查看: 1904|回复: 15
收起左侧

[病毒样本] 恶意msi 白加黑 new

[复制链接]
wwwab
发表于 2023-6-19 20:04:34 | 显示全部楼层 |阅读模式
心醉咖啡
发表于 2023-6-19 20:08:26 | 显示全部楼层
火绒扫描miss
swizzer
发表于 2023-6-19 20:08:40 | 显示全部楼层
本帖最后由 swizzer 于 2023-6-19 20:34 编辑




  1. The app C:\Users\Public\Documents\62O1P\EQ6d5@v1\ConsoleProxy.exe has been detected as a potentially unwanted application and was moved to quarantine.
  2. Detection name: Application.Agent.LCC
复制代码


123456aaaafsdeg
发表于 2023-6-19 20:10:21 | 显示全部楼层
Wps_ Setup.msi detected as PUP
对对对对
发表于 2023-6-19 20:10:49 | 显示全部楼层
360 时间        操作        说明        次数
2023-06-19 20:10:02        [已清除]          发现木马:Generic/Trojan.Generic.HnoATEcA        防护 1 次
详细描述:
木马名称:Generic/Trojan.Generic.HnoATEcA
所在路径:C:\Users\Aserdong\AppData\Local\Temp\360zip$Temp\360$0\WPS_Setup.msi
Hibike
发表于 2023-6-19 20:13:07 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
anthonyqian
发表于 2023-6-19 20:22:27 | 显示全部楼层
本帖最后由 anthonyqian 于 2023-6-20 08:31 编辑

ESET 0

The detection for this threat will be included in the next update of detection engine, expected version: 27435.

WPS_Setup.msi - Win32/Farfli.DCK trojan


喀反
发表于 2023-6-19 20:49:33 | 显示全部楼层
WD kill msi Trojan:Win32/Spursint.F!cl
km_xyx
发表于 2023-6-19 20:58:19 | 显示全部楼层
Avast miss
隔山打空气
发表于 2023-6-19 21:07:43 | 显示全部楼层
SentinelOne
Shellcode detected

Persistence
Application registered itself to become persistent via service
MITRE : Privilege Escalation [T1543.003][T1547.001]
MITRE : Persistence [T1543.003][T1547.001]

Exploitation
Detected a shellcode that loads a DLL with socket APIs after process creation
MITRE : Defense Evasion [T1055.001]
MITRE : Privilege Escalation [T1055.001]

Reconnaissance
Network sniffing API DLL loaded
MITRE : Credential Access [T1040]
MITRE : Discovery [T1040]
A known network sniffing executable was run
MITRE : Credential Access [T1040]
MITRE : Discovery [T1040]

Evasion
Indirect command was executed
MITRE : Defense Evasion [T1218][T1202]

General
User logged on
MITRE : Persistence [T1078]
MITRE : Defense Evasion [T1078]
MITRE : Privilege Escalation [T1078]
MITRE : Initial Access [T1078]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-2 06:39 , Processed in 0.125774 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表