查看: 1248|回复: 6
收起左侧

[病毒样本] 2020-05-01 ICEDID (BOKBOT)

[复制链接]
YorkWaugh
发表于 2020-5-3 21:18:33 | 显示全部楼层 |阅读模式
下载地址:https://ww.lanzous.com/ic853le最近没来,发重了别打我

NOTES:
  • I assume these password-protected zip archives containing German language Word docs are coming in as attachments from malspam to German recipients.
IMAGES

Shown above:  Screenshot of the XLS spreadsheet.

Shown above:  XLS macro retrieves Loader EXE.

Shown above:  Loader EXE retrieves initial IcedID EXE.

Shown above:  Pcap from an infection filtered in Wireshark.



dreams521
发表于 2020-5-3 21:21:28 | 显示全部楼层
卡巴
  1. 03.05.2020 21.20.48;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\Foxems.exe;C:\Users\Administrator\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\Foxems.exe;Trojan-Banker.Win32.Cridex.mgx;木马程序;05/03/2020 21:20:48
  2. 03.05.2020 21.20.48;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\GCqLBrG.exe;C:\Users\Administrator\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\GCqLBrG.exe;Trojan.Win32.Ligooc.z;木马程序;05/03/2020 21:20:48
  3. 03.05.2020 21.20.46;检测到的对象 ( 文件 ) 已删除;C:\Users\Administrator\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\~521792.exe;C:\Users\Administrator\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\~521792.exe;Trojan-Banker.Win32.Cridex.mgv;木马程序;05/03/2020 21:20:46
复制代码
救命稻草
发表于 2020-5-3 21:23:52 | 显示全部楼层
管家
  1. 2020-5-3 21:22:37 MD5:87c5c3ddcab7e03dad0384c170a94755 G:\Download\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\GCqLBrG.exe [Win32.Trojan.Ligooc.Ecuf]  [未处理]
  2. 2020-5-3 21:22:37 MD5:049a7732ad88c6353ad4dde9808d6066 G:\Download\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\Foxems.exe [Win32.Trojan-banker.Cridex.Eyk]  [未处理]
  3. 2020-5-3 21:22:37 MD5:7209f2d5270cf295d923d72c72379e67 G:\Download\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\1May__1.xls [Win32.Trojan-downloader.Agent.Adkj]  [未处理]
  4. 2020-5-3 21:22:37 MD5:d14b5b9d35caf69ba8eaae98dc4e8629 G:\Download\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\~521792.exe [Win32.Trojan-banker.Cridex.Wofr]  [未处理]
复制代码


wangyuhe
发表于 2020-5-3 21:43:28 | 显示全部楼层
亚信

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
小Q机器人
发表于 2020-5-3 21:54:18 | 显示全部楼层
智量 2.61 杀4个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wuming_bpnes
发表于 2020-5-3 22:12:15 | 显示全部楼层
大蜘蛛 kill
病毒库:05/03 PM7:16

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Nocria
发表于 2020-5-3 22:36:15 | 显示全部楼层
IKARUS

  1. [03.05.2020 22:35:48] On-demand scan started: "user_defined"
  2. [03.05.2020 22:35:48] Found, 0.15s, SigName: "Trojan.Office.Doc", SigId: 3787365, Type: "VIRUS", File: "C:\Users\promi\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\1May__1.xls"
  3. [03.05.2020 22:35:48] Found, 0.63s, SigName: "Trojan.SuspectCRC", SigId: 299855261, Type: "VIRUS", File: "C:\Users\promi\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\Foxems.exe"
  4. [03.05.2020 22:35:48] Found, 0.63s, SigName: "Trojan.Win32.Krypt", SigId: 299845247, Type: "VIRUS", File: "C:\Users\promi\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\GCqLBrG.exe"
  5. [03.05.2020 22:35:48] Found, 0.47s, SigName: "Trojan.Win32.Krypt", SigId: 299855264, Type: "VIRUS", File: "C:\Users\promi\Desktop\2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts\~521792.exe"
  6. [03.05.2020 22:35:48] On-demand scan FINISHED: "user_defined"
  7. [03.05.2020 22:35:48] ----------------------------------------------------
  8. [03.05.2020 22:35:48] Directories scanned: 1
  9. [03.05.2020 22:35:48] Files scanned: 11
  10. [03.05.2020 22:35:48] Virus found: 4
  11. [03.05.2020 22:35:48] ----------------------------------------------------
复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-1 16:57 , Processed in 0.113507 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表