查看: 1334|回复: 9
收起左侧

[病毒样本] #Ransomware (2020-04-21)

[复制链接]
a233
发表于 2020-4-21 14:48:11 | 显示全部楼层
Avast
Win32:RansomX-gen [Ransom]
猥琐大叔
发表于 2020-4-21 14:48:17 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
杀软病综合医院
发表于 2020-4-21 14:48:41 | 显示全部楼层
解压后eset首先预警,其次卡巴
360和智量没有预警

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
knight0756
发表于 2020-4-21 15:25:36 | 显示全部楼层
SEP Trojan.Gen.2
dreams521
发表于 2020-4-21 19:05:49 | 显示全部楼层
卡巴
  1. 21.04.2020 19.05.29;检测到的对象 ( 文件 ) 将在计算机重启后处理;C:\Users\Administrator\Desktop\#Ako (2020-04-21)\#Ako (2020-04-21).exe;C:\Users\Administrator\Desktop\#Ako (2020-04-21)\#Ako (2020-04-21).exe;HEUR:Trojan.Win32.DelShad.vho;木马程序;04/21/2020 19:05:29
复制代码
epattack
发表于 2020-4-21 22:25:29 | 显示全部楼层
微点

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
病毒探索者
发表于 2020-4-22 23:00:07 | 显示全部楼层
App Check
  1. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\kingsoft\office6\mtfont\AkoReadMe.txt,,Removed,RansomGuard
  2. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\kingsoft\office6\mtfont\AkoReadMe.html,,Removed,RansomGuard
  3. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\kingsoft\office6\mtfont\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  4. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{4931385B-094D-4DC5-BD6A-5188FE9C51DF}v14.20.27508\packages\vcRuntimeAdditional_amd64\AkoReadMe.txt,,Removed,RansomGuard
  5. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{4931385B-094D-4DC5-BD6A-5188FE9C51DF}v14.20.27508\packages\vcRuntimeAdditional_amd64\AkoReadMe.html,,Removed,RansomGuard
  6. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{4931385B-094D-4DC5-BD6A-5188FE9C51DF}v14.20.27508\packages\vcRuntimeAdditional_amd64\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  7. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{7b178cda-9740-4701-a92a-f168d213b343}\AkoReadMe.txt,,Removed,RansomGuard
  8. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{7b178cda-9740-4701-a92a-f168d213b343}\AkoReadMe.html,,Removed,RansomGuard
  9. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{7b178cda-9740-4701-a92a-f168d213b343}\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  10. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\AkoReadMe.txt,,Removed,RansomGuard
  11. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\AkoReadMe.html,,Removed,RansomGuard
  12. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  13. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\packages\vcRuntimeMinimum_x86\AkoReadMe.txt,,Removed,RansomGuard
  14. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\packages\vcRuntimeMinimum_x86\AkoReadMe.html,,Removed,RansomGuard
  15. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\packages\vcRuntimeMinimum_x86\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  16. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\packages\vcRuntimeAdditional_x86\AkoReadMe.txt,,Removed,RansomGuard
  17. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\packages\vcRuntimeAdditional_x86\AkoReadMe.html,,Removed,RansomGuard
  18. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\packages\vcRuntimeAdditional_x86\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  19. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{F3241984-5A0E-4632-9025-AA16E0780A4B}v14.20.27508\packages\vcRuntimeMinimum_amd64\AkoReadMe.txt,,Removed,RansomGuard
  20. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{F3241984-5A0E-4632-9025-AA16E0780A4B}v14.20.27508\packages\vcRuntimeMinimum_amd64\AkoReadMe.html,,Removed,RansomGuard
  21. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{F3241984-5A0E-4632-9025-AA16E0780A4B}v14.20.27508\packages\vcRuntimeMinimum_amd64\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  22. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\USOShared\Logs\User\AkoReadMe.txt,,Removed,RansomGuard
  23. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\USOShared\Logs\User\AkoReadMe.html,,Removed,RansomGuard
  24. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\USOShared\Logs\User\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  25. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\logs\AkoReadMe.txt,,Removed,RansomGuard
  26. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\logs\AkoReadMe.html,,Removed,RansomGuard
  27. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\logs\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  28. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\RawdskCompatibility\AkoReadMe.txt,,Removed,RansomGuard
  29. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\RawdskCompatibility\AkoReadMe.html,,Removed,RansomGuard
  30. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\RawdskCompatibility\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  31. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\manifest.txt,,Restored,RansomGuard
  32. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\manifest.txt,,Restored,RansomGuard
  33. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\manifest.txt.AKO,,Removed,RansomGuard
  34. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\AkoReadMe.txt,,Removed,RansomGuard
  35. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\AkoReadMe.html,,Removed,RansomGuard
  36. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  37. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\Adobe{过}{滤}Flashcs3.txt,,Restored,RansomGuard
  38. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\Adobe{过}{滤}Flashcs3.txt,,Restored,RansomGuard
  39. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\Adobe{过}{滤}Flashcs3.txt.AKO,,Removed,RansomGuard
  40. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\AkoReadMe.txt,,Removed,RansomGuard
  41. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\AkoReadMe.html,,Removed,RansomGuard
  42. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  43. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\adobephotoshopcs3.txt,,Restored,RansomGuard
  44. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\adobephotoshopcs3.txt,,Restored,RansomGuard
  45. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\adobephotoshopcs3.txt.AKO,,Removed,RansomGuard
  46. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\googledesktop.txt,,Restored,RansomGuard
  47. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\googledesktop.txt,,Restored,RansomGuard
  48. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\googledesktop.txt.AKO,,Removed,RansomGuard
  49. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\microsoftoffice.txt,,Restored,RansomGuard
  50. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\microsoftoffice.txt,,Restored,RansomGuard
  51. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\microsoftoffice.txt.AKO,,Removed,RansomGuard
  52. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vistasidebar.txt,,Restored,RansomGuard
  53. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vistasidebar.txt,,Restored,RansomGuard
  54. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vistasidebar.txt.AKO,,Removed,RansomGuard
  55. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\visualstudio2005.txt,,Restored,RansomGuard
  56. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\visualstudio2005.txt,,Restored,RansomGuard
  57. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\visualstudio2005.txt.AKO,,Removed,RansomGuard
  58. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vmwarefilters.txt,,Restored,RansomGuard
  59. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vmwarefilters.txt,,Restored,RansomGuard
  60. 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vmwarefilters.txt.AKO,,Removed,RansomGuard
  61. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\win7gadgets.txt,,Restored,RansomGuard
  62. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\win7gadgets.txt,,Restored,RansomGuard
  63. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\win7gadgets.txt.AKO,,Removed,RansomGuard
  64. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de\AkoReadMe.txt,,Removed,RansomGuard
  65. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de\AkoReadMe.html,,Removed,RansomGuard
  66. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  67. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en\AkoReadMe.txt,,Removed,RansomGuard
  68. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en\AkoReadMe.html,,Removed,RansomGuard
  69. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  70. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es\AkoReadMe.txt,,Removed,RansomGuard
  71. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es\AkoReadMe.html,,Removed,RansomGuard
  72. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  73. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr\AkoReadMe.txt,,Removed,RansomGuard
  74. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr\AkoReadMe.html,,Removed,RansomGuard
  75. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  76. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it\AkoReadMe.txt,,Removed,RansomGuard
  77. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it\AkoReadMe.html,,Removed,RansomGuard
  78. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  79. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja\AkoReadMe.txt,,Removed,RansomGuard
  80. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja\AkoReadMe.html,,Removed,RansomGuard
  81. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  82. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko\AkoReadMe.txt,,Removed,RansomGuard
  83. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko\AkoReadMe.html,,Removed,RansomGuard
  84. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  85. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN\AkoReadMe.txt,,Removed,RansomGuard
  86. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN\AkoReadMe.html,,Removed,RansomGuard
  87. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  88. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW\AkoReadMe.txt,,Removed,RansomGuard
  89. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW\AkoReadMe.html,,Removed,RansomGuard
  90. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  91. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\AkoReadMe.txt,,Removed,RansomGuard
  92. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\AkoReadMe.html,,Removed,RansomGuard
  93. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  94. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Default\AkoReadMe.txt,,Removed,RansomGuard
  95. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Default\AkoReadMe.html,,Removed,RansomGuard
  96. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Default\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
  97. 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Public\Desktop\Bandizip.lnk,,Restored,RansomGuard
  98. 04/22/2020 10:58:31 下午,Ransomware Behavior Detected,File,C:\Users\virus\Downloads\#Ako (2020-04-21).exe,21195dabaebdbf3c584025ac5b9b1b5c,Blocked,RansomGuard
复制代码
病毒探索者
发表于 2020-4-22 23:05:02 | 显示全部楼层
Acronis

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
病毒探索者
发表于 2020-4-22 23:13:31 | 显示全部楼层
瑞星之剑

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-19 11:45 , Processed in 0.124609 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表