楼主: Jerry.Lin
收起左侧

[病毒样本] 【开放测试】卡饭病毒样本包 第四十五期 20190315

  [复制链接]
Miostartos
发表于 2019-3-15 21:28:35 | 显示全部楼层
BE_HC 发表于 2019-3-15 21:12
Norton扫这种大包慢的。。。打开日记还可以UI崩掉。。。

我这不慢而且不崩。
不要让自动防护处理啊。
BE_HC
发表于 2019-3-15 21:37:44 | 显示全部楼层
STCn1000 发表于 2019-3-15 21:28
我这不慢而且不崩。
不要让自动防护处理啊。

不是,我默认关掉自动防护扫,扫完在处理的时候自动防护自己就开了。。
Miostartos
发表于 2019-3-15 21:46:11 | 显示全部楼层
BE_HC 发表于 2019-3-15 21:37
不是,我默认关掉自动防护扫,扫完在处理的时候自动防护自己就开了。。

你要做的是专门给个测试文件夹加自动防护排除。而不是关掉。
ziyerain2015
发表于 2019-3-15 21:50:54 | 显示全部楼层
你好,再见 发表于 2019-3-15 20:33
你电脑速度真快,21个每秒,我这里才7个。。。

一台没有很老很老的酷睿2的笔记本4G内存,装了个TV9用来杀毒哈哈
Sailer.X 该用户已被删除
发表于 2019-3-15 22:04:59 来自手机 | 显示全部楼层
本帖最后由 霄栋 于 2019-3-15 22:09 编辑
裂空我爱杰 发表于 2019-3-15 21:26
看了下,BD和卡巴斯基还是一如既往的稳定。支持一波。
不知道BDF的引擎和收费版是不是一样。

版本基本是一致的,主要防护功能(特征引擎,云,主防,反入侵等)都在,不过bdf的更新策略更激进一些,有时候会优先使用一些新的模块,这可能导致检测率与家庭版不一致,同时也可能存在稳定性问题。例如,bdf之前率先更新ctc heur模块,该模块在bd2019才加入家庭版;今年也是bdf先更新了bd的第二代漏洞防御组件gemma,后来才同步到家庭版。这阵子bdf的特征库似乎又加了点新东西,同时出现了独立的主防进程(atchost),估计bd又有些新动作。但老实说,从我个人的测试来看,bdf的新组件带来的检测率变化并不明显,稳定性倒确实差一些(我这里遇见过多次无法加载特征库的bug,以及主进程反复异常重启)。我个人仍然倾向于bdf就是家庭版的试验田,所以追求稳定的话还是推荐使用家庭版(虽然家庭版bug也不少,像搜索建议失效,otp排除失效,atd日志丢失等)。如果喜欢尝鲜且不介意遇到一些更严重的bug(主进程崩溃,无法更新组件等)倒是可以试试bdf。

评分

参与人数 1人气 +3 收起 理由
静影沉璧 + 3 感谢解答: )

查看全部评分

petr0vic
发表于 2019-3-15 22:28:17 | 显示全部楼层
测试环境:WIN10 1703  64 实机
测试产品:DrWeb
测试项目:扫描
结果:(57/82)69,51%
  1. Kafan_Sample_0351e4f1b5fcd2ea0ebf370033c59e9f1aa4122a78fb4bd69190f49f893ef83f.exe infected with Trojan.Nanocore.427
  2. Kafan_Sample_047df77f3370052fcf5b5bd5e8dccc0274ff51bb43506dff29884394a2c59793.exe infected with Trojan.Siggen8.16221
  3. Kafan_Sample_067c930e219da0b0c7df46187abc1847d05f0c9391f2a3967e84de7e649972ce.exe infected with Trojan.DownLoader23.54074
  4. Kafan_Sample_09160f0aae57d08465220b38564145642c38e99ba27174356eae3229922ed187.exe infected with Trojan.Siggen8.16564
  5. Kafan_Sample_0ac19ab365d9770ce556fad288f23413c48c054e164d635610011f7e6baef8c0.exe infected with Trojan.Siggen8.16564
  6. Kafan_Sample_10a2e2df9177d431480a8f3fe0a4f9472dacded3f3ccdff42365f1d81cad0165.exe infected with Trojan.Siggen8.16606
  7. Kafan_Sample_29a0a0d1c5944549c5b58420c949d38fdf73284e9968aef4bda532f704eb5eee.exe infected with Trojan.Fbng.8
  8. Kafan_Sample_2e814142b2e638b48925b31e247c63cf9dd0b7a989aaacba036a0cd2cfb62681.exe infected with Trojan.Tofsee.39
  9. Kafan_Sample_30df64b624047af61c4fb18c17fc33a7e8add90effd9187c9855db42d762169e.exe infected with Trojan.Siggen8.15861
  10. Kafan_Sample_374250a78e0a695c8cf1d01e0712f4069b342cbac57ec28108eafe9378d87eaf.exe infected with Trojan.DownLoader13.38206
  11. Kafan_Sample_39b6dfab8f231ff31018f7ff986624dc8b1745ac4ea3e895957946253a633b1f.exe infected with Trojan.DownLoader13.38206
  12. Kafan_Sample_3f5aafc60f2ca9904f6cefb6b2a00aead15bd5c1c9df368e7460cbb4b8eb9567.exe infected with Trojan.DownLoader27.37984
  13. Kafan_Sample_430247204787a502d6cd184b5e98ba868be61d747760b904ae18f22698e31361.exe infected with Trojan.Packed2.41590
  14. Kafan_Sample_4371d4f7e36191c22ecd9255128e0d62fac8c7eed8c285a1db53374720dbd453.exe infected with Trojan.StartPage1.30721
  15. >>Kafan_Sample_44d2a8f16a2874b2d2efa9e60ad14066540971f7203ec5140ea94deebaec7055.exe/Users\ANOBS\AppData\Local\AutoIt v3\Aut2Exe\aut3A5F.tmp.tok - infected with Trojan.PWS.Pony.26
  16. Kafan_Sample_44d2a8f16a2874b2d2efa9e60ad14066540971f7203ec5140ea94deebaec7055.exe - archive contains infected objects
  17. Kafan_Sample_4f7e7f92490f842f753dfabe5e2d93965b806ce62248195df73b268a9b8b830a.exe infected with Trojan.Nanocore.23
  18. Kafan_Sample_5362910a979e699123b47dcf85e1727f9f42de805934937161b1b3b8c2c439ef.exe infected with Trojan.PWS.Stealer.19347
  19. Kafan_Sample_551aabcba9d35ea99a4108d5853e46e277ed8624c79c657ec1c6e8e3a58a818b.exe infected with Trojan.PWS.Stealer.21377
  20. Kafan_Sample_5d11d75dc9ecba71d33f246f0f277ffec929402f96c132d186a398e6942ffb7e.exe infected with Trojan.Siggen8.16205
  21. Kafan_Sample_5df4693945481747d9f9c37a48553cce6efcf7676ad564cbb63298129bf3a17f.exe infected with Trojan.Nanocore.499
  22. >Kafan_Sample_5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120.exe/data001 - infected with Trojan.DownLoader13.38206
  23. >>>Kafan_Sample_5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120.exe/data002/Users\USER\AppData\Local\AutoIt v3\Aut2Exe\aut47AC.tmp.tok - infected with Trojan.PWS.Pony.36
  24. >Kafan_Sample_5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120.exe/data002 - archive contains infected objects
  25. >Kafan_Sample_5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120.exe/data003 - infected with BackDoor.Quasar.1
  26. Kafan_Sample_5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120.exe - archive contains infected objects
  27. Kafan_Sample_65f750af58456ce7ff79936dba02c53bb4802f0c9acd81e7e37039a21ed06063.exe infected with Trojan.DownLoader24.65022
  28. Kafan_Sample_68bb279723aa175b1cbaa567c0e0d6a8a17e6886501ff311493813a15e4e6176.exe infected with Trojan.Siggen8.16119
  29. >Kafan_Sample_69ff04aa3967dd2747e33cd97e7517026d49eaf13340774b6a0d5d7fd95ac35f.exe/data006 - is a hacktool Tool.Equation.32
  30. Kafan_Sample_69ff04aa3967dd2747e33cd97e7517026d49eaf13340774b6a0d5d7fd95ac35f.exe - archive contains infected objects
  31. Kafan_Sample_6db4a008383e5a63ec5405aadec49e702e25a426bd159bf8729ba725823379f1.exe infected with Trojan.DownLoader27.27645
  32. Kafan_Sample_6ddd0ce0a815da44d73286130cf49016830b2f18329e65c4f54f487e910b0fe3.exe infected with Trojan.Encoder.26818
  33. Kafan_Sample_70e78c8fb63161bfbcb877ff9fb126daffd960ceab3d209422161b109d53f60e.exe infected with Trojan.Encoder.26818
  34. Kafan_Sample_7218993e1163f824a450cd8f997483ead16982e89c82000f3c3a90731dc0320b.exe infected with Trojan.Siggen8.16564
  35. Kafan_Sample_73101f348a0e5cfc7527ec024f367aca774f282a0d040bd2df76fc922e7c37c0.exe infected with Trojan.PWS.Stealer.25515
  36. Kafan_Sample_77aa1c5b69b9514c852dda17080b2dceb725b5c9fe7d38d26aec03bc3a5a99f4.exe infected with Trojan.Trick.46210
  37. Kafan_Sample_77c3ff05ac628664156b8b36d875ac63692a67d748338ddcf6912457184f8a25.exe infected with Trojan.PWS.Stealer.19347
  38. Kafan_Sample_7db4e826433bd6b2e75804cae202113ae10b7f1e48633eb577b60b7f6c5e3457.exe infected with Trojan.PWS.Stealer.23680
  39. Kafan_Sample_8ad82ffc1771372a1bb2bf6951f7709870220a8223d688589052fb4577780b39.exe infected with Trojan.Siggen8.16161
  40. Kafan_Sample_96a1c05c25331e549ac46cd52b4278f7d6d0d28d3b50664f9bb3e46c702e5f62.exe infected with Trojan.DownLoader13.38206
  41. Kafan_Sample_9a86202cf00ac850f340090faebbab0404d6b93d46f0ad61f1b96646ee2896c0.exe infected with Trojan.Siggen8.16254
  42. Kafan_Sample_a2269ea055a7ea6dfc5065b6f69854b9702d94d97af43f8c2c50342f9cf62195.exe infected with Trojan.DownLoader27.33753
  43. Kafan_Sample_a4ea64ffd4cd2773f361d3ef1788781b96be25fbcb19693d32c887b28aedf514.exe infected with Trojan.PWS.Stealer.15120
  44. Kafan_Sample_a572affb06e0d690b025788717a52d9be709b0aedc38db40f37f995bf484a00b.exe infected with Trojan.Siggen8.16161
  45. Kafan_Sample_b3a8a530b7c7e481d6516e001dbb9f0caafd8b0efaa368a1fac142a6ff8517ed.exe infected with Trojan.DownLoader27.33753
  46. Kafan_Sample_ba54f698cf9664219ab8587b72a9a8e4bd252e51f49b47c6abe7d2d9697e8d91.exe infected with Trojan.Siggen8.16646
  47. >Kafan_Sample_ba7ef373c14a528700345e17ccb2b41c367532fadb2130be1d691ccf6d7600df.exe/ADDSTA~2.EXE - infected with Trojan.Siggen8.16626
  48. Kafan_Sample_ba7ef373c14a528700345e17ccb2b41c367532fadb2130be1d691ccf6d7600df.exe - archive contains infected objects
  49. Kafan_Sample_bbee13b6aa523df726fd16899abd2f717595cacdee5f85ab7e5a1b735bb8662f.exe infected with Win32.FloodFix.7
  50. Kafan_Sample_bf301895350bac4b2e0ef38955637782b49d77e1eb12e06f6e3f4d781512f313.exe infected with Trojan.DownLoader27.33753
  51. Kafan_Sample_c02ffc07d7e1246d920cf82e2e06c007296b4ff6f6b8af5584267e6ef674443b.exe infected with Trojan.Nanocore.24
  52. Kafan_Sample_c50167d9a899572e7dba0da1d80e3b9a94b2d3803a8f125119097ed5f92add6d.exe infected with Trojan.Encoder.27479
  53. Kafan_Sample_d7a930096fb7265fc09d94238a35ea931eced0ce53654f5e6f8e7ab3c5a9cf89.exe infected with Trojan.Fbng.8
  54. Kafan_Sample_dfd6310aca41781df8d04b9d2c1c4cbcc9bc77911e715592fe14285df0690a9d.exe infected with Trojan.Trick.46210
  55. >>Kafan_Sample_e340a007f89f90ca9b24124d74ef6730bb68a442da433e83fa398cf07a975819.exe/Users\Peter Kamau\AppData\Local\AutoIt v3\Aut2Exe\autFDBD.tmp.tok - infected with Trojan.PWS.Pony.36
  56. Kafan_Sample_e340a007f89f90ca9b24124d74ef6730bb68a442da433e83fa398cf07a975819.exe - archive contains infected objects
  57. Kafan_Sample_e62c7165911c2d7dce44e61d94a06b3e5f50bc77f5cdb033a3c98ef76b408be8.exe infected with Trojan.Packed2.41525
  58. Kafan_Sample_e77e47cd626affe1105519365258a01fa5046250bfc825885d15c15fc8255ab9.exe infected with BackDoor.Remcos.80
  59. >Kafan_Sample_e7d643331bbacc455e5b28876cdc58409d1d3408e9769dc88e1eebc5b050b20b.exe infected with Trojan.Fbng.8
  60. Kafan_Sample_e9dbe28e22b669f5b1bec91209e5a34186052da771435eb321ba28da3eec4fbc.exe infected with Trojan.Vittalia.17867
  61. Kafan_Sample_ebdea0461935c7dae8409e442e5757c91cec88cb6b4e674c6adf217971913e94.exe infected with Trojan.Trick.46210
  62. Kafan_Sample_f7c7e52276e12dad6412fa7a739401f99ead69543fd4686c696af82550c9f341.exe infected with Trojan.Packed2.41525
  63. Kafan_Sample_f830cbc35f6eb21f7e9f28cc88290db13662551f6a9994b06ada7caf4cd79b2f.exe infected with Trojan.Packed2.41525
  64. Kafan_Sample_fc6f5675a96d62ae37fdd3aa103d2050bffe1ee62238bbd3ba78eab4ed84eab4.exe infected with Trojan.DownLoader22.41353
  65. >>>>Kafan_Sample_fccb6eaceff1a6d9822c0beb903fa981630b38fb202d906b2f3440fadca01c29.exe infected with Trojan.DownLoader14.35508
复制代码



记录微笑
发表于 2019-3-15 22:36:20 | 显示全部楼层
小Q机器人 发表于 2019-3-15 21:04
经典HitmanPro 3.8 最新版 多引擎云反病毒扫描器    100%查杀
  扫描器包括(卡巴+BD+自动引 ...

坛友你好,我是论坛督察whl2606555,请以后不要使用会影响其他坛友阅读的字体和背景色。
小Q机器人
发表于 2019-3-15 22:42:30 | 显示全部楼层
whl2606555 发表于 2019-3-15 22:36
坛友你好,我是论坛督察whl2606555,请以后不要使用会影响其他坛友阅读的字体和背景色。

好的谢谢提醒,以后不会了
B100D1E55
发表于 2019-3-16 04:00:13 | 显示全部楼层
本帖最后由 B100D1E55 于 2019-3-16 09:54 编辑


3月3日库扫描28X,剩余54X
Hash 3月3日库 3月15日库(家族)
2e2944bbcf94bc44ef10c3029df5afbd1195872198aaad0cda3bac638f953bee MISS混淆器(自动)
2e814142b2e638b48925b31e247c63cf9dd0b7a989aaacba036a0cd2cfb62681AMS:Tofsee.AX混淆器
3fbabe52d536722de8b22a557d8c3a56832f7cbc05b3e03cb3344c65e14affa9AMS: Rescoms.B混淆器(自动)
4f7e7f92490f842f753dfabe5e2d93965b806ce62248195df73b268a9b8b830aMISS混淆器
05c81fdeabbd82516ec8dd2bdd663577049208b968110d143e0d73ae37ff6307MISS混淆器
5d11d75dc9ecba71d33f246f0f277ffec929402f96c132d186a398e6942ffb7eMISS注入器
5df4693945481747d9f9c37a48553cce6efcf7676ad564cbb63298129bf3a17fMISS注入器
7db4e826433bd6b2e75804cae202113ae10b7f1e48633eb577b60b7f6c5e3457AMS: Fareit混淆器
8ad82ffc1771372a1bb2bf6951f7709870220a8223d688589052fb4577780b39MISS注入器
8ff9a8a043ceb2e95d7f83f6317f3f777ec4b0cebadb3a4db37c5c2d95061a48MISS混淆器(自动)
9a86202cf00ac850f340090faebbab0404d6b93d46f0ad61f1b96646ee2896c0MISSFormbook
10a2e2df9177d431480a8f3fe0a4f9472dacded3f3ccdff42365f1d81cad0165AMS: Emotet混淆器
30df64b624047af61c4fb18c17fc33a7e8add90effd9187c9855db42d762169eAMS: FareitFareit
39b6dfab8f231ff31018f7ff986624dc8b1745ac4ea3e895957946253a633b1fMISS注入器
44d2a8f16a2874b2d2efa9e60ad14066540971f7203ec5140ea94deebaec7055AMS: NanoCoreAutoit注入器
047df77f3370052fcf5b5bd5e8dccc0274ff51bb43506dff29884394a2c59793僵尸网络防御 + AMS: Ursnif自动机
47cee620da66bc2dda3b95f3e1402cede1835f8c68a12c8880eff4e6cd701f8aAMS: FareitFareit
56fa173ed69c171f3d015dfebcd0189caeba747ed1d207aab3857de1eecf4fb1MISS混淆器
68bb279723aa175b1cbaa567c0e0d6a8a17e6886501ff311493813a15e4e6176AMS: Fareit注入器
69ff04aa3967dd2747e33cd97e7517026d49eaf13340774b6a0d5d7fd95ac35fURL过滤Python exploit
77aa1c5b69b9514c852dda17080b2dceb725b5c9fe7d38d26aec03bc3a5a99f4MISS混淆器
77c3ff05ac628664156b8b36d875ac63692a67d748338ddcf6912457184f8a25MISS注入器
96a1c05c25331e549ac46cd52b4278f7d6d0d28d3b50664f9bb3e46c702e5f62MISS注入器
0351e4f1b5fcd2ea0ebf370033c59e9f1aa4122a78fb4bd69190f49f893ef83fMISS注入器
420d1f08a4eb57d7b197f53df1b9d66de2b441dba64f06fd7da58f4ba465547aAMS: Fareit混淆器
551aabcba9d35ea99a4108d5853e46e277ed8624c79c657ec1c6e8e3a58a818bMISSFareit
854bd12b55f5664791ebba5e9f2617d75ac3065b19db14c518b4a14e42391ae0僵尸网络防御 + AMS: Fareit注入器
35131a30bbd6810fc68065937ddbe89b67f8c3cc612d71e6fc6ad2461cc81b36僵尸网络防御混淆器
374250a78e0a695c8cf1d01e0712f4069b342cbac57ec28108eafe9378d87eafMISS注入器
5362910a979e699123b47dcf85e1727f9f42de805934937161b1b3b8c2c439efMISS注入器
a4ea64ffd4cd2773f361d3ef1788781b96be25fbcb19693d32c887b28aedf514MISS注入器
a572affb06e0d690b025788717a52d9be709b0aedc38db40f37f995bf484a00bMISS注入器
a694ef8a1a6c5143236ad8dfe1d0bc16dd33fecff59af30c3893806058a36658MISS注入器
abd55c84ab787199e2cb9b16835b25e59b0b00f211c62da2b732db375462fc17MISS混淆器
b4bf672cfc8f70d09393eac68d203b204c14ecad7f00ed2fb17d7d39aa4baba4AMS: Spy.Agent注入器
ba7ef373c14a528700345e17ccb2b41c367532fadb2130be1d691ccf6d7600dfMISSMISS
ba54f698cf9664219ab8587b72a9a8e4bd252e51f49b47c6abe7d2d9697e8d91AMS: Weecnaw混淆器
bbee13b6aa523df726fd16899abd2f717595cacdee5f85ab7e5a1b735bb8662fAMS: BladabindiAutoit注入器
c02ffc07d7e1246d920cf82e2e06c007296b4ff6f6b8af5584267e6ef674443bAMS: NanocoreAutoit注入器
c50167d9a899572e7dba0da1d80e3b9a94b2d3803a8f125119097ed5f92add6dAMS: GandCrab混淆器
d7a930096fb7265fc09d94238a35ea931eced0ce53654f5e6f8e7ab3c5a9cf89URL过滤+AMS: PSW.Delf注入器
dfd6310aca41781df8d04b9d2c1c4cbcc9bc77911e715592fe14285df0690a9dMISS混淆器
e2c933b2177b1acc36acfaa7182808742ea8a75287ea5ff12607f45baac2fed8僵尸网络防御+AMS:Fareit注入器
e6c06f42aa3b75cc2da0740481d9e9eb71bf0eef77daf13fd34b266595432c88AMS: Rescoms混淆器(自动)
e7d643331bbacc455e5b28876cdc58409d1d3408e9769dc88e1eebc5b050b20bMISS注入器
e54dec3f342c4394e6f5f2c310d889388b5ec8cdec65fd1bbe31c01efa6d852bclipbanker+PSW.Agent自动机
e62c7165911c2d7dce44e61d94a06b3e5f50bc77f5cdb033a3c98ef76b408be8AMS: Spy.AgentAutoit注入器
e77e47cd626affe1105519365258a01fa5046250bfc825885d15c15fc8255ab9MISS混淆器(自动)
e340a007f89f90ca9b24124d74ef6730bb68a442da433e83fa398cf07a975819AMS: BladabindiAutoit注入器
ebdea0461935c7dae8409e442e5757c91cec88cb6b4e674c6adf217971913e94MISS注入器[/td]
f7c7e52276e12dad6412fa7a739401f99ead69543fd4686c696af82550c9f341MISS混淆器
f830cbc35f6eb21f7e9f28cc88290db13662551f6a9994b06ada7caf4cd79b2fMISS混淆器
fc6f5675a96d62ae37fdd3aa103d2050bffe1ee62238bbd3ba78eab4ed84eab4AMS: AgentAutoit注入器


二周目(关闭AMS)
Hash 3月3日库 3月15日库(家族)
c50167d9a899572e7dba0da1d80e3b9a94b2d3803a8f125119097ed5f92add6d 勒索护盾(C255)混淆器(自动)
10a2e2df9177d431480a8f3fe0a4f9472dacded3f3ccdff42365f1d81cad0165深度行为防御(Emotet)混淆器
有空再更新这个列表……

其中某个样本的衍生物出发了新报法(Generik),但是具体记录弄丢了,贴个截图:


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 3人气 +5 收起 理由
Sailer.X + 1 版区有你更精彩: )
Jerry.Lin + 3 版区有你更精彩: )
xiaofeizei + 1 版区有你更精彩: )

查看全部评分

神算子
发表于 2019-3-16 08:35:21 | 显示全部楼层
小草猫 发表于 2019-3-15 19:42
瑞星 v17 收费版 最近加了一个引擎组件 对流行病毒查杀率甚至超过RDM+

无图无真相
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 21:01 , Processed in 0.104402 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表