12
返回列表 发新帖
楼主: Jerry.Lin
收起左侧

[病毒样本] 3x

[复制链接]
anthonyqian
发表于 2021-7-4 23:57:27 | 显示全部楼层
avast剩一个com,双击cyber capture报安全。
windows11BigSur
头像被屏蔽
发表于 2021-7-4 23:57:53 | 显示全部楼层
不想被妳发现 发表于 2021-7-4 22:57
KES的弹窗能看一下吗?

都是机器学习

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
救命稻草
发表于 2021-7-5 00:10:42 | 显示全部楼层
瑞星3X

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aboringman
发表于 2021-7-5 01:02:49 | 显示全部楼层
歌德塔:1X

我很想吐槽的是,主防的反应太慢了。。。。。。(DeepRay和BEAST)
  1. G DATA INTERNET SECURITY has prevented malicious software from running on your system.
  2. The malicious program was identified by BEAST (Behavior Monitoring) as: Keylogger3(注:键盘记录器)

  3. The following processes were therefore terminated by G DATA for security reasons:
  4.         ----------------------------------------------------------------
  5.         C:\Users\123456\Desktop\29126196aaf319113c8afe42498c0bbb.com
  6.         C:\Windows\Abcdef.exe (PID 8400)
  7.         C:\Windows\Abcdef.exe (PID 2896)
  8.         ----------------------------------------------------------------

  9. The following programs responsible were moved to Quarantine by G DATA:
  10.         ----------------------------------------------------------------
  11.         C:\Users\123456\Desktop\29126196aaf319113c8afe42498c0bbb.com
  12.         C:\Windows\Abcdef.exe
  13.         ----------------------------------------------------------------

  14. Further information:
  15. Module: DeepRay
  16. Process: Abcdef.exe (8400)
  17. File: C:\Windows\Abcdef.exe
  18. Sha256: EE248144C876247D2BB5A7A358B18D8D1EAB47AF27E3FCDFE9AB00E7E1D51D3B
  19. Md5: 29126196AAF319113C8AFE42498C0BBB
  20. Size: 339968
  21. Ref: 5bba3646-8b2c-4d01-bd48-6953c88449de

  22. G DATA INTERNET SECURITY has prevented malicious software from running on your system.
  23. The malicious program was identified by BEAST (Behavior Monitoring) as: Verdict.ContactedMaliciousHost(注:与恶意主机通讯)

  24. The following processes were therefore terminated by G DATA for security reasons:
  25.         ----------------------------------------------------------------
  26.         C:\Users\123456\Desktop\bc52292288db5773b994c2a638298014.cmd (PID 3032)
  27.         ----------------------------------------------------------------

  28. The following programs responsible were moved to Quarantine by G DATA:
  29.         ----------------------------------------------------------------
  30.         C:\Users\123456\Desktop\bc52292288db5773b994c2a638298014.cmd
  31.         ----------------------------------------------------------------

  32. Registry items
  33.         ----------------------------------------------------------------
  34.         HKEY_USERS\S-1-5-21-3839188502-333370962-3824098329-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Emamqcs.exe
  35.         ----------------------------------------------------------------

  36. Further information:
  37. Module: CnC
  38. Domain: six.skt-one.com
  39. Domain ip: 185.227.70.219
  40. Ref: 5a862896-e52d-4895-b527-d2f36d008dea

  41. G DATA INTERNET SECURITY has prevented malicious software from running on your system.
  42. The malicious program was identified by BEAST (Behavior Monitoring) as: Generic.9FFB3645(注:可能是衍生物报法啦)

  43. The following processes were therefore terminated by G DATA for security reasons:
  44.         ----------------------------------------------------------------
  45.         C:\Users\123456\Desktop\29126196aaf319113c8afe42498c0bbb.com
  46.         C:\Windows\Abcdef.exe (PID 4888)
  47.         C:\Windows\Abcdef.exe (PID 1332)
  48.         ----------------------------------------------------------------

  49. The following programs responsible were moved to Quarantine by G DATA:
  50.         ----------------------------------------------------------------
  51.         C:\Windows\Abcdef.exe
  52.         ----------------------------------------------------------------

  53. Further information:
  54. Ref: 07842a9f-2a41-4ea2-a7dc-937e7deedfdf

复制代码


心心相印
发表于 2021-7-5 08:12:25 | 显示全部楼层
360kill
sichuanwenxuan
发表于 2021-7-5 09:23:17 | 显示全部楼层
WD清空。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wh759626933
发表于 2021-7-5 10:59:14 | 显示全部楼层
不想被妳发现 发表于 2021-7-5 00:11
机器学习?这报法怎么看都不像啊

heur是启发啊,就是机器学习的报法啊
heavencc
发表于 2021-7-5 15:41:38 | 显示全部楼层
智量
  1. 2021-07-05 15:41:07 C:\Users\Stardust\Desktop\3GpbJSrC_3\bc52292288db5773b994c2a638298014.cmd                           Heur.ML.PE.A        
  2. 2021-07-05 15:41:07 C:\Users\Stardust\Desktop\3GpbJSrC_3\29126196aaf319113c8afe42498c0bbb.com                           Heur.ML.PE.A        
  3. 2021-07-05 15:41:05 C:\Users\Stardust\Desktop\3GpbJSrC_3\3f2477191ff5149fa5aaf3974de001eb.bat                           Heur.ML.PE.A        
复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-6 01:34 , Processed in 0.099270 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表