123
返回列表 发新帖
楼主: huangzihang
收起左侧

[讨论] (里程碑)BDTS首次在magniber双击运行后成功封锁

[复制链接]
企稳向好
发表于 2022-6-6 14:44:16 | 显示全部楼层
pal家族 发表于 2022-6-6 11:24
那你再找一个没入库的 试下主防呗

ATD目前是拦不住的。日志里连着一堆检测到恶意命令行,但该加密还是加密
企稳向好
发表于 2022-6-6 14:47:00 | 显示全部楼层
本帖最后由 企稳向好 于 2022-6-6 14:59 编辑
a8855942 发表于 2022-6-6 10:18
应该测测企业版

企业版现在是这样,对于新mb变种:
HD机器学习没有对应模型;
ATD拦不住加密;
msi似乎触发不了沙盒分析(但就算触发也没什么用,手动上传,BD企业版沙盘分析跑不出行为)之前SA是这么说的:
The sample avoids analysis by checking whether it is run in a virtual environment or monitored with debuggers or other monitoring tools. Moreover, the sample performs various changes on the system so it can remain hidden. Such changes include hiding files or file extensions, modifying security, notifications or system settings, deleting the original file, changing file attributes or other actions. The sample writes additional files on the system, which may be used in various ways, including ensuring persistence. The new files can be executables that continue the sample's actions or storage/configuration files that hold viable information for the sample.

然后鉴定为
No threat detected

结论:拦不住

下次有新样本可以@我,我多整些人工丢到SA去跑跑看
mogu6666
发表于 2022-6-6 15:55:40 | 显示全部楼层
两周之前给Bitdefender上报的一个病毒现在终于处理了(也有可能是因为我用的是wetransfer网盘,文件过大处理慢)
来了三个邮件,第一封是自动回复,此时是2022/5/21
Thank you for contacting Bitdefender Customer Care.

This is an automated reply to confirm that we have received your request, and that we are working on resolving your issue(s) as promptly as possible. Your assigned ticket number is 1007440566 . We advise that you keep this reference number in a safe place for further tracking/follow-up.

Regards,

Bitdefender Customer Care Team
然后在我以为石沉大海的时候,2022/6/4来了第二封
Hello,

First of all, please accept my apologies for our late reply, it was by no means intended. We are working around the clock to improve our response time and I am sure that in the future you will notice a significant improvement.

We have sent the files to our Malware Research Lab for analysis purposes and we will contact you with more information once this process has been successfully completed.

Have a great day!

Best regards,
Mihnea G.
Technical Support Engineer
2022/6/5第三个,终于处理了
Hello,

Thank you for your patience and I hope my e-mail finds you well.

Our malware research team has finished analyzing the sample you submitted.
The file is malicious and detection will be added in the next couple of updates.

Feel free to get back to me anytime if you have other cyber-security questions.

Stay safe and have a great day!

Best regards,
Mihnea G.
Technical Support Engineer
起码比ESET强,可见官方对上报还是上心的
Tom179090
发表于 2022-6-6 18:16:06 | 显示全部楼层
本帖最后由 Tom179090 于 2022-6-6 18:17 编辑

可以理解为他们打算提取人工特征了吗?虽然是 "during the next couple of weeks"
BD expert community:
anti-malware team is working for a detection which should be activated during the next couple of weeks. Thanks again for sharing this in our community.

cheers,

Mike



欧阳宣
头像被屏蔽
发表于 2022-6-7 04:41:04 | 显示全部楼层
什么时候能少一点这种一个样本论英雄

要么封神要么过街老鼠的帖子呢
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-28 07:15 , Processed in 0.097864 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表