12
返回列表 发新帖
楼主: hsks
收起左侧

[病毒样本] 2021-08-10-TA551-BazarLoader-with-CobaltStrike-malware-samples

[复制链接]
SayWhat13
发表于 2021-8-11 15:03:12 | 显示全部楼层
本帖最后由 SayWhat13 于 2021-8-11 15:04 编辑

Malwarebytes杀10
www.malwarebytes.com

  1. -Log Details-
  2. Scan Date: 8/11/21
  3. Scan Time: 3:01 PM
  4. Log File: f8692812-fa71-11eb-84fd-489ebd2588e4.json

  5. -Software Information-
  6. Version: 4.4.4.126
  7. Components Version: 1.0.1413
  8. Update Package Version: 1.0.44032
  9. License: Premium

  10. -Scan Summary-
  11. Scan Type: Custom Scan
  12. Scan Initiated By: Manual
  13. Result: Completed
  14. Objects Scanned: 31
  15. Threats Detected: 10
  16. Threats Quarantined: 10
  17. Time Elapsed: 0 min, 14 sec

  18. -Scan Options-
  19. Memory: Disabled
  20. Startup: Disabled
  21. Filesystem: Enabled
  22. Archives: Enabled
  23. Rootkits: Disabled
  24. Heuristics: Enabled
  25. PUP: Detect
  26. PUM: Detect

  27. -Scan Details-
  28. Process: 0
  29. (No malicious items detected)

  30. Module: 0
  31. (No malicious items detected)

  32. Registry Key: 0
  33. (No malicious items detected)

  34. Registry Value: 0
  35. (No malicious items detected)

  36. Registry Data: 0
  37. (No malicious items detected)

  38. Data Stream: 0
  39. (No malicious items detected)

  40. Folder: 0
  41. (No malicious items detected)

  42. File: 10
  43. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\INSTALLSETUPSTART.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , C55B65A202F19CF40E569A05684DA6F6, 6BA18D4835C77CEB9DAD64B870BB3BECB041017C2EF59FFD417D9BCEDBD1BFE5
  44. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\STARTMIX.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 46454D614F3DFF8C7DE526F5A8849466, 92F08770E9D9C86FF5DC8384CA46A0BF70E407BEBD4D3D5AAF5DCBCAD05791D8
  45. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\INSTALLVIDEO.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 6BAEB5A0CD83E3A9878DC4D6D7A5509C, 029B714502283599A5EFB86D41C48FD46751AB727B707BDE620E517EC3AA3C39
  46. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\MP4WAVBEFORE.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , F773D2547B618EDE21759282FC4F0CD2, 1F0F521CA8586846C9623F7BDBEFBBBC84CEC351AC3925DC66E8C59E44CB1713
  47. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\PLAYINSTALL.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 295A6F94BDE7AD570ED22653533B142C, 3638E918A3F0DFA6A610BCF906E6BD2413BE02621154800FC18A0DD15D43F142
  48. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\STOPPLAY.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , F3CCF2596704547B246CBC3BDDC301F6, F4147B15DE09F117235FA765C9796D6FF424F703D34ACDBFCF2D1177B0F2DF1A
  49. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\VIDEOSTOPVIDEO.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 590361F848DB0027505396828F95868A, 36D4159D7D413FCE963687F89EC4AEC7EE8AB6FBA05697E0BA0634DB36A673A8
  50. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\STOPSTOPDATE.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 8E0FEF8EA7204E668B3CAB3BFB4CA096, 41EE1D7254BE06B34250D38FC6D0406A5FEBB22187E14FD50511E39069091391
  51. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\MP3MP4.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 2552F71685C4BD3379EBC4F971BF26C6, 612F74D0A1F2F90A5A4AE11889755EA68656967CF0401E15D9C375DDCFB1D9E7
  52. RiskWare.ExtensionMismatch, C:\USERS\HP\DOWNLOADS\COMPRESSED\3POJ8MF9_2021-08-10-TA551-BAZARLOADER-WITH-COBALTSTRIKE-MALWARE-SAMPLES\HTA-AND-DLL-FILES\VIDEOINSTALL.JPG, Quarantined, 12142, 79314, 1.0.44032, , ame, , 738025A0727D4F95C08895447B936247, 5590123543C7E78AF3C7911466B6C4147F1B39928F648A252132BAF06F2B1153

  53. Physical Sector: 0
  54. (No malicious items detected)

  55. WMI: 0
  56. (No malicious items detected)


  57. (end)
复制代码

心醉咖啡
发表于 2021-8-11 19:04:53 | 显示全部楼层
毒霸
  1. 扫描时间:[2021-08-11 19:04:18]
  2. 扫描用时:[00:00:08]
  3. 扫描类型:自定义查杀
  4. 扫描文件总数:31
  5. 扫描速度:3文件/秒
  6. 发现威胁:30个
  7. 清除威胁:30个
  8. =============================================
  9. [2021-08-11 19:04:36]
  10. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-01.txt
  11. 类型:win32.scriptc.undef.a.(kcloud)
  12. 处理方式:删除

  13. [2021-08-11 19:04:36]
  14. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-02.txt
  15. 类型:win32.scriptc.undef.a.(kcloud)
  16. 处理方式:删除

  17. [2021-08-11 19:04:36]
  18. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-03.txt
  19. 类型:win32.scriptc.undef.a.(kcloud)
  20. 处理方式:删除

  21. [2021-08-11 19:04:36]
  22. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-04.txt
  23. 类型:win32.scriptc.undef.a.(kcloud)
  24. 处理方式:删除

  25. [2021-08-11 19:04:36]
  26. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-05.txt
  27. 类型:win32.scriptc.undef.a.(kcloud)
  28. 处理方式:删除

  29. [2021-08-11 19:04:36]
  30. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-06.txt
  31. 类型:win32.scriptc.undef.a.(kcloud)
  32. 处理方式:删除

  33. [2021-08-11 19:04:36]
  34. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-07.txt
  35. 类型:win32.scriptc.undef.a.(kcloud)
  36. 处理方式:删除

  37. [2021-08-11 19:04:36]
  38. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-08.txt
  39. 类型:win32.scriptc.undef.a.(kcloud)
  40. 处理方式:删除

  41. [2021-08-11 19:04:36]
  42. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-09.txt
  43. 类型:win32.scriptc.undef.a.(kcloud)
  44. 处理方式:删除

  45. [2021-08-11 19:04:36]
  46. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\2021-08-10-ta551-hta-file-example-10.txt
  47. 类型:win32.scriptc.undef.a.(kcloud)
  48. 处理方式:删除

  49. [2021-08-11 19:04:36]
  50. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\installsetupstart.jpg
  51. 类型:win32.troj.generic_a.a.(kcloud)
  52. 处理方式:删除

  53. [2021-08-11 19:04:36]
  54. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\installvideo.jpg
  55. 类型:win32.troj.generic_a.a.(kcloud)
  56. 处理方式:删除

  57. [2021-08-11 19:04:36]
  58. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\mp3mp4.jpg
  59. 类型:win32.troj.generic_a.a.(kcloud)
  60. 处理方式:删除

  61. [2021-08-11 19:04:36]
  62. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\mp4wavbefore.jpg
  63. 类型:win32.troj.generic_a.a.(kcloud)
  64. 处理方式:删除

  65. [2021-08-11 19:04:36]
  66. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\playinstall.jpg
  67. 类型:win32.troj.generic_a.a.(kcloud)
  68. 处理方式:删除

  69. [2021-08-11 19:04:36]
  70. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\startmix.jpg
  71. 类型:win32.troj.generic_a.a.(kcloud)
  72. 处理方式:删除

  73. [2021-08-11 19:04:36]
  74. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\stopplay.jpg
  75. 类型:win32.troj.generic_a.a.(kcloud)
  76. 处理方式:删除

  77. [2021-08-11 19:04:36]
  78. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\stopstopdate.jpg
  79. 类型:win32.troj.generic_a.a.(kcloud)
  80. 处理方式:删除

  81. [2021-08-11 19:04:36]
  82. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\videoinstall.jpg
  83. 类型:win32.troj.generic_a.a.(kcloud)
  84. 处理方式:删除

  85. [2021-08-11 19:04:36]
  86. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\hta-and-dll-files\videostopvideo.jpg
  87. 类型:win32.troj.generic_a.a.(kcloud)
  88. 处理方式:删除

  89. [2021-08-11 19:04:36]
  90. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\bid,08.21.doc
  91. 类型:win32.scriptc.undef.a.(kcloud)
  92. 处理方式:删除

  93. [2021-08-11 19:04:36]
  94. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\docs,08.010.2021.doc
  95. 类型:win32.scriptc.undef.a.(kcloud)
  96. 处理方式:删除

  97. [2021-08-11 19:04:36]
  98. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\instruct 08.21.doc
  99. 类型:win32.scriptc.undef.a.(kcloud)
  100. 处理方式:删除

  101. [2021-08-11 19:04:36]
  102. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\legal paper-08.21.doc
  103. 类型:win32.scriptc.undef.a.(kcloud)
  104. 处理方式:删除

  105. [2021-08-11 19:04:36]
  106. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\material-08.21.doc
  107. 类型:win32.scriptc.undef.a.(kcloud)
  108. 处理方式:删除

  109. [2021-08-11 19:04:36]
  110. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\official paper-08.21.doc
  111. 类型:win32.scriptc.undef.a.(kcloud)
  112. 处理方式:删除

  113. [2021-08-11 19:04:36]
  114. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\report.08.21.doc
  115. 类型:win32.scriptc.undef.a.(kcloud)
  116. 处理方式:删除

  117. [2021-08-11 19:04:36]
  118. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\rule 08.010.2021.doc
  119. 类型:win32.scriptc.undef.a.(kcloud)
  120. 处理方式:删除

  121. [2021-08-11 19:04:36]
  122. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\specifics.08.21.doc
  123. 类型:win32.scriptc.undef.a.(kcloud)
  124. 处理方式:删除

  125. [2021-08-11 19:04:36]
  126. 威胁:e:\浏览器下载\3poj8mf9_2021-08-10-ta551-bazarloader-with-cobaltstrike-malware-samples\extracted-docs\statistics_08.21.doc
  127. 类型:win32.scriptc.undef.a.(kcloud)
  128. 处理方式:删除

复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-25 21:18 , Processed in 0.097246 second(s), 13 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表