12
返回列表 发新帖
楼主: QVM360
收起左侧

[病毒样本] #Ransomware (2020-04-15)

[复制链接]
Xw1nd极风
发表于 2020-4-15 11:44:00 | 显示全部楼层
BDTS
Generic.Ransom.Small.E65F3125
knight0756
发表于 2020-4-15 13:28:06 | 显示全部楼层
SEP Ransom.HiddenTear!g1
病毒探索者
发表于 2020-4-15 18:44:16 | 显示全部楼层
HitmanPro.Alert

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
54ss
发表于 2020-4-15 18:55:35 | 显示全部楼层
BEST 双击测试
本体自删?
所在文件夹(桌面)有两个文件被加密
随后
高级威胁防护已拦截一个恶意进程。进程路径: C:\ljsjo\Rand123\local.exe.
哎 差一点点……
病毒探索者
发表于 2020-4-15 20:25:39 | 显示全部楼层
54ss 发表于 2020-4-15 18:55
BEST 双击测试
本体自删?
所在文件夹(桌面)有两个文件被加密

我现在感觉反勒索做的最好的还是HitmanPro.Alert,几乎无对手
病毒探索者
发表于 2020-4-15 20:28:30 | 显示全部楼层
App Check
  1. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\AppCheck Anti-Ransomware.lnk,,Restored,RansomGuard
  2. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\AppCheck Anti-Ransomware.lnk,,Restored,RansomGuard
  3. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\AppCheck Anti-Ransomware.lnk.rogue,,Removed,RansomGuard
  4. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试1.txt,,Restored,RansomGuard
  5. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试1.txt,,Restored,RansomGuard
  6. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试1.txt.rogue,,Removed,RansomGuard
  7. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试2.pptx,,Restored,RansomGuard
  8. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试2.pptx,,Restored,RansomGuard
  9. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试2.pptx.rogue,,Removed,RansomGuard
  10. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试3.pdf,,Restored,RansomGuard
  11. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试3.pdf,,Restored,RansomGuard
  12. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试3.pdf.rogue,,Removed,RansomGuard
  13. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试4.docx,,Restored,RansomGuard
  14. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试4.docx,,Restored,RansomGuard
  15. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试4.docx.rogue,,Removed,RansomGuard
  16. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\123.docx,,Restored,RansomGuard
  17. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\123.docx,,Restored,RansomGuard
  18. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\123.docx.rogue,,Removed,RansomGuard
  19. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\123.pdf,,Restored,RansomGuard
  20. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\123.pdf,,Restored,RansomGuard
  21. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\123.pdf.rogue,,Removed,RansomGuard
  22. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\13123.pdf,,Restored,RansomGuard
  23. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\13123.pdf,,Restored,RansomGuard
  24. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\13123.pdf.rogue,,Removed,RansomGuard
  25. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\213.png,,Restored,RansomGuard
  26. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\213.png,,Restored,RansomGuard
  27. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\213.png.rogue,,Removed,RansomGuard
  28. 04/15/2020 08:27:21 下午,File Created by Ransomware,File,C:\Users\virus\Desktop\测试5\2313.docx,,Restored,RansomGuard
  29. 04/15/2020 08:27:21 下午,Ransomware Behavior Detected,File,C:\Users\virus\Downloads\Attachment.exe,,Blocked,RansomGuard
复制代码
Nocria
发表于 2020-4-15 20:32:03 | 显示全部楼层
趋势安全大师

病毒探索者
发表于 2020-4-15 20:36:24 | 显示全部楼层

Mac的杀软界面真的好看啊,简洁!
swizzer
发表于 2020-4-16 07:50:01 | 显示全部楼层
病毒探索者 发表于 2020-4-15 20:25
我现在感觉反勒索做的最好的还是HitmanPro.Alert,几乎无对手

误报也挺高每次登录电脑版微信都会被杀一次Generic.Ransom.C

还好新版能添加排除了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-26 01:22 , Processed in 0.100075 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表