查看: 1104|回复: 7
收起左侧

[病毒样本] 2020-04-17 - QAKBOT (QBOT) SPX99

[复制链接]
YorkWaugh
发表于 2020-4-18 20:30:54 | 显示全部楼层 |阅读模式
本帖最后由 YorkWaugh 于 2020-4-18 20:34 编辑

好久没来了,来诈个尸:https://ww.lanzous.com/ibkl4md
其他样本:https://ww.lanzous.com/b0159g2mb
0140012.zip   (101,528 bytes)
2020-04-17-Qakbot-EXE-spx99-example-1-of-4.bin   (2,295,808 bytes)
2020-04-17-Qakbot-EXE-spx99-example-2-of-4.bin   (2,295,808 bytes)
2020-04-17-Qakbot-EXE-spx99-example-3-of-4.bin   (2,295,808 bytes)
2020-04-17-Qakbot-EXE-spx99-example-4-of-4.bin   (2,295,808 bytes)
2164939.zip   (98,776 bytes)
50208.zip   (95,056 bytes)
82386.zip   (100,122 bytes)

评分

参与人数 1人气 +1 收起 理由
QVM360 + 1 版区有你更精彩: )

查看全部评分

jiaobaoyun51
头像被屏蔽
发表于 2020-4-18 20:39:13 | 显示全部楼层
红伞清空
a233
发表于 2020-4-18 20:41:25 | 显示全部楼层
Avast清空


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Xw1nd极风
发表于 2020-4-18 21:07:47 | 显示全部楼层
Norton
扫描VBS的好像都Miss了
双击
这...算拦住了吗

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
傻猪猪米走鸡
发表于 2020-4-18 21:12:16 | 显示全部楼层
Time;Scanner;Object type;Object;Detection;Action;User;Information;Hash;First seen here
2020/4/18 21:09:57;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\2020-04-17-Qakbot-EXE-spx99-example-1-of-4.bin;a variant of Win32/GenKryptik.EILP trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Windows\explorer.exe (421C8FE40D4A8B70547DCCD21D924B3C58C26F89).;111D219DFB11EE95F4B558E2ACF0F19977ACDDAE;2020/4/18 21:09:55
2020/4/18 21:09:58;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\2020-04-17-Qakbot-EXE-spx99-example-2-of-4.bin;a variant of Win32/GenKryptik.EILP trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Windows\explorer.exe (421C8FE40D4A8B70547DCCD21D924B3C58C26F89).;F2AD8B80AE7EFEF7DFFFEEB83456456731264FC3;2020/4/18 21:09:56
2020/4/18 21:09:59;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\2020-04-17-Qakbot-EXE-spx99-example-3-of-4.bin;a variant of Win32/GenKryptik.EILP trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Windows\explorer.exe (421C8FE40D4A8B70547DCCD21D924B3C58C26F89).;4768323A806F3F76741B28B78A2F84641191B14A;2020/4/18 21:09:57
2020/4/18 21:10:00;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\2020-04-17-Qakbot-EXE-spx99-example-4-of-4.bin;a variant of Win32/GenKryptik.EILP trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Windows\explorer.exe (421C8FE40D4A8B70547DCCD21D924B3C58C26F89).;5692F839A7FCAB0188BB98D60AFDA038A450FD89;2020/4/18 21:09:57
2020/4/18 21:11:41;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\0140012\NUM_54386.vbs;VBS/TrojanDownloader.Agent.TIV trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Program Files (x86)\360\360zip\360zip.exe (C2085BBEE171ABAAA42BD3D8209596747E3710B8).;73C40AEAE1B2EEF6CCAEC2B4EB94DA0520269FB6;2020/4/18 21:11:36
2020/4/18 21:11:41;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\0140012\NUM_71700.vbs;VBS/TrojanDownloader.Agent.TIV trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Program Files (x86)\360\360zip\360zip.exe (C2085BBEE171ABAAA42BD3D8209596747E3710B8).;015308AB1FE11BB05A10C33A71188FCA18AD16F7;2020/4/18 21:11:35
2020/4/18 21:11:42;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\0140012\NUM_50905.vbs;VBS/TrojanDownloader.Agent.TIV trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Program Files (x86)\360\360zip\360zip.exe (C2085BBEE171ABAAA42BD3D8209596747E3710B8).;6405B6C167D0454DDBA36A54AE1E8625CC742BC6;2020/4/18 21:11:35
2020/4/18 21:11:42;Real-time file system protection;file;C:\Users\Galaxy\Downloads\2020-04-17-Qakbot-spx99-malware-samples\0140012\NUM_353.vbs;VBS/TrojanDownloader.Agent.TIV trojan;cleaned by deleting;DESKTOP-NV3EN59\Galaxy;Event occurred on a new file created by the application: C:\Program Files (x86)\360\360zip\360zip.exe (C2085BBEE171ABAAA42BD3D8209596747E3710B8).;99D099FA960A924A2E89669DC22813C3CF75FFD1;2020/4/18 21:11:35


By ESET
心醉咖啡
发表于 2020-4-18 21:56:49 | 显示全部楼层
本帖最后由 心醉咖啡 于 2020-4-18 22:07 编辑

21.56毒霸0
22.07
  1. 扫描时间:[2020-04-18 22:06:57]
  2. 扫描用时:[00:00:07]
  3. 扫描类型:自定义查杀
  4. 扫描文件总数:12
  5. 扫描速度:1文件/秒
  6. 发现威胁:4个
  7. 清除威胁:4个
  8. =============================================
  9. [2020-04-18 22:07:10]
  10. 威胁:e:\浏览器下载\2020-04-17-qakbot-spx99-malware-samples\2020-04-17-qakbot-exe-spx99-example-1-of-4.bin
  11. 类型:win32.troj.banker.(kcloud)
  12. 处理方式:删除

  13. [2020-04-18 22:07:10]
  14. 威胁:e:\浏览器下载\2020-04-17-qakbot-spx99-malware-samples\2020-04-17-qakbot-exe-spx99-example-2-of-4.bin
  15. 类型:win32.troj.banker.(kcloud)
  16. 处理方式:删除

  17. [2020-04-18 22:07:10]
  18. 威胁:e:\浏览器下载\2020-04-17-qakbot-spx99-malware-samples\2020-04-17-qakbot-exe-spx99-example-3-of-4.bin
  19. 类型:win32.troj.banker.(kcloud)
  20. 处理方式:删除

  21. [2020-04-18 22:07:10]
  22. 威胁:e:\浏览器下载\2020-04-17-qakbot-spx99-malware-samples\2020-04-17-qakbot-exe-spx99-example-4-of-4.bin
  23. 类型:win32.troj.banker.(kcloud)
  24. 处理方式:删除

复制代码

巍巍
发表于 2020-4-18 22:10:19 | 显示全部楼层
卡巴清空

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
QVM360
发表于 2020-4-18 22:20:16 | 显示全部楼层
ESET
0140012.zip > ZIP > NUM_71700.vbs - VBS/TrojanDownloader.Agent.TIV 特洛伊木马
2020-04-17-Qakbot-EXE-spx99-example-1-of-4.bin - Win32/GenKryptik.EILP 特洛伊木马 的变种
2020-04-17-Qakbot-EXE-spx99-example-2-of-4.bin - Win32/GenKryptik.EILP 特洛伊木马 的变种
2020-04-17-Qakbot-EXE-spx99-example-3-of-4.bin - Win32/GenKryptik.EILP 特洛伊木马 的变种
2020-04-17-Qakbot-EXE-spx99-example-4-of-4.bin - Win32/GenKryptik.EILP 特洛伊木马 的变种
2164939.zip > ZIP > NUM_353.vbs - VBS/TrojanDownloader.Agent.TIV 特洛伊木马
50208.zip > ZIP > NUM_50905.vbs - VBS/TrojanDownloader.Agent.TIV 特洛伊木马
82386.zip > ZIP > NUM_54386.vbs - VBS/TrojanDownloader.Agent.TIV 特洛伊木马



您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-20 07:39 , Processed in 0.122264 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表