发现一个现象:
红伞对这堆样本在第一次右键扫描时一概以Virut家族实行清除操作 实时监控好像把修复后的产物又检测了一遍,还动用了APC和AGEN定义。
这也是第一见到APC在读写监控时就触发。
右键扫描的日志:
- 11/16/2018,01-56-19 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\proquota.exe'
- 11/16/2018,01-56-19 [INFO] e:\samples\被感染文件\proquota.exe
- 11/16/2018,01-56-19 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-19 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\rrinstaller.exe'
- 11/16/2018,01-56-19 [INFO] e:\samples\被感染文件\rrinstaller.exe
- 11/16/2018,01-56-19 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-19 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\rstrui.exe'
- 11/16/2018,01-56-19 [INFO] e:\samples\被感染文件\rstrui.exe
- 11/16/2018,01-56-19 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-19 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\runlegacycplelevated.exe'
- 11/16/2018,01-56-19 [INFO] e:\samples\被感染文件\runlegacycplelevated.exe
- 11/16/2018,01-56-19 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\runonce.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\runonce.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\rwinsta.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\rwinsta.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\subst.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\subst.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\sxstrace.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\sxstrace.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\synchost.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\synchost.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\unlodctr.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\unlodctr.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\upnpcont.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\upnpcont.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\utilman.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\utilman.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\vaultcmd.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\vaultcmd.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\vds.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\vds.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\vdsldr.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\vdsldr.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\vssadmin.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\vssadmin.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\vssvc.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\vssvc.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\w32tm.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\w32tm.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\waitfor.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\waitfor.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wallpaperhost.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\wallpaperhost.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-20 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wbadmin.exe'
- 11/16/2018,01-56-20 [INFO] e:\samples\被感染文件\wbadmin.exe
- 11/16/2018,01-56-20 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wevtutil.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\wevtutil.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wextract.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\wextract.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wfs.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\wfs.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\where.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\where.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\whoami.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\whoami.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wiaacmgr.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\wiaacmgr.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\wimserv.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\wimserv.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\windowsanytimeupgraderesults.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\windowsanytimeupgraderesults.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\bfsvc.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\bfsvc.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\helppane.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\helppane.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\hh.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\hh.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\msra.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\msra.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\notepad.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\notepad.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-21 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\nslookup.exe'
- 11/16/2018,01-56-21 [INFO] e:\samples\被感染文件\nslookup.exe
- 11/16/2018,01-56-21 [INFO] [DETECTION] file contains 'W32/Virut.Gen'
- 11/16/2018,01-56-24 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\被感染文件\proquota.exe'
复制代码
隔离区里有APC的字样
|