查看: 4317|回复: 18
收起左侧

[病毒样本] Rootkit 3X-麻辣香锅MLXG病毒最新变种

[复制链接]
wwwab
发表于 2021-7-24 09:31:44 | 显示全部楼层 |阅读模式
恶意URLs:jhgj.njxwang.com、win.xzhyl.top
火绒报告:https://bbs.huorong.cn/thread-87756-1-1.html
和以往不同的是,该版本的病毒除了劫持用户流量以外,还会劫持安全厂商提供的专杀工具的下载地址(如火绒的专杀工具),从而能够长久驻留用户电脑中。

微云:https://share.weiyun.com/JYb6ssoX
文叔叔:https://ws28.cn/f/5z93k6n7zxs 复制链接到浏览器打开

评分

参与人数 1魅力 +1 收起 理由
屁颠屁颠 + 1 长期发帖奖励

查看全部评分

wwwab
 楼主| 发表于 2021-7-24 09:36:17 | 显示全部楼层
本帖最后由 wwwab 于 2021-7-24 09:40 编辑

他那个样本不全,是根据报告下面的哈希值下载的,火绒只是以一例样本进行分析的,所以就只有暴风版本与其衍生物和一堆sys驱动文件

我这是从病毒网站上面下载的,暴风小马kms版本几例的的样本全都有的,只不过没提取出来与其衍生物以及sys驱动文件而已

所以,是不一样的哦
救命稻草
发表于 2021-7-24 09:37:54 | 显示全部楼层

  1. Virus check with G DATA INTERNET SECURITY
  2. Version 25.5.11.112 (2021/3/25)
  3. Virus signature dated 2021/7/24
  4. Start time: 2021/7/24 9:35:54
  5. Engine(s): Engine A (AVA 25.30375), Engine B (GD 27.23830)
  6. Heuristics: On
  7. Archives: On
  8. System areas: Off
  9. Check rootkits: Off

  10. Check the following directories and files:
  11.   C:\Users\Jkc\Desktop\virus\归档\

  12. Analysis performed in full: 2021/7/24 9:36:06
  13.     3 files checked
  14.     3 infected files detected
  15.     0 suspicious files found


  16. Object: xiaoma.exe
  17.         Path: C:\Users\Jkc\Desktop\virus\归档
  18.         Status: Junkware (PUP) found
  19.         Junkware (PUP): Dropped:Application.Hacktool.DisableDefender.E (Engine A)

  20. Object: baofeng.exe
  21.         Path: C:\Users\Jkc\Desktop\virus\归档
  22.         Status: Junkware (PUP) found
  23.         Junkware (PUP): Dropped:Application.Hacktool.DisableDefender.E (Engine A)

  24. Archive: HEU_KMS.exe
  25.         Path: C:\Users\Jkc\Desktop\virus\归档
  26.         Status: Virus detected
  27.         Virus: Application.Hacktool.AFJ (3x), Application.Hacktool.APE (3x), Application.Hacktool.APF (3x), Application.Hacktool.DisableDefender.E, Application.Hacktool.KMSActivator.AR (3x), Application.Hacktool.KMSActivator.FU (3x), Application.Hacktool.KMSActivator.FV (3x), Trojan.GenericKD.37275870 (Engine A)
  28.         ----------------------------------------------------------------
  29.         Object: (NSIS o)=>dControl.exe
  30.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  31.                 Status: Junkware (PUP) found
  32.                 Junkware (PUP): Application.Hacktool.DisableDefender.E
  33.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(Dropped 6)=>HEU_KMS.exe=>KMSmini.7z=>HEU_KMS_Service.exe
  34.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  35.                 Status: Junkware (PUP) found
  36.                 Junkware (PUP): Application.Hacktool.KMSActivator.AR
  37.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(Dropped 6)=>HEU_KMS.exe=>KMSmini.7z=>KMSClient.exe
  38.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  39.                 Status: Junkware (PUP) found
  40.                 Junkware (PUP): Application.Hacktool.KMSActivator.FU
  41.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(Dropped 6)=>HEU_KMS.exe=>KMSmini.7z=>KMSServer.exe
  42.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  43.                 Status: Junkware (PUP) found
  44.                 Junkware (PUP): Application.Hacktool.KMSActivator.FV
  45.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(Dropped 6)=>HEU_KMS.exe=>KMSmini.7z=>x64/SppExtComObj.Exe
  46.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  47.                 Status: Junkware (PUP) found
  48.                 Junkware (PUP): Application.Hacktool.AFJ
  49.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(Dropped 6)=>HEU_KMS.exe=>KMSmini.7z=>x64/SppExtComObjHook.dll
  50.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  51.                 Status: Junkware (PUP) found
  52.                 Junkware (PUP): Application.Hacktool.APE
  53.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(Dropped 6)=>HEU_KMS.exe=>KMSmini.7z=>x86/SppExtComObjHook.dll
  54.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  55.                 Status: Junkware (PUP) found
  56.                 Junkware (PUP): Application.Hacktool.APF
  57.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>(AutoIT o)=>KMSmini.7z=>HEU_KMS_Service.exe
  58.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  59.                 Status: Junkware (PUP) found
  60.                 Junkware (PUP): Application.Hacktool.KMSActivator.AR
  61.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>(AutoIT o)=>KMSmini.7z=>KMSClient.exe
  62.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  63.                 Status: Junkware (PUP) found
  64.                 Junkware (PUP): Application.Hacktool.KMSActivator.FU
  65.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>(AutoIT o)=>KMSmini.7z=>KMSServer.exe
  66.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  67.                 Status: Junkware (PUP) found
  68.                 Junkware (PUP): Application.Hacktool.KMSActivator.FV
  69.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>(AutoIT o)=>KMSmini.7z=>x64/SppExtComObj.Exe
  70.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  71.                 Status: Junkware (PUP) found
  72.                 Junkware (PUP): Application.Hacktool.AFJ
  73.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>(AutoIT o)=>KMSmini.7z=>x64/SppExtComObjHook.dll
  74.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  75.                 Status: Junkware (PUP) found
  76.                 Junkware (PUP): Application.Hacktool.APE
  77.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>(AutoIT o)=>KMSmini.7z=>x86/SppExtComObjHook.dll
  78.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  79.                 Status: Junkware (PUP) found
  80.                 Junkware (PUP): Application.Hacktool.APF
  81.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>KMSmini.7z=>HEU_KMS_Service.exe
  82.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  83.                 Status: Junkware (PUP) found
  84.                 Junkware (PUP): Application.Hacktool.KMSActivator.AR
  85.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>KMSmini.7z=>KMSClient.exe
  86.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  87.                 Status: Junkware (PUP) found
  88.                 Junkware (PUP): Application.Hacktool.KMSActivator.FU
  89.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>KMSmini.7z=>KMSServer.exe
  90.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  91.                 Status: Junkware (PUP) found
  92.                 Junkware (PUP): Application.Hacktool.KMSActivator.FV
  93.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>KMSmini.7z=>x64/SppExtComObj.Exe
  94.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  95.                 Status: Junkware (PUP) found
  96.                 Junkware (PUP): Application.Hacktool.AFJ
  97.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>KMSmini.7z=>x64/SppExtComObjHook.dll
  98.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  99.                 Status: Junkware (PUP) found
  100.                 Junkware (PUP): Application.Hacktool.APE
  101.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play15.dat=>HEU_KMS.exe=>KMSmini.7z=>x86/SppExtComObjHook.dll
  102.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  103.                 Status: Junkware (PUP) found
  104.                 Junkware (PUP): Application.Hacktool.APF
  105.         Object: (NSIS o)=>HEU.dat=>HEU.exe=>(NSIS o)=>Play64.dat=>UfdsvtIopuy.sys
  106.                 In archive: C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  107.                 Status: Virus detected
  108.                 Virus: Trojan.GenericKD.37275870
  109.         ----------------------------------------------------------------

  110. The following files are password-protected:
  111.         ----------------------------------------------------------------
  112.         C:\Users\Jkc\Desktop\virus\归档\HEU_KMS.exe
  113.         ----------------------------------------------------------------
复制代码


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
windows11BigSur
头像被屏蔽
发表于 2021-7-24 09:52:00 | 显示全部楼层
本帖最后由 windows11BigSur 于 2021-7-24 09:55 编辑

卡巴 kill all

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
狂欢...
发表于 2021-7-24 10:16:40 | 显示全部楼层
C:\360极速浏览器下载\归档.zip=>HEU_KMS.exe        感染型病毒(Win32/HackTool.Generic.HgIASYUA)        已删除
C:\360极速浏览器下载\归档.zip=>baofeng.exe        感染型病毒(Win32/HackTool.Generic.HgIASYUA)        已删除
C:\360极速浏览器下载\归档.zip=>xiaoma.exe                感染型病毒(Win32/HackTool.Generic.HyoDjDoA)        已删除
wwwab
 楼主| 发表于 2021-7-24 10:20:36 | 显示全部楼层
报hackdoor的我说什么好呢,完全就说不过去了,你哪怕报adware也倒还说得过去,这种就应该报trojan
zay365
头像被屏蔽
发表于 2021-7-24 10:28:15 | 显示全部楼层
wwwab 发表于 2021-7-24 10:20
报hackdoor的我说什么好呢,完全就说不过去了,你哪怕报adware也倒还说得过去,这种就应该报trojan

报HackTool估计报的是工具本体
a27573
发表于 2021-7-24 10:49:35 | 显示全部楼层
ESET


刚刚还 miss all,瞬间拉黑可还行

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Jerry.Lin
发表于 2021-7-24 11:09:33 | 显示全部楼层
WD
3/3
  1. Filename        Threat Name        Severity        Initial Detect Time        Threat ID        Detect Source Type        Category       
  2. baofeng.exe        HackTool:Win32/DefenderControl        High (4)        7/23/2021 10:09:00 PM        2147746246        Real Time        Tool       
  3. xiaoma.exe        HackTool:Win32/DefenderControl        High (4)        7/23/2021 10:07:15 PM        2147746246        System        Tool       
  4. baofeng.exe        HackTool:Win32/DefenderControl        High (4)        7/23/2021 10:07:12 PM        2147746246        Real Time        Tool       
复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-5 15:21 , Processed in 0.113370 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表