楼主: 神龟Turmi
收起左侧

[病毒样本] TurtleRansom v0

  [复制链接]
wwwab
发表于 2023-11-29 06:54:57 | 显示全部楼层
Hi Team,

Sophos Labs has reviewed your sample and have determined the following:

File states:

============
Following samples are covered under “Troj/Agent-BKJG“

ELF
c13b626e4f1d27ef1220e83c0e6a04b1e508cc50
08279fc6616a8adac0346d5e9b60dfbe9c254b81
b3c1324dc47e3ec34114b8129ab1aaa1ba42c03e
67ec42249df03ec57845c65cd3d59a4ca8ac27f4
06f7b22c7645eb74bc3e7965eb4c88c912cb116f
9079552373d2c573638d80d623b1e77086aae358

Macho
264a7608b986f2aa163ee173828d7f1d44061a54
aad142a701e8b27278477e52582d2b7e49cda1f4

555.exe (SHA1: 804faed19c0d48e8e5f68c6153c58c1d1a2ca0ff) is corrupt


This ticket will now be closed.
Sophos:这Windows端的样本损坏了吧
小岛花六
发表于 2023-11-29 13:44:35 | 显示全部楼层



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
dustychen1
发表于 2023-12-1 18:00:23 | 显示全部楼层

感谢老哥,Dr.Web清空

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
anthonyqian
发表于 2023-12-3 17:19:04 | 显示全部楼层
铁壳终于分析完了,目测全部hash拉黑:

Files Submitted / Assessment
#FilenameHash (SHA256/MD5)DeterminationSignature Protection NameExtended Defs Version & Sequence NumberAssessment
120231125132148-12-sample(s).zipBA8625595D62F9F6573BF9F0257648DAC3E7C09A6DC0451D156A05C1C6D83D36 / 0F1B0C3BB7D8E128ECBBE6571CFBA749ArchiveN/A
N/AFile is a archive file.
291a5faa41d19090e1c5c1016254fd22a.virA48AF4A62358831FE5376AA52DB1A3555B0C93C1665B242C0C1F49462F614C56 / 91A5FAA41D19090E1C5C1016254FD22AAlready DetectedOSX.Trojan.Gen
11/27/2023 rev. 20 & 231678File is detected by Symantec AV products with the latest definitions.
38aa2ba539740aed251f006c2c6ecad23.vir52337055CCA751B8B2B716A1C8F3BA179DDD74B268B67641ADE223D3D3CF773D / 8AA2BA539740AED251F006C2C6ECAD23Already Detectedtrojan.gen.mbt
11/27/2023 rev. 20 & 231678File is detected by Symantec AV products with the latest definitions.
467baf56a929be3a7b03459f8bee5a0a1.virF5B9B80F491E5779F646D2510A2C9C43F3072C45302D271798C4875544ACE4F2 / 67BAF56A929BE3A7B03459F8BEE5A0A1Already Detectedtrojan.gen.npe
11/27/2023 rev. 20 & 231678File is detected by Symantec AV products with the latest definitions.
58a53f6e4e46023de77d874c2faca020c.virA4789E0B79A8BAC486FBC3B0F00B6DCBAAC6854E621D40FC3005D23F83D2E5EC / 8A53F6E4E46023DE77D874C2FACA020CAlready Detectedtrojan.gen.npe
11/27/2023 rev. 20 & 231678File is detected by Symantec AV products with the latest definitions.
6782284dae1244553f15795f5e32f1f56.virB384155B74845BEEEA0F781C9C216C69ECEB018520D819DD09823CFF6EF0E7DE / 782284DAE1244553F15795F5E32F1F56Already Detectedtrojan.gen.npe
12/1/2023 rev. 21 & 231765File is detected by Symantec AV products with the latest definitions.
7a5023ffd14ce39f2ca81261a36bc1927.vir5F9CD91D8D1DCFE2F6CF4C6995AD746694CE57023DFB82B1CD6AF5697113D1B0 / A5023FFD14CE39F2CA81261A36BC1927Already DetectedOSX.Trojan.Gen
11/26/2023 rev. 22 & 231663File is detected by Symantec AV products with the latest definitions.
87acca4ae31fca1e92d92374e53e6fdd6.vir00B52A5905E042A9A9F365F7E5404F420AE26F463F24C069D6076E9094F61A8E / 7ACCA4AE31FCA1E92D92374E53E6FDD6Already Detectedtrojan.gen.mbt
11/26/2023 rev. 22 & 231663File is detected by Symantec AV products with the latest definitions.
9529404c71791ae3c4d4c4cbd2901167b.vir62F84AFDAB28727AB47B5C1E4AF92B33DC2B11E55DCA7B097FE94DA5BCC9EC4E / 529404C71791AE3C4D4C4CBD2901167BAlready Detectedtrojan.gen.npe
11/28/2023 rev. 23 & 231703File is detected by Symantec AV products with the latest definitions.
10c0fc411df7436c28e8e567407c185d97.virDF5F7570BF0B1F99F33C31913AB9F25B9670286E8E2462278AEA2157F8173A68 / C0FC411DF7436C28E8E567407C185D97Already Detectedtrojan.gen.npe
12/2/2023 rev. 20 & 231785File is detected by Symantec AV products with the latest definitions.
11822900fa44a08a8a1e1f0dc14697d5b8.virF14EF1C911DEB8714D1BB501064505C13237049AC51F0A657DA4B0BF11F5F59E / 822900FA44A08A8A1E1F0DC14697D5B8Already Detectedtrojan.gen.mbt
11/26/2023 rev. 22 & 231663File is detected by Symantec AV products with the latest definitions.
1212306f134610a7aba33ba67993dfb9ad.vir65EEA957148D75C29213DFF0C5465C6DC1DB266437865538CFE8744C2436F5E1 / 12306F134610A7ABA33BA67993DFB9ADAlready Detectedtrojan.gen.mbt
11/26/2023 rev. 22 & 231663File is detected by Symantec AV products with the latest definitions.
1379966500ccb17916d24ba2a2bfd875a7.virB5AB9C61C81DFCD2242B615C9AF2CB018403C9A784B7610B39ED56222D669297 / 79966500CCB17916D24BA2A2BFD875A7Already Detectedtrojan.gen.npe
11/29/2023 rev. 23 & 231724File is detected by Symantec AV products with the latest definitions.
bbszy
发表于 2023-12-3 23:01:22 | 显示全部楼层
vt上趋势不报
mac上的趋势清空

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
GreatMOLA
发表于 2023-12-4 12:08:36 | 显示全部楼层
anthonyqian 发表于 2023-12-3 17:19
铁壳终于分析完了,目测全部hash拉黑:

Files Submitted / Assessment

实测也是拉黑报法,AdvML根本没触发。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-6 17:52 , Processed in 0.111792 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表