查看: 915|回复: 8
收起左侧

[病毒样本] #Anti-VM #APT #VT:9/61

[复制链接]
BE_HC
发表于 2020-3-13 15:46:57 | 显示全部楼层 |阅读模式
下载:https://www.lanzous.com/ia7rjib 密码:337d


2020-01-20 老东西,在WIN7 X86下可以运行
  1. YARA signature "IronTiger_Gh0stRAT_variant" classified file "all.bstring" as "apt,irontiger,gh0strat,rat" based on indicators: "Winds Update" (Reference: http://goo.gl/T5fSJC, Author: Cyber Safety Solutions, Trend Micro)
  2. YARA signature "EnfalStrings" classified file "all.bstring" as "enfal" based on indicators: "Crpq2.cgi" (Author: Seth Hardy)
  3. YARA signature "Enfal" classified file "all.bstring" as "enfal" (Author: Seth Hardy)
  4. YARA signature "gh0st" classified file "all.bstring" as "rat,gh0st" based on indicators: "Gh0st Update" (Author: https://github.com/jackcr/)
  5. YARA signature "update_PcMain" matched file "all.bstring" as "Chinese Hacktool Set - file PcMain.dll" based on indicators: "Global\%s-key-event,%d%d.exe,%d.exe,Global\%s-key-metux,GET / HTTP/1.1,\Services" (Reference: http://tools.zjqhr.com/, Author: Florian Roth)
  6. YARA signature "CN_Honker_T00ls_Lpk_Sethc_v4_LPK" matched file "all.bstring" as "Sample from CN Honker Pentest Toolset - file LPK.DAT" based on indicators: "c:\1.exe" (Reference: Disclosed CN Honker Pentest Toolset, Author: Florian Roth)
  7. YARA signature "Typical_Malware_String_Transforms" matched file "all.bstring" as "Detects typical strings in a reversed or otherwise modified form" based on indicators: "exe.tsohcvs" (Reference: Internal Research, Author: Florian Roth)
  8. Internal YARA signature matched on file "all.bstring"
复制代码
https://www.hybrid-analysis.com/sample/ed2038ca387e15e3c3a177624541c5c851e71eaa3d7858eb285e43c07b7cab10?environmentId=110


https://www.virustotal.com/gui/file/ed2038ca387e15e3c3a177624541c5c851e71eaa3d7858eb285e43c07b7cab10/details
a233
发表于 2020-3-13 15:48:38 | 显示全部楼层


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
CHURP
发表于 2020-3-13 15:50:39 | 显示全部楼层
卡巴斯基不报现在卡巴都要废了
YorkWaugh
发表于 2020-3-13 15:51:03 | 显示全部楼层
火绒miss
lifan88
发表于 2020-3-13 15:53:21 | 显示全部楼层
有没有驱动
巍巍
发表于 2020-3-13 15:57:07 | 显示全部楼层
BD miss
智量miss
静影沉璧
发表于 2020-3-13 16:00:00 | 显示全部楼层
ESET miss
已上报


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
BE_HC
 楼主| 发表于 2020-3-13 16:04:10 | 显示全部楼层

不清楚,这个可能是Exploit
a445441
发表于 2020-3-13 17:06:58 | 显示全部楼层

反虚拟机微点MISS

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-4-30 19:25 , Processed in 0.129798 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表