楼主: 落华无痕
收起左侧

[病毒样本] 利用W32Time服务TimeProviders开机启动的后门病毒1x

[复制链接]
心心相印
发表于 2022-6-13 21:37:24 | 显示全部楼层
md miss
LeeHS
发表于 2022-6-13 21:46:03 | 显示全部楼层
落华无痕 发表于 2022-6-13 21:34
自解压包的方便点:https://free.lanzoub.com/iogrl06cwuvc

crowdstrike 双击杀
Hibike
发表于 2022-6-13 21:54:01 | 显示全部楼层



管家 miss



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kuroandsan
发表于 2022-6-13 22:24:04 | 显示全部楼层
本帖最后由 kuroandsan 于 2022-6-13 22:25 编辑

dll 信誉杀


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
swizzer
发表于 2022-6-13 23:48:18 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
zwl2828
发表于 2022-6-14 06:00:36 | 显示全部楼层
McAfee
1x
wwwab
发表于 2022-6-14 06:51:10 | 显示全部楼层
Hello,
Thank you for the submitted sample (sample-16551239271766.dll.zip).

We have received an update from our Antimalware Laboratory regarding the analysis of the provided sample which states that the file is malicious and a detection will be added in the next couple of updates. Make sure to have Bitdefender Endpoint Security Tools properly updated, in order to benefit from the best protection.  

Should you need any further information, please don't hesitate to contact us.  

Have a nice day!
Solomondemeter
发表于 2022-6-14 08:59:26 | 显示全部楼层
Time;Scanner;Object type;Object;Detection;Action;User;Information;Hash;First seen here
14/6/2022 上午 8:56:55;Real-time file system protection;file;C:\Users\123\OneDrive\桌面\NtpService\NtpService.dll;a variant of Win64/Agent.BKM trojan;cleaned by deleting;PIXEL\123;Event occurred during an attempt to access the file by the application: C:\Program Files\Microsoft OneDrive\OneDrive.exe (81C18400CC9E4284707FEBAB832E26D2C342369E).;0EE3C10DF605E6A13F5E3BD4BAFE8824BA236C50;13/6/2022 下午 7:13:29
谈谈MEMZ
发表于 2022-6-14 20:43:10 | 显示全部楼层
wwwab
发表于 2022-6-15 19:26:13 | 显示全部楼层
The SophosLabs has reviewed the submitted sample and have stated the following:
-- Detection added on the file “NtpService.dll” as Troj/Agent-BIYL, it is dropped at %windir%\system32% by parent file EXTSETUP_1_6.exe - 3f4d31c4d587a1d0591563561a469978a18942c2

-- Yesterday we already added detection for the parent file as Troj/Inject-HVO
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-7 03:04 , Processed in 0.097209 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表