查看: 1037|回复: 13
收起左侧

[病毒样本] 龟包 240312 9X

[复制链接]
神龟Turmi
发表于 2024-3-12 20:08:24 | 显示全部楼层 |阅读模式
下载:
https://malware.camp/Turtle/TurtleSUSP-240312.zip
分流:
https://mirrors-s1.malware.camp/Turtle/TurtleSUSP-240312.zip
https://mirrors-s2.malware.camp/Turtle/TurtleSUSP-240312.zip
https://mirrors-s3.malware.camp/Turtle/TurtleSUSP-240312.zip
龟包列表:
https://malware.camp/Turtle/

Webroot:


扫描7X 双击1X衍生物 余StrRAT无Java环境暂未双击
合计8/9

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
t0kenzero
发表于 2024-3-12 20:10:42 来自手机 | 显示全部楼层
本帖最后由 t0kenzero 于 2024-3-12 20:32 编辑

cylance 7X
Miss
TS-240312-04-StrRAT-856900
TS-240312-08-UnknownStealer-51f52a

Fadouse
发表于 2024-3-12 20:13:09 | 显示全部楼层
本帖最后由 Fadouse 于 2024-3-12 20:15 编辑

Kaspersky Premium+ ESSP 清空

Jar运行卡巴斯基PDM杀
其余解压杀

  1. Time;Scanner;Object type;Object;Detection;Action;User;Information;Hash;First seen here
  2. 3/12/2024 8:13:21 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-02-RisePro-b03aed.exe;a variant of MSIL/Kryptik.ALDJ trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;B03AEDDEE413357B2A9BAD2E408C59894DAAEA9A;3/12/2024 8:12:01 PM
  3. 3/12/2024 8:13:21 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-01-AgentTesla-362ce9.exe;a variant of MSIL/Kryptik.ALDN trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;362CE94F21182850CCAA5B6504D8C1E78FFD06A9;3/12/2024 8:12:00 PM
  4. 3/12/2024 8:13:22 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-05-Remcos-368d0b.exe;Win32/TrojanDownloader.ModiLoader.ABF trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;368D0BB53222008A264E8E860CC181540A48EA5F;3/12/2024 8:12:01 PM
  5. 3/12/2024 8:13:25 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-09-Lumma-a2aef4.exe;a variant of MSIL/Kryptik.ALCY trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;A2AEF4A79EC52FE8BD228A49FD78A7876DC4600B;3/12/2024 8:12:01 PM
  6. 3/12/2024 8:13:26 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-08-UnknownStealer-51f52a.exe;a variant of Win32/TrojanDropper.Agent.SLC trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;51F52A5A139D1642CA71A2A41A09D8BB4524709C;
  7. 3/12/2024 8:13:27 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-06-FormBook-7aa5cc.exe;a variant of MSIL/Kryptik.ALDA trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;7AA5CCCD0EF833A30C1E111A44A1990E7C8F9702;3/12/2024 8:12:01 PM
  8. 3/12/2024 8:13:28 PM;Real-time file system protection;file;E:\Code\Virus\TS-240312-03-RisePro-130424.exe;a variant of Win32/Agent.ADVG trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;13042435D155CBA9C0170C815A3D920D1BB527F4;3/12/2024 8:12:01 PM
复制代码
  1. Event: Malicious object detected
  2. Application: Java(TM) Platform SE binary
  3. User: LAPTOP\Fadouse
  4. User type: Initiator
  5. Component: System Watcher
  6. Result description: Detected
  7. Type: Trojan
  8. Name: PDM:Trojan.Win32.Bazon.a
  9. Threat level: High
  10. Object type: File
  11. Object path: E:\Code\Virus
  12. Object name: TS-240312-04-StrRAT-856900.jar
  13. Reason: Behavior analysis
  14. Databases release date: Today, 3/12/2024 2:48:00 PM
  15. MD5: 575D75ECAE9946950AF94951BFAC908E
  16. Event: Malicious object detected
  17. User: LAPTOP\Fadouse
  18. User type: Initiator
  19. Application name: explorer.exe
  20. Application path: C:\Windows
  21. Component: File Anti-Virus
  22. Result description: Detected
  23. Type: Trojan
  24. Name: UDS:Trojan.MSIL.Taskun.gen
  25. Precision: Exactly
  26. Threat level: High
  27. Object type: File
  28. Object name: TS-240312-01-AgentTesla-362ce9.exe
  29. Object path: E:\Code\Virus
  30. MD5 of an object: B2C3A82ACF4112B2489CB9BDCA04B8EF
  31. Reason: Cloud Protection
复制代码

祸兮福所倚
头像被屏蔽
发表于 2024-3-12 20:23:17 | 显示全部楼层
本帖最后由 祸兮福所倚 于 2024-3-12 20:24 编辑

监控3X+扫描3X=6X

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1094947421
发表于 2024-3-12 20:24:30 | 显示全部楼层
华为7x
  1. 【1】 2024-03-12 20:23:28,自定义扫描,发现风险7个风险项目

  2. 病毒库版本:2024031202
  3. 杀毒引擎版本:11.Release_2024022800
  4. 开始时间:2024-03-12 20:23:28
  5. 总计用时:00:00:00
  6. 任务状态:已完成
  7. 扫描文件:9
  8. 发现风险:7
  9. 已处理风险:0
  10. 病毒详情:
  11. 病毒名称:Win32.Trojan.NN_@t1.9912,病毒文件名称:TS-240312-01-AgentTesla-362ce9.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:28,处置结果:未处置
  12. 病毒名称:Win32.Trojan.NN_@t1.9995,病毒文件名称:TS-240312-02-RisePro-b03aed.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:28,处置结果:未处置
  13. 病毒名称:Win32.Trojan.NN_@t1.9914,病毒文件名称:TS-240312-03-RisePro-130424.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:29,处置结果:未处置
  14. 病毒名称:Win32.Trojan.NN_@t1.9991,病毒文件名称:TS-240312-05-Remcos-368d0b.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:29,处置结果:未处置
  15. 病毒名称:Win32.Trojan.NN_@t1.9955,病毒文件名称:TS-240312-06-FormBook-7aa5cc.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:29,处置结果:未处置
  16. 病毒名称:Win32.Trojan.NN_@t1.9947,病毒文件名称:TS-240312-08-UnknownStealer-51f52a.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:29,处置结果:未处置
  17. 病毒名称:Win32.Trojan.NN_@t1.9999,病毒文件名称:TS-240312-09-Lumma-a2aef4.exe,病毒文件路径:D:\下载\Compressed\TurtleSUSP-240312\,病毒等级:中,病毒类型:木马病毒,病毒发现时间:2024-03-12 20:23:29,处置结果:未处置
复制代码


PYAS_Security
发表于 2024-3-12 20:29:01 | 显示全部楼层
PYAS

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
心醉咖啡
发表于 2024-3-12 20:36:49 | 显示全部楼层
360

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
DisaPDB
发表于 2024-3-12 21:05:03 | 显示全部楼层
本帖最后由 DisaPDB 于 2024-3-12 21:11 编辑

360 二扫6x


StrRAT ATA高置信

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
123456aaaafsdeg
发表于 2024-3-12 21:14:03 | 显示全部楼层
江民3X
s2bRgD
发表于 2024-3-12 22:29:13 | 显示全部楼层
卡巴斯基 plus 9/9

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-28 04:25 , Processed in 0.117464 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表