查看: 1585|回复: 5
收起左侧

[病毒样本] Kovter-Nemucod勒索

[复制链接]
3245076553
发表于 2018-11-18 18:49:06 | 显示全部楼层 |阅读模式
静影沉璧
发表于 2018-11-18 19:01:15 | 显示全部楼层
EMSI

C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\Kovter-Nemucod勒索 密码:infected\c2556.bat  Trojan.BAT.Poweliks.Gen (B)
C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\Kovter-Nemucod勒索 密码:infected\UPS-Parcel-ID-003634085.doc.js  Trojan-Downloader.Nemucod (A)
C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\Kovter-Nemucod勒索 密码:infected\UPS-Delivery-01049711.doc.js  Trojan-Downloader.Nemucod (A)
C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\Kovter-Nemucod勒索 密码:infected\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK2.exe  Trojan.Generic.21981039 (B)
C:\Users\Administrator.SXCSXC-AJKJJUBR\Desktop\Kovter-Nemucod勒索 密码:infected\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.php  Trojan.GenericKD.3003338 (B)

BE_HC
发表于 2018-11-18 19:11:39 | 显示全部楼层
Norton Kill 9x Repair 4x
  1. Resolved Threats:
  2. JS.Downloader
  3. Type: Compressed
  4. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  5. Categories: Virus
  6. Status: Fully Resolved
  7. -----------
  8. 1 Infected File
  9. [ups-delivery-01049711.doc.js] inside of [c:\users\drclef\desktop\s\ups-delivery-01049711.zip] - Deleted


  10. JS.Downloader
  11. Type: Compressed
  12. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  13. Categories: Virus
  14. Status: Fully Resolved
  15. -----------
  16. 1 Infected File
  17. [ups-parcel-id-003634085.doc.js] inside of [ups-parcel-id-003634085.zip] inside of [c:\users\drclef\desktop\s\2017-07-09-kovter-malspam-1439-utc.eml] - Deleted


  18. JS.Downloader
  19. Type: Compressed
  20. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  21. Categories: Virus
  22. Status: Fully Resolved
  23. -----------
  24. 1 Infected File
  25. [ups-parcel-id-003634085.doc.js] inside of [c:\users\drclef\desktop\s\ups-parcel-id-003634085.zip] - Deleted


  26. JS.Downloader
  27. Type: Compressed
  28. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  29. Categories: Virus
  30. Status: Fully Resolved
  31. -----------
  32. 1 Infected File
  33. [ups-delivery-01049711.doc.js] inside of [ups-delivery-01049711.zip] inside of [c:\users\drclef\desktop\s\2017-07-10-kovter-malspam-1020-utc.eml] - Deleted


  34. JS.Downloader
  35. Type: Anomaly
  36. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  37. Categories: Virus
  38. Status: Fully Resolved
  39. -----------
  40. 2 Infected Files
  41. C:\Users\DrClef\Desktop\s\UPS-Delivery-01049711.doc.js - Deleted
  42. C:\Users\DrClef\Desktop\s\UPS-Parcel-ID-003634085.doc.js - Deleted
  43. 1 Browser Cache



  44. Trojan.Gen.NPE
  45. Type: Anomaly
  46. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  47. Categories: Virus
  48. Status: Fully Resolved
  49. -----------
  50. 3 Infected Files
  51. C:\Users\DrClef\Desktop\s\UPS-Delivery-01049711.doc.js - No Action Required
  52. C:\Users\DrClef\Desktop\s\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.php - Deleted
  53. C:\Users\DrClef\Desktop\s\UPS-Parcel-ID-003634085.doc.js - No Action Required
  54. 1 Browser Cache



  55. Ransom.Nemucod.B!php
  56. Type: Anomaly
  57. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  58. Categories: Virus
  59. Status: Fully Resolved
  60. -----------
  61. 1 Infected File
  62. C:\Users\DrClef\Desktop\s\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.php - No Action Required
  63. 1 Browser Cache



  64. Trojan.Malscript
  65. Type: Anomaly
  66. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  67. Categories: Virus
  68. Status: Fully Resolved
  69. -----------
  70. 1 Infected File
  71. C:\Users\DrClef\Desktop\s\2017-07-10-www.shisashop.com-domiains-shaishopcom-counter.txt - Deleted
  72. 1 Browser Cache



  73. Trojan.Gen.7
  74. Type: Anomaly
  75. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  76. Categories: Heuristic Virus
  77. Status: Fully Resolved
  78. -----------
  79. 1 Infected File
  80. C:\Users\DrClef\Desktop\s\2017-07-10-www.shisashop.com-domiains-shaishopcom-counter.txt - No Action Required
  81. 1 Browser Cache



  82. Ransom.Kovter
  83. Type: Anomaly
  84. Risk: High (High Stealth, High Removal, High Performance, High Privacy)
  85. Categories: Virus
  86. Status: Fully Resolved
  87. -----------
  88. 1 Infected File
  89. C:\Users\DrClef\Desktop\s\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK2.exe - Deleted
  90. 1 Browser Cache
复制代码

dreams521
发表于 2018-11-18 19:29:21 | 显示全部楼层
  1. 18.11.2018 19.28.28;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\2017-07-09-Kovter-malspam-1439-UTC.eml;C:\Users\Administrator\Desktop\123\2017-07-09-Kovter-malspam-1439-UTC.eml;11/18/2018 19:28:28
  2. 18.11.2018 19.28.28;检测到的对象 ( 邮件附件 ) 已删除;C:\Users\Administrator\Desktop\123\2017-07-09-Kovter-malspam-1439-UTC.eml//UPS-Parcel-ID-003634085.zip//UPS-Parcel-ID-003634085/UPS-Parcel-ID-003634085.doc.js;C:\Users\Administrator\Desktop\123\2017-07-09-Kovter-malspam-1439-UTC.eml//UPS-Parcel-ID-003634085.zip//UPS-Parcel-ID-003634085/UPS-Parcel-ID-003634085.doc.js;HEUR:Trojan.Script.Agent.gen;木马程序;11/18/2018 19:28:28
  3. 18.11.2018 19.28.28;检测到的对象 ( 邮件附件 ) 已删除;C:\Users\Administrator\Desktop\123\2017-07-10-Kovter-malspam-1020-UTC.eml//UPS-Delivery-01049711.zip//UPS-Delivery-01049711/UPS-Delivery-01049711.doc.js;C:\Users\Administrator\Desktop\123\2017-07-10-Kovter-malspam-1020-UTC.eml//UPS-Delivery-01049711.zip//UPS-Delivery-01049711/UPS-Delivery-01049711.doc.js;HEUR:Trojan.Script.Agent.gen;木马程序;11/18/2018 19:28:28
  4. 18.11.2018 19.28.28;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\2017-07-10-Kovter-malspam-1020-UTC.eml;C:\Users\Administrator\Desktop\123\2017-07-10-Kovter-malspam-1020-UTC.eml;11/18/2018 19:28:28
  5. 18.11.2018 19.28.18;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\UPS-Delivery-01049711.doc.js;C:\Users\Administrator\Desktop\123\UPS-Delivery-01049711.doc.js;HEUR:Trojan.Script.Agent.gen;木马程序;11/18/2018 19:28:18
  6. 18.11.2018 19.28.18;检测到的对象 ( 文件 ) 已被清除;C:\Users\Administrator\Desktop\123\UPS-Delivery-01049711.zip;C:\Users\Administrator\Desktop\123\UPS-Delivery-01049711.zip;11/18/2018 19:28:18
  7. 18.11.2018 19.28.18;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\UPS-Delivery-01049711.zip//UPS-Delivery-01049711/UPS-Delivery-01049711.doc.js;C:\Users\Administrator\Desktop\123\UPS-Delivery-01049711.zip//UPS-Delivery-01049711/UPS-Delivery-01049711.doc.js;HEUR:Trojan.Script.Agent.gen;木马程序;11/18/2018 19:28:18
  8. 18.11.2018 19.28.17;检测到的对象 ( 文件 ) 已被清除;C:\Users\Administrator\Desktop\123\UPS-Parcel-ID-003634085.zip;C:\Users\Administrator\Desktop\123\UPS-Parcel-ID-003634085.zip;11/18/2018 19:28:17
  9. 18.11.2018 19.28.17;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\UPS-Parcel-ID-003634085.zip//UPS-Parcel-ID-003634085/UPS-Parcel-ID-003634085.doc.js;C:\Users\Administrator\Desktop\123\UPS-Parcel-ID-003634085.zip//UPS-Parcel-ID-003634085/UPS-Parcel-ID-003634085.doc.js;HEUR:Trojan.Script.Agent.gen;木马程序;11/18/2018 19:28:17
  10. 18.11.2018 19.28.16;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\UPS-Parcel-ID-003634085.doc.js;C:\Users\Administrator\Desktop\123\UPS-Parcel-ID-003634085.doc.js;HEUR:Trojan.Script.Agent.gen;木马程序;11/18/2018 19:28:16
  11. 18.11.2018 19.28.16;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\2017-07-10-www.shisashop.com-domiains-shaishopcom-counter.txt;C:\Users\Administrator\Desktop\123\2017-07-10-www.shisashop.com-domiains-shaishopcom-counter.txt;Trojan.JS.Agent.dyn;木马程序;11/18/2018 19:28:16
  12. 18.11.2018 19.28.15;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK2.exe;C:\Users\Administrator\Desktop\123\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK2.exe;Trojan.Win32.Poweliks.adtx;木马程序;11/18/2018 19:28:15
  13. 18.11.2018 19.28.15;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.php;C:\Users\Administrator\Desktop\123\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.php;Trojan.PHP.Agent.ss;木马程序;11/18/2018 19:28:15
  14. 18.11.2018 19.28.15;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\123\c2556.bat;C:\Users\Administrator\Desktop\123\c2556.bat;Trojan.VBS.Starter.hj;木马程序;11/18/2018 19:28:15
复制代码
www-tekeze
发表于 2018-11-18 20:05:17 | 显示全部楼层

火绒 kill 8X (其中修复2X),智量不检测文本文件,只 kill 3X 。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
松竹承茂
发表于 2018-11-18 20:56:24 | 显示全部楼层
www-tekeze 发表于 2018-11-18 20:05
火绒 kill 8X (其中修复2X),智量不检测文本文件,只 kill 3X 。

360kill8x
360杀毒扫描日志

病毒库版本:2018-11-18 14:39
扫描时间:2018-11-18 20:53:31
扫描用时:00:00:09
扫描类型:右键扫描
扫描文件总数:15
项目总数:8
清除项目数:8

扫描选项
----------------------
扫描所有文件:否
扫描压缩包:否
发现病毒处理方式:由用户选择处理
扫描磁盘引导区:是
扫描 Rootkit:是
使用云查杀引擎:是
使用QVM人工智能引擎:是
扫描建议修复项:是
常规引擎设置:Avira(小红伞)

扫描内容
----------------------
C:\Windows.old\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.php
C:\Windows.old\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK2.exe
C:\Windows.old\2017-07-09-Kovter-malspam-1439-UTC.eml
C:\Windows.old\2017-07-10-Kovter-malspam-1020-UTC.eml
C:\Windows.old\2017-07-10-www.shisashop.com-domiains-shaishopcom-counter.txt
C:\Windows.old\c2556.bat
C:\Windows.old\DECRYPT.hta
C:\Windows.old\e2c39.733a25
C:\Windows.old\UPS-Delivery-01049711.doc.js
C:\Windows.old\UPS-Delivery-01049711.zip
C:\Windows.old\UPS-Parcel-ID-003634085.doc.js
C:\Windows.old\UPS-Parcel-ID-003634085.zip
C:\Windows.old\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.bmp
C:\Windows.old\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.doc
C:\Windows.old\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK.exe


白名单设置
----------------------


扫描结果
======================
高危风险项
----------------------
C:\Windows.old\15FEWz6pAjz1k2pNFtGLHddjxHq2G8LmjK2.exe        TR.Crypt.XPACK.vmdzw        已删除
C:\Windows.old\c2556.bat        感染型病毒(Win32/Trojan.script.f44)        已删除
C:\Windows.old\UPS-Delivery-01049711.doc.js        virus.js.qexvmc.1        已删除
C:\Windows.old\2017-07-09-Kovter-malspam-1439-UTC.eml        virus.js.qexvmc.1        已删除
C:\Windows.old\2017-07-10-Kovter-malspam-1020-UTC.eml        virus.js.qexvmc.1        已删除
C:\Windows.old\UPS-Parcel-ID-003634085.doc.js        virus.js.qexvmc.1        已删除
C:\Windows.old\UPS-Delivery-01049711.zip        virus.js.qexvmc.1        已删除
C:\Windows.old\UPS-Parcel-ID-003634085.zip        virus.js.qexvmc.1        已删除



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-26 09:21 , Processed in 0.128652 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表