楼主: 神龟Turmi
收起左侧

[病毒样本] 龟包 240107 30X

  [复制链接]
123456aaaafsdeg
发表于 2024-1-7 14:12:16 | 显示全部楼层
xcvbaby 发表于 2024-1-7 14:02
鲁大师病毒查杀:24x(看安装目录应该用的小红伞的引擎)

鲁大师。。。杀毒功能。。。和360肩并肩?
ANY.LNK
发表于 2024-1-7 14:20:10 | 显示全部楼层
嗯……看来我这边网络又抽风了,机器人验证过不去

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
神龟Turmi
 楼主| 发表于 2024-1-7 14:23:39 | 显示全部楼层

查日志没查到什么问题 方便的话pm我一下公网ip我详细看一下
123456aaaafsdeg
发表于 2024-1-7 14:29:19 | 显示全部楼层
本帖最后由 123456aaaafsdeg 于 2024-1-7 14:31 编辑

分流:https://pro.huang1111.cn/s/bxpHO
  1. 360 Total Security扫描日志

  2. 扫描时间:2024-01-07 14:29:03
  3. 扫描用时:00:00:22
  4. 扫描项目总数:118
  5. 威胁总数:23
  6. 处理威胁数:23

  7. 扫描选项
  8. ----------------------
  9. 扫描压缩包:否
  10. 常规引擎设置:鲲鹏引擎

  11. 扫描内容
  12. ----------------------
  13. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-05-Hijack\
  14. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-08-Wasp-a85458.exe
  15. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-09-NJRat-85f1b4.exe
  16. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-10-StormKitty-db61c7.exe
  17. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-11-StormKitty-a48ab6.exe
  18. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-12-Miner-e776ac.exe
  19. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-13-Unknown-0e2013.exe
  20. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-14-CobaltStrike-816da6.exe
  21. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-15-CobaltStrike-1bddd4.exe
  22. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-16-Reverse-69c288.exe
  23. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-17-Expiro-3d5d51.exe
  24. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-18-Expiro-8688c0.exe
  25. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-19-Expiro-3cba45.exe
  26. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-20-Expiro-8fe8ce.exe
  27. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-21-Expiro-6afa85.exe
  28. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-22-Expiro-6248c7.exe
  29. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-23-Miner-6c975d.exe
  30. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-24-Antavmu-daa40a.exe
  31. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-25-Antavmu-559e70.exe
  32. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-26-Expiro-fd7a6c.exe
  33. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-27-Sfone-caefeb.exe
  34. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-28-Facido-e38b98.exe
  35. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-29-Berbew-cda438.exe
  36. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-30-Revenge-50a7ca.exe

  37. 扫描结果
  38. ======================
  39. 高风险项目
  40. ----------------------
  41. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-05-Hijack\Register.dll 9E91E13DFC7956487E58A58658FF236B 24C8DD08E4679EA932F2569C68ED88D713CFCA15 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win32/Trojan.Generic.HgkATRAA][隔离文件][已处理]
  42. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-09-NJRat-85f1b4.exe 8A05D2196C045B19AF0094FE35240614 85F1B4F55A9612B1F06ED403FD93114EC83B4023 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win32/Backdoor.NjRAT.HykCfiwA][隔离文件][已处理]
  43. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-10-StormKitty-db61c7.exe DB6F79C65191CFD9B40BE0F4B0F01810 DB61C7EF4537F57AF736044FF3B93D8A8B49FBA8 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][G_Trojan.MSIL.0e4C8!pG14][隔离文件][已处理]
  44. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-11-StormKitty-a48ab6.exe A2EE5D8372BAB116504DA13652C53BC0 A48AB6532C9599854A7B972B1181F1E90BFB1A15 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win32/TrojanDropper.Generic.HgIATQ8A][隔离文件][已处理]
  45. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-12-Miner-e776ac.exe 15136FD54C900B1DE57DC97277E24740 E776AC3C6993E804DFADD6256DAA250E36D3390D 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][G_Trojan.Gen.0e4C8!cyfn][隔离文件][已处理]
  46. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-13-Unknown-0e2013.exe 0E6F13FF8E458A4BAF9A39B46CCADBE0 0E20135934D0BB9636EF14729F0069073CAB8338 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Trojan.Generic.H8oAe1cA][隔离文件][已处理]
  47. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-14-CobaltStrike-816da6.exe E983E808D6F334C6B9B8DEA2537E0120 816DA6285E0F6DCD6FB8220BA57DEB0CDE364180 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/HackTool.CobaltStrike.H8oAevkA][隔离文件][已处理]
  48. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-15-CobaltStrike-1bddd4.exe C09D21A2EFE6C19F614403CA143D2180 1BDDD4010DC8A03D078902734B244528DB90DE83 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/HackTool.CobaltStrike.H8oAf8AA][隔离文件][已处理]
  49. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-16-Reverse-69c288.exe 9493AEFB50AC38079B7A7203427E83A0 69C288994283A1370835509F03DFC06528E739CB 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Heur.Generic.H8oAJ1wA][隔离文件][已处理]
  50. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-17-Expiro-3d5d51.exe F68280AC44ACDECF0309BFD2B67A50C0 3D5D51F086EA1A6146A068A9E095A67F46F6FE92 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.H8oAJ1wA][隔离文件][已处理]
  51. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-19-Expiro-3cba45.exe AABE4B5D62C70C4FB87462C6BC8D4C50 3CBA45BB2E9D428AE0E84A454B67F76F2D495540 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.HgEATQkA][隔离文件][已处理]
  52. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-20-Expiro-8fe8ce.exe 0419A98E30D3C4AB45521641CFE39F80 8FE8CECC8F1400C4579892FEFEBE72E1F35CD2F6 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.H8oAJ1wA][隔离文件][已处理]
  53. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-21-Expiro-6afa85.exe FEA144EFB8756C20B1E4A1F51D153390 6AFA85745C460B1569A172952F4E20D8C564CEDB 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.H8oAJ1wA][隔离文件][已处理]
  54. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-22-Expiro-6248c7.exe F13FF2B7205E322CABCBA1031B4680D0 6248C7EC0088028C5756CF23ECF34791DB2ED8C3 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.H8oAJ1wA][隔离文件][已处理]
  55. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-23-Miner-6c975d.exe 7750884128B4A305BD70E736623AD460 6C975D1898C21EA5F57CB9A7FDF09124C9611C81 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Miner.Generic.H8oAJ1wA][隔离文件][已处理]
  56. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-24-Antavmu-daa40a.exe FFC5AF5F265113318368C0A937F436D0 DAA40A2D47D83D0EF3834120ED2D900B22C89C37 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][Trojan.Win32.KillFiles.A][隔离文件][已处理]
  57. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-25-Antavmu-559e70.exe 0849327E9FB19889C09A9209EC225A50 559E70CEE2CCD2E84E21ADD1793E0426F34F26A4 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][Trojan.Win32.KillFiles.A][隔离文件][已处理]
  58. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-26-Expiro-fd7a6c.exe FEF6E00D5E4962DC640F66C8665B8A90 FD7A6C1FE7AFF1433C9222E7D35AC19FA7FEA31A 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.H8oAJ1wA][隔离文件][已处理]
  59. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-27-Sfone-caefeb.exe A64D19ADC43745342175BC12038A8890 CAEFEBB41A2D9124DEEEF634E01864A113C2B4C0 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][Worm.Win32.Sfone.E][隔离文件][已处理]
  60. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-18-Expiro-8688c0.exe E9C43F272FD5EAABEDDE8A522C21F240 8688C01A70851DAAACAD4AA606F5D7FE8F7BAA35 70,3,2,4,280,1,256, || 0_0_1  [360云查杀引擎][Win64/Virus.Expiro.H8oAJ1wA][隔离文件][已处理]
  61. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-29-Berbew-cda438.exe 36F91829EFB064F9854D2A59CBE8D8D0 CDA43884BEA3FCD7049C7C5A86BFDADD5A5EBCF2 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][Backdoor.Win32.Berbew.M][隔离文件][已处理]
  62. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-28-Facido-e38b98.exe AEA6011F9E4F9A7CF53A621749443E00 E38B98E3C948D02A6F613CCEA0CA26F97CF860FB 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][G_Trojan.Gen.0e4C8!j5Hf][隔离文件][已处理]
  63. C:\Users\Administrator\Desktop\新建文件夹\TurtleSUSP-240107-30-Revenge-50a7ca.exe DB18BD492F7F4AEFB385D5C71895DE80 50A7CAF1BB962DFBC780470C7497901903A48FAA 70,4,2,4,280,1,256, || 0_0_1  [鲲鹏引擎][G_Trojan.Gen.0e4C8!j4jv][隔离文件][已处理]
复制代码



评分

参与人数 1人气 +2 收起 理由
ANY.LNK + 2 感谢分流

查看全部评分

LSPLDD
发表于 2024-1-7 14:38:52 | 显示全部楼层
卡巴扫描 Kill 26X
双击Kill 2X

剩余:
TurtleSUSP-240107-11-StormKitty-a48ab6.exe 未能成功运行
TurtleSUSP-240107-16-Reverse-69c288.exe      miss



wwwab
发表于 2024-1-7 14:42:26 | 显示全部楼层
2345:

开启小红伞引擎后24X




关闭小红伞引擎后零鸭蛋

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
123456aaaafsdeg + 1 蚌埠住了

查看全部评分

smz2011
发表于 2024-1-7 14:56:32 | 显示全部楼层
本帖最后由 smz2011 于 2024-1-7 14:59 编辑

大陆用户也被和谐了……     ANKit kill 28xD:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-01-Rootkit-ac7b1b.sys发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-02-Rootkit-ef0b03.sys发现引擎:(ANK)ML.89+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-03-NJRat-ce0020.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-04-NJRat-d96e8f.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-06-Redline-8bbef9.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-07-Purelogs-ac5e54.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-09-NJRat-85f1b4.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-10-StormKitty-db61c7.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-11-StormKitty-a48ab6.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-12-Miner-e776ac.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-13-Unknown-0e2013.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-14-CobaltStrike-816da6.exe发现引 擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-15-CobaltStrike-1bddd4.exe发现引 擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-16-Reverse-69c288.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-17-Expiro-3d5d51.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-18-Expiro-8688c0.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-19-Expiro-3cba45.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-20-Expiro-8fe8ce.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-21-Expiro-6afa85.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-22-Expiro-6248c7.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-23-Miner-6c975d.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-25-Antavmu-559e70.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-26-Expiro-fd7a6c.exe发现引擎:(ANK)ML.83+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-27-Sfone-caefeb.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-28-Facido-e38b98.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-29-Berbew-cda438.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-30-Revenge-50a7ca.exe发现引擎:(ANK)ML.100+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-05-Hijack\Register.dll发现引擎:(ANK)ML.78+(360)cloud
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-05-Hijack\Settings\VBoxC.dll发现 引擎:(ANK)ML.57
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-05-Hijack\Settings\VBoxDD.dll发现引擎:(ANK)ML.29
D:\HuaweiMoveData\Users\dsm77\Desktop\卡饭论坛\TurtleSUSP-240107 (2)\TurtleSUSP-240107-05-Hijack\Settings\VBoxDD2.dll发 现引擎:(ANK)ML.71

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
神龟Turmi
 楼主| 发表于 2024-1-7 14:59:13 | 显示全部楼层
smz2011 发表于 2024-1-7 14:56
大陆用户也被和谐了……

已经确认这个问题是无法访问google recaptcha导致的
我已经暂时关掉了recaptcha
晚些换到hcaptcha/arkose
刷新应该就可以访问了
天狐狐狐
发表于 2024-1-7 16:09:50 | 显示全部楼层
神龟Turmi 发表于 2024-1-7 14:59
已经确认这个问题是无法访问google recaptcha导致的
我已经暂时关掉了recaptcha
晚些换到hcaptcha/arko ...

可以访问了
神龟Turmi
 楼主| 发表于 2024-1-7 16:15:10 | 显示全部楼层

嗯 晚点换别的验证码
看起来即使用recaptcha.net而不是google.com域名 到recaptcha有连通性问题的人也不在少数。。。

评分

参与人数 1人气 +1 收起 理由
Eset小粉絲 + 1 可以下载了

查看全部评分

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-8 16:02 , Processed in 0.090023 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表