_2107EF.zip=>bf3f834.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HT Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(168).vir Trojan.Downloader.JS.SA Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(268).vir=>[Subject: Invoice INV0000104][Date: Thu, 07 Dec 2017 10:59:52 +0100]=>invoice inv0000104.7z=>Invoice INV0000138.vbs VB:Trojan.VBS.Agent.AQF Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(178).vir=>[Subject: Financial statement][Date: Fri, 22 Jul 2016 05:09:25 +0700]=>rhonda_330F92.zip=>INV000 da0.js Trojan.JS.Agent.MJC Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(275).vir=>[Subject: Order 24605687 (Acknowledgement)][Date: Thu, 03 Nov 2016 11:22:56 -0500]=>TXymLf24605687.zip=>TmUPy382-1682.vbs Trojan.VBS.Downloader.ZC Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(194).vir Trojan.GenericKD.6204055 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(274).vir=>[Subject: 50138 [recipient]][Date: Thu, 27 Apr 2017 11:55:12 -0000]=>84296497.zip=>17779.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(27).vir Trojan.GenericKD.12589066 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(155).vir=>[Subject: Emailing: IMG_20171221_501005613, IMG_20171221_798070330, ][Date: Thu, 21 Dec 2017 22:24:32 +0700]=>img_20171221_501005613.7z=>IMG_20171221_312327133.js Trojan.JS.Downloader.Nemucod.BL Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(186).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(150).vir=>[Subject: UPS Tracking Number for shipment H6902644376][Date: Fri, 28 Apr 2017 14:01:40 +0400]=>H6902644376.rar=>H6902644376.js Trojan.GenericKD.4953926 Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(263).vir=>[Subject: uk_confirmation_ph097166710.pdf][Date: Thu, 30 Mar 2017 13:45:46 +0100]=>uk_confirmation_ph097166710.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715278 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(175).vir W97m.Downloader.GNQ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(269).vir=>[Subject: Website Job Application][Date: Wed, 15 Nov 2017 06:27:48 +0100]=>Mary's Resume.doc VB:Trojan.Valyria.983 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(270).vir=>(objdata)=>() Exploit.CVE-2017-0199.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(266).vir=>[Subject: SAFARI LPO [MAL] 988284][Date: Tue, 24 May 2016 20:16:35 +0700]=>LPOMAL988284-C163-1708089.zip=>LIT-1803889.js Trojan.GenericKD.3264118 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(262).vir=>[Subject: Account Statement][Date: Thu, 25 Jan 2018 04:34:42 -0800]=>114755590.7z=>114755590.vbs Trojan.Agent.CUAI Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(184).vir=>[Subject: Please find attached a XLS Invoice 55935][Date: Tue, 29 Nov 2016 17:07:04 +0530]=>INVOICE.TAM_55935_20161129_055BB65DD.xls Trojan.GenericKD.3790082 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(261).vir W97M.Downloader.IF Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(260).vir VB:Trojan.Valyria.773 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(26).vir VB:Trojan.Valyria.1658 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(117).vir=>[Subject: New Doc 2017-10-02 - Page 1]=>new doc 2017-10-02 - page 1.7z=>New Doc 2017-10-02 - Page 2 -8300.js=>(INFECTED_JS) JS:Trojan.JS.Agent.QYD Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(258).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(170).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(259).vir=>[Subject: Invoice][Date: Wed, 01 Nov 2017 17:44:52 +0530]=>49545_Invoice.doc Trojan.GenericKD.6181525 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(142).vir=>[Subject: Re: P.0 18003.][Date: Thu, 6 Aug 2015 03:01:35 -0700]=>P.O_18003.jar=>CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class Java.Trojan.GenericGB.19948 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(257).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(254).vir=>[Subject: Emailing: IMG_20171221_167023012, IMG_20171221_911069898, ][Date: Thu, 21 Dec 2017 16:34:47 -0200]=>img_20171221_167023012.7z=>IMG_20171221_508871502.js Trojan.JS.Downloader.IGF Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(133).vir=>[Subject: 26567 [recipient]][Date: Thu, 27 Apr 2017 18:00:26 -0000]=>3.zip=>23759.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(173).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(264).vir=>xl/vbaProject.bin VB:Trojan.Valyria.211 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(183).vir Trojan.GenericKD.3789563 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(159).vir=>[Subject: You have a new secure communication ][Date: Wed, 2 Aug 2017 13:39:41 -0400]=>SecureCommunication.doc Trojan.Doc.Agent.FV Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(242).vir=>[Subject: FW: Invoice][Date: Thu, 28 Apr 2016 19:45:31 +0530]=>68BBC_scan-invoice_1888CD.zip=>e7bdaa4.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HT Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(40).vir=>[Subject: Courier was not able to deliver your parcel (ID07907895, U][Date: Fri, 30 Jun 2017 12:57:06 -0300]=>UPS-Package-07907895.zip=>(dummy) JS.TeslaCrypt.4.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(250).vir=>[Subject: ][Date: Tue, 03 Oct 2017 19:30:12 -0000]=>04143368910.zip=>11150.zip=>11150.js=>(INFECTED_JS) JS:Trojan.Cryxos.1289 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(249).vir=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(247).vir=>word/vbaProject.bin VB:Trojan.Valyria.543 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(209).vir=>[From: <sherryloveless@gmail.com>][Date: Thu, 19 Jan 2017 16:57:47 -0000]=>505635089.zip=>(dummy) Trojan.Oroles.Gen.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(248).vir=>word/vbaProject.bin VB:Trojan.Valyria.405 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(189).vir=>[Subject: CCE28122017_007792][Date: Thu, 28 Dec 2017 15:19:54 +0300]=>CCE28122017_007792.7z=>CCE28122017_008328.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(245).vir=>word/document.xml Trojan.Downloader.DDE.Gen.1 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(255).vir=>[From: <jiggymovementbusiness@gmail.com>][Date: Thu, 19 Jan 2017 16:52:30 -0000]=>EMAIL_327120_[recipient].zip=>22230_ZIP.zip=>22230.doc VB:Trojan.Valyria.138 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(174).vir Trojan.JS.RKN Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(204).vir=>[Subject: PDF_69898][Date: Thu, 28 Dec 2017 20:52:52 +0300]=>PDF_69898.7z=>PDF_6342214.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(227).vir=>[From: <[recipient]@rma.usda.gov>][Date: Thu, 20 Apr 2017 09:53:39 -0000]=>EMAIL_1874513753_[recipient].zip=>18092.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(246).vir=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(161).vir=>[Subject: Please find attached a XLS Invoice 42709][Date: Tue, 29 Nov 2016 03:21:09 -0700]=>INVOICE.TAM_42709_20161129_A805F73C0.xls Trojan.GenericKD.3790281 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(243).vir=>[Subject: File COPY.29112016.494446.XLS Sent 29/11/2016][Date: Tue, 29 Nov 2016 21:21:01 +0530]=>COPY.29112016.494446.XLS X97M.Downloader.CC Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(162).vir VB:Trojan.VBA.Downloader.GQ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(24).vir=>[From: <4070703@web.de>][Date: Fri, 28 Jul 2017 22:17:12 -0000]=>EMAIL_537710951959_[recipient].zip=>01637815.zip=>DIy.js=>(INFECTED_JS) JS:Trojan.Cryxos.1145 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(120).vir=>[Subject: Re:][Date: Tue, 24 May 2016 18:44:40 +0530]=>to_sign_inv_19D6F7A3.zip=>customers 040.wsf Gen:Heur.JS.Downloader.1 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(239).vir VB:Trojan.Valyria.138 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(127).vir W97M.Downloader.GCY Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(208).vir Trojan.GenericKD.5806167 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(237).vir=>[Subject: Message from KM_C224e][Date: Fri, 02 Jun 2017 15:36:38 +0530]=>skm_c224e27127577722.pdf=>745FVHCXUFN614.docm=>word/vbaProject.bin VB:Trojan.VBA.Downloader.FI Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(236).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(235).vir=>[Subject: uk_confirmation_ph633892641.pdf][Date: Thu, 30 Mar 2017 19:38:31 +0530]=>uk_confirmation_ph633892641.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4716377 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(234).vir Trojan.Exploit.MSOfficeWord.GenericKDS.30602583 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(244).vir=>(objdata)=>() Exploit.CVE-2017-0199.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(152).vir=>[Subject: Payment_1479][Date: Mon, 31 Jul 2017 14:58:07 +0300]=>P1479.zip=>42421.2017-07-31_15.10.22.vbs Trojan.VBS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(23).vir=>[Subject: Emailed Invoice - 631798]=>i_631798.7z=>I_362789.js=>(INFECTED_JS) JS:Trojan.JS.Agent.QYD Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(228).vir W97M.Downloader.CUZ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(133).vir=>[Subject: 26567 [recipient]][Date: Thu, 27 Apr 2017 18:00:26 -0000]=>3.zip=>23759.zip=>23759.js=>(INFECTED_JS) JS:Trojan.JS.Downloader.HVH Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(227).vir=>[From: <[recipient]@rma.usda.gov>][Date: Thu, 20 Apr 2017 09:53:39 -0000]=>EMAIL_1874513753_[recipient].zip=>18092.zip=>18092.js=>(INFECTED_JS) JS:Trojan.Cryxos.620 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(225).vir Trojan.GenericKD.12412767 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(187).vir=>[Subject: File COPY.29112016.61652.XLS Sent 29=>11=>2016][Date: Tue, 29 Nov 2016 18:07:40 +0300]=>COPY.29112016.61652.XLS=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(177).vir=>[From: <info@snowandice.com>][Date: Wed, 18 Jan 2017 15:12:28 -0000]=>EMAIL_89868_[recipient].zip=>23079_ZIP.zip=>23079.js Trojan.GenericKD.4412397 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(232).vir=>[Subject: Message from "RNP002673C28069"][Date: Tue, 08 Aug 2017 05:15:41 -0500]=>20170808051541.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(223).vir W97m.Downloader.GBT Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(222).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(148).vir X97M.Downloader.H Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(220).vir=>[Subject: File_348087][Date: Thu, 28 Dec 2017 23:23:55 +0600]=>File_348087.7z=>Copy_64549058.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(219).vir Trojan.GenericKD.5085797 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(218).vir W97m.Downloader.GPX Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(212).vir=>[Subject: 24007 [recipient]][Date: Thu, 27 Apr 2017 11:07:14 -0000]=>1473818521163.zip=>6307.js=>(INFECTED_JS) JS.Remucod.2.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(217).vir W97M.Downloader.GNO Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(215).vir=>[Subject: Supplement payment 4158120230][Date: Wed, 11 Oct 2017 16:44:14 +0700]=>F4158120230_11102017.7z=>F8906797410.vbs VB:Trojan.VBS.Agent.AOM Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(18).vir=>[Subject: Status of invoice][Date: Mon, 18 Sep 2017 16:39:33 +0300]=>a2179187-37.7z=>41431435149.vbs Trojan.VBS.Downloader.ADV Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(137).vir=>[Subject: Your Booking 04320655][Date: Thu, 30 Mar 2017 15:52:31 +0530]=>Direct-Documentation 04320655-1.zip=>Direct-Documentation 1530219.zip=>Direct-Documentation 1530219/Direct-Documentation 1530219.vbs VB:Trojan.Valyria.330 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(22).vir Trojan.GenericKD.40207607 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(57).vir=>[Subject: Please recheck your delivery address (UPS parcel 06520201)][Date: Sun, 2 Jul 2017 04:03:54 +0800]=>UPS-Package-06520201.zip=>UPS-Package-06520201=>UPS-Package-06520201.doc.js=>(INFECTED_JS) JS:Trojan.Agent.CIYK Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(209).vir=>[From: <sherryloveless@gmail.com>][Date: Thu, 19 Jan 2017 16:57:47 -0000]=>505635089.zip=>8970_ZIP.zip=>8970.doc VB:Trojan.MSWord.Downloader.CD Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(203).vir=>word/vbaProject.bin W97M.Bendis.CC Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(202).vir=>[Subject: uk_confirmation_ph398437058.pdf][Date: Thu, 30 Mar 2017 17:36:06 +0530]=>uk_confirmation_ph398437058.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715278 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(57).vir=>[Subject: Please recheck your delivery address (UPS parcel 06520201)][Date: Sun, 2 Jul 2017 04:03:54 +0800]=>UPS-Package-06520201.zip=>(dummy) JS.TeslaCrypt.4.Gen Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(200).vir=>[Subject: CCE28122017_004928][Date: Thu, 28 Dec 2017 20:09:58 +0600]=>CCE28122017_004928.7z=>CCE28122017_005204.vbs Trojan.VBS.Downloader.AFR Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(20).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(179).vir=>[From: <g_yorum35@windowslive.com>][Date: Thu, 19 Jan 2017 15:53:03 -0000]=>EMAIL_6161214_[recipient].zip=>32449_ZIP.zip=>32449.doc VB:Trojan.Valyria.138 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(199).vir=>[Subject: Message from KM_C224e][Date: Fri, 02 Jun 2017 15:43:17 +0530]=>skm_c224e31729375367.pdf=>307AKH56YVU512.docm Trojan.GenericKD.5249552 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(195).vir=>[Subject: Emailing: IMG_20171221_855525309, IMG_20171221_558874225, ][Date: Thu, 21 Dec 2017 13:03:01 +0100]=>img_20171221_855525309.7z=>IMG_20171221_968347573.js Trojan.JS.Downloader.IGE Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(142).vir=>[Subject: Re: P.0 18003.][Date: Thu, 6 Aug 2015 03:01:35 -0700]=>P.O_18003.jar=>c/CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class Trojan.Java.Adwind.P Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(212).vir=>[Subject: 24007 [recipient]][Date: Thu, 27 Apr 2017 11:07:14 -0000]=>1473818521163.zip=>(dummy) Trojan.Oroles.Gen.8 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(111).vir=>[Subject: Receipt 77077-14409][Date: Mon, 24 Oct 2016 19:26:36 +0530]=>Receipt=>Receipt 34469-690103.wsf Trojan.JS.Downloader.FXY Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(142).vir=>[Subject: Re: P.0 18003.][Date: Thu, 6 Aug 2015 03:01:35 -0700]=>P.O_18003.jar=>CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzf.class Trojan.Java.Adwind.P Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(192).vir=>[Subject: Status of invoice][Date: Mon, 18 Sep 2017 20:55:39 +0700]=>a2176576-71.7z=>32028947946.vbs Trojan.VBS.Downloader.ADV Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(188).vir=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(185).vir=>xl/vbaProject.bin W97M.Downloader.EVY Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(17).vir=>[Subject: Fw:][Date: Tue, 12 Jul 2016 16:02:19 +0200]=>susan_copies_104906.zip=>-SWIFT-43f-.js Generic.JS.DownloaderAG.04355846 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(19).vir=>[Subject: Re: Enquiry][Date: Thu, 6 Aug 2015 02:38:03 -0700]=>P.O_001_UST-TRADE.jar=>CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class Java.Trojan.GenericGB.19948 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(105).vir=>[Subject: File COPY.29112016.2456.XLS Sent 29=>11=>2016][Date: Tue, 29 Nov 2016 23:30:00 +0700]=>COPY.29112016.2456.XLS=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(180).vir=>xl/vbaProject.bin X97M.Downloader.CL Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(176).vir=>[Subject: Budget report][Date: Mon, 12 Sep 2016 20:57:22 +0700]=>fb1fe573a08d.zip=>863AEEA3 Budget_report_xls - 1.js Generic.JS.NemucodA.AD350CF4 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(19).vir=>[Subject: Re: Enquiry][Date: Thu, 6 Aug 2015 02:38:03 -0700]=>P.O_001_UST-TRADE.jar=>Main.class Trojan.Java.Adwind.P Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(265).vir=>[Subject: IMG_5890.GIF][Date: Wed, 09 Aug 2017 03:50:51 +0700]=>img_5890.zip=>IMG_2361.js=>(INFECTED_JS) JS:Trojan.Downloader.JTQX Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(176).vir=>[Subject: Budget report][Date: Mon, 12 Sep 2016 20:57:22 +0700]=>fb1fe573a08d.zip=>863AEEA3 Budget_report_xls.js Generic.JS.NemucodA.AD350CF4 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(19).vir=>[Subject: Re: Enquiry][Date: Thu, 6 Aug 2015 02:38:03 -0700]=>P.O_001_UST-TRADE.jar=>CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzf.class Trojan.Java.Adwind.P Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(165).vir=>[Subject: File COPY.29112016.6922.XLS Sent 29=>11=>2016][Date: Tue, 29 Nov 2016 16:03:09 +0200]=>COPY.29112016.6922.XLS=>xl/vbaProject.bin Trojan.MSWord.Downloader.AS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(164).vir=>[Subject: ][Date: Wed, 02 Aug 2017 12:34:09 -0000]=>EMAIL_3365126820_[recipient].zip=>40613.zip=>pHzI.js=>(INFECTED_JS) JS:Trojan.Cryxos.1223 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(177).vir=>[From: <info@snowandice.com>][Date: Wed, 18 Jan 2017 15:12:28 -0000]=>EMAIL_89868_[recipient].zip=>(dummy) Trojan.Oroles.Gen.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(163).vir=>[Subject: Updated][Date: Tue, 28 Jun 2016 01:17:19 +0300]=>update_greg_015676.zip=>swift c9eb.js Generic.JS.DownloaderAG.1508ACD3 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(16).vir VB:Trojan.Agent.CZVU Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(130).vir VB:Trojan.Valyria.11 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(211).vir Trojan.Doc.Agent.FC Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(179).vir=>[From: <g_yorum35@windowslive.com>][Date: Thu, 19 Jan 2017 15:53:03 -0000]=>EMAIL_6161214_[recipient].zip=>(dummy) Trojan.Oroles.Gen.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(151).vir=>[Subject: Emailing: 3772626][Date: Mon, 04 Dec 2017 17:54:50 +0530]=>3772626.7z=>IMG_9198.vbs Trojan.GenericKD.12653163 Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(147).vir=>[From: <panakova@technicalmuseum.cz>][Date: Thu, 19 Jan 2017 14:35:12 -0000]=>EMAIL_608170693_[recipient].zip=>13622_ZIP.zip=>13622.doc VB:Trojan.Valyria.138 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(128).vir=>[Subject: uk_confirmation_ph937798943.pdf][Date: Thu, 30 Mar 2017 17:09:02 +0530]=>uk_confirmation_ph937798943.zip=>uk_confirmation_ph954869378.zip=>uk_confirmation_ph954869378.exe Trojan.GenericKD.4715170 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(14).vir=>[Subject: Document invoice_252_sign_and_return.pdf is complete][Date: Tue, 10 Oct 2017 15:54:30 +0530]=>invoice_252_sign_and_return.7z=>invoice_12397_sign_and_return.vbs VB:Trojan.Agent.COFZ Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(12).vir=>[Subject: Payment Invoice #08152][Date: Tue, 3 Apr 2018 22:02:18 +0800]=>DOC2708740260.zip=>DOC2708740260.js Trojan.GenericKD.30537540 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(134).vir=>[Subject: CCE26122017_000092][Date: Tue, 26 Dec 2017 21:54:53 +0700]=>CCE26122017_000092.7z=>CCE26122017_43632.js Trojan.JS.Downloader.IGK Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(131).vir=>[Subject: Invoice][Date: Wed, 01 Nov 2017 17:03:59 +0530]=>328731_Invoice.doc Trojan.GenericKD.6180824 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(132).vir=>[Subject: Copy_74025343][Date: Wed, 27 Dec 2017 21:06:49 +0430]=>copy_74025343.7z=>File_42284200.js Trojan.JS.Downloader.IGK Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(103).vir=>[Subject: [ IMPORTANTE ] DENUNCIA DE RACISMO EM SEU PERFIL - 5301438][Date: Fri, 4 Nov 2016 12:30:22 +0000 (UTC)]=>(message body) Trojan.Scam.LN Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(147).vir=>[From: <panakova@technicalmuseum.cz>][Date: Thu, 19 Jan 2017 14:35:12 -0000]=>EMAIL_608170693_[recipient].zip=>(dummy) Trojan.Oroles.Gen.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(113).vir=>[Subject: ][Date: Tue, 03 Oct 2017 22:48:33 -0000]=>28275.zip=>17317.zip=>17317.js=>(INFECTED_JS) JS:Trojan.Cryxos.1289 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(119).vir VB:Trojan.VBA.Agent.KD Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(142).vir=>[Subject: Re: P.0 18003.][Date: Thu, 6 Aug 2015 03:01:35 -0700]=>P.O_18003.jar=>Main.class Trojan.Java.Adwind.P Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(118).vir=>[Subject: Please find attached a XLS Invoice 844370][Date: Tue, 29 Nov 2016 12:38:56 +0200]=>INVOICE.TAM_844370_20161129_3B7365ECB.xls Trojan.GenericKD.3790182 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(114).vir=>[Subject: Xenos Allen][Date: Tue, 10 May 2016 20:31:23 +0700]=>181j28.3797-x.dot=>word/vbaProject.bin W97M.Downloader.CDS Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(104).vir=>[Subject: Scanned image][Date: Wed, 06 Dec 2017 19:48:53 +0530]=>20171206262405.7z=>20171206506954.vbs Trojan.GenericKD.12659047 Moved to Quarantine
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(107).vir W97m.Downloader.GNQ Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(101).vir=>[Subject: ACH Payment Advice][Date: Thu, 03 May 2018 10:27:30 -0600]=>Scan.doc VB:Trojan.Valyria.1734 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(110).vir=>[Subject: Image][Date: Mon, 12 Sep 2016 09:21:38 -0400]=>IG_20160830_9_9_01_Pro.zip=>05omKt2S13.wsf Gen:Heur.JS.Downloader.2 Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(10).vir=>[Subject: Lisa Maloney manager FedEx][Date: Wed, 28 Mar 2018 22:00:29 +0100]=>TF.48678398483.zip=>TF.48678398483/TF.48678398483.bat Generic.Bat.Downloader.1.97D29B5A Deleted
- C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\VirusSamples_50\Samp(115).vir=>[Subject: 1 Unread Message of High Priority][Date: Tue, 03 May 2016 14:23:47 +0200]=>detail_robert_919012.zip=>finInfo6506.js=>(INFECTED_JS)
复制代码
|