查看: 1152|回复: 20
收起左侧

[病毒样本] 8x (2024-03-27)

[复制链接]
swizzer
发表于 2024-3-27 15:44:46 | 显示全部楼层 |阅读模式
本帖最后由 swizzer 于 2024-3-27 16:17 编辑

https://funami.lanzoue.com/igszN1st85qd

DI 7/8 (Win平台似乎不检测其他平台的恶意软件?)

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
祸兮福所倚 + 1 版区有你更精彩: )

查看全部评分

keen-qv
发表于 2024-3-27 18:55:29 | 显示全部楼层
本帖最后由 keen-qv 于 2024-3-27 18:56 编辑

火绒 2个(6.0版本,开启高启发,病毒库日期2024-03-27 18:13)

评分

参与人数 1人气 +3 收起 理由
swizzer + 3 最喜欢的一集

查看全部评分

DisaPDB
发表于 2024-3-27 16:09:36 | 显示全部楼层
本帖最后由 DisaPDB 于 2024-3-27 16:11 编辑

360 扫描4x

双击 2x


合计6/8

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Fadouse
发表于 2024-3-27 16:14:11 | 显示全部楼层
  1. Event: Malicious object detected
  2. User: LAPTOP\Fadouse
  3. User type: Active user
  4. Application name: explorer.exe
  5. Application path: C:\Windows
  6. Component: File Anti-Virus
  7. Result description: Detected
  8. Name: UDS:DangerousObject.Multi.Generic
  9. Precision: Exactly
  10. Threat level: High
  11. Object type: File
  12. Object name: timeSync.exe
  13. Object path: E:\Code\Virus
  14. MD5 of an object: 2B635D5080590A14D5AEA4D77BF03CD7
  15. Reason: Cloud Protection
  16. Event: Malicious object detected
  17. User: LAPTOP\Fadouse
  18. User type: Active user
  19. Application name: explorer.exe
  20. Application path: C:\Windows
  21. Component: File Anti-Virus
  22. Result description: Detected
  23. Type: Trojan
  24. Name: Trojan-PSW.Win32.Disco.wks
  25. Precision: Exactly
  26. Threat level: High
  27. Object type: File
  28. Object name: Mauqes.exe
  29. Object path: E:\Code\Virus
  30. MD5 of an object: 75CCB6ED3C85A68633E0DD8319A2CF36
  31. Reason: Databases
  32. Databases release date: Today, 3/27/2024 4:20:00 AM
  33. Event: Malicious object detected
  34. User: LAPTOP\Fadouse
  35. User type: Active user
  36. Application name: explorer.exe
  37. Application path: C:\Windows
  38. Component: File Anti-Virus
  39. Result description: Detected
  40. Name: UDS:DangerousObject.Multi.Generic
  41. Precision: Exactly
  42. Threat level: High
  43. Object type: File
  44. Object name: 7d18e238febf88bc7c868e3ee4189fd12a2aa4db21f66151bb4c15c0600eca6e.exe
  45. Object path: E:\Code\Virus
  46. MD5 of an object: 3E56975127F436AA5E8A9B9C7AF5EB23
  47. Reason: Cloud Protection
  48. Event: Malicious object detected
  49. User: LAPTOP\Fadouse
  50. User type: Initiator
  51. Application name: smartscreen.exe
  52. Application path: C:\Windows\System32
  53. Component: File Anti-Virus
  54. Result description: Detected
  55. Type: Trojan
  56. Name: HEUR:Trojan.VBS.SAgent.gen
  57. Precision: Heuristic Analysis
  58. Threat level: High
  59. Object type: File
  60. Object name: Angel.vbs
  61. Object path: E:\Code\Virus
  62. MD5 of an object: A22712D23B2775C205038A1AC865442A
  63. Reason: Machine learning
  64. Databases release date: Today, 3/27/2024 4:20:00 AM
复制代码
  1. Time;Scanner;Object type;Object;Detection;Action;User;Information;Hash;First seen here
  2. 3/27/2024 3:02:59 PM;Real-time file system protection;file;E:\Code\Virus\cvtres.bat;BAT/TrojanDropper.Agent.NKP trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;19F2B5B063B11D8ED5A61178EB1BA4E1243AE21F;3/27/2024 3:02:17 PM
  3. 3/27/2024 3:03:02 PM;Real-time file system protection;file;E:\Code\Virus\Vbnhtlkdfw.exe;a variant of MSIL/TrojanDownloader.Agent.QNG trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;7B8D97CEF22C86E4C514B78D9AC529357C98D4D3;3/27/2024 3:02:18 PM
  4. 3/27/2024 3:03:03 PM;Real-time file system protection;file;E:\Code\Virus\Qmpjm.exe;a variant of MSIL/Kryptik.AIZW trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;35C32BCAE2F8ECBEADB8D22CF70E254E3E4F9CFA;3/27/2024 3:02:18 PM
  5. 3/27/2024 3:03:04 PM;Real-time file system protection;file;E:\Code\Virus\timeSync.exe;ML/Augur trojan;cleaned by deleting (after the next restart);LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;2BAF94CEA34CDA8BF542BF63AD117F4243345B65;3/27/2024 3:02:18 PM
  6. 3/27/2024 3:03:09 PM;Real-time file system protection;file;E:\Code\Virus\00ea585591b87304ac152936bbd2ab9b9c68583a76c5c3cc5da5646dd6614f96.exe;a variant of Win32/Kryptik.HWRX trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;F372B5BFB1BFFAEEFAABF18E40DE5B3C72F8794C;3/27/2024 3:02:17 PM
  7. 3/27/2024 3:03:11 PM;Real-time file system protection;file;E:\Code\Virus\Ljauypuypg.exe;a variant of MSIL/TrojanDownloader.Agent_AGen.BFI trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;993807041F53F2E254671687AE4F3444E8D313EF;3/27/2024 3:02:17 PM
  8. 3/27/2024 3:14:00 PM;Real-time file system protection;file;C:\Users\ASUS\AppData\Local\Temp\BNZ.6603c7241bc6a8\x.vbs;VBS/TrojanDownloader.Agent.AADP trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;8506F5EE6F4D65207E953CCB98EE7FB97AB55526;3/27/2024 3:13:41 PM
  9. 3/27/2024 3:18:02 PM;HTTP filter;file;https://bbs.kafan.cn/forum.php?mod=attachment&aid=MzM4NDcwNXw1MjFlOWQ4YXwxNzExNTIzODU5fDEzMDY5NTl8MjI2NzU2OA==;a variant of Win64/TrojanDownloader.Agent.ARC trojan;connection terminated;LAPTOP\Fadouse;Event occurred during an attempt to access the web by the application: C:\Program Files\Google\Chrome\Application\chrome.exe (29D461DAEB9214C9100A2CFA2FF59BE60F9452B9).;843C898EDE02ACCA58F0F731E3BD0BC524BCA184;
  10. 3/27/2024 4:08:06 PM;Real-time file system protection;file;E:\Code\Virus\#DarkGate\script.ahk;Win32/AHK.DT trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;C40B80BC4947D4AC52BC9C17D6D218B1FA9CD452;3/27/2024 4:07:41 PM
  11. 3/27/2024 4:08:10 PM;Real-time file system protection;file;E:\Code\Virus\#Vidar\sqlite.dll;a variant of Win64/TrojanDownloader.Rugmi.AU trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;D94C6D5A8933D7FA7BF5C4020031020FB0E41747;3/27/2024 4:07:41 PM
  12. 3/27/2024 4:08:12 PM;Real-time file system protection;file;E:\Code\Virus\Telecaster.exe;a variant of Win32/Injector.ETQY trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;857FA64483F911AAF2ED6238DEC1B46D7017A1EB;3/27/2024 4:07:41 PM
  13. 3/27/2024 4:08:13 PM;Real-time file system protection;file;E:\Code\Virus\Angle.exe;a variant of MSIL/Kryptik.ALGI trojan;cleaned by deleting;LAPTOP\Fadouse;Event occurred on a new file created by the application: C:\Program Files\Bandizip\Bandizip.exe (AB7C5C3728A1B132444C69A31DA61541F2BF4B25).;6C58DDFFEC036207692A8C65EBC844D3AB3AAFCF;3/27/2024 4:07:41 PM
复制代码

祸兮福所倚
头像被屏蔽
发表于 2024-3-27 17:53:58 | 显示全部楼层
解压1+扫描7=8X

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
swizzer
 楼主| 发表于 2024-3-27 18:21:04 | 显示全部楼层

按截图来看,扫描的7x里有3个都是同一文件吧
123456aaaafsdeg
发表于 2024-3-27 18:52:24 | 显示全部楼层
-----------------------------------
总检测数量: 6
总清除数量: 6
C:/Users/Administrator/Desktop/Mazoku\Amos.dmg --- 已检出
C:/Users/Administrator/Desktop/Mazoku\Angel.vbs --- 已检出
C:/Users/Administrator/Desktop/Mazoku\Anger.vbs --- 已检出
C:/Users/Administrator/Desktop/Mazoku\Angle.exe --- 已检出
C:/Users/Administrator/Desktop/Mazoku\Telecaster.exe --- 已检出
C:/Users/Administrator/Desktop/Mazoku\Telephonk.exe --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#DarkGate\AutoHotkey.exe --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#DarkGate\script.ahk --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#DarkGate\test.txt --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#Vidar\griddlecake.bmp --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#Vidar\podium.cfg --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#Vidar\Setup.exe --- 未检出
C:/Users/Administrator/Desktop/Mazoku\#Vidar\sqlite.dll --- 已检出
-----------------------------------


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
祸兮福所倚
头像被屏蔽
发表于 2024-3-27 19:24:40 | 显示全部楼层
swizzer 发表于 2024-3-27 18:21
按截图来看,扫描的7x里有3个都是同一文件吧

大佬您好,我小学文化,是什么文件真看不大懂,每次就是下载-解压-扫描-截图-发出来-删除样本和隔离区,如有操作不当,一定改正,谢谢指正
hhjjjjjj123
发表于 2024-3-27 21:30:24 | 显示全部楼层
卡巴扫描5x
tjsh
发表于 2024-3-27 21:47:57 | 显示全部楼层
Hezhong 3x

  1. ------------------------HEZHONG ANTIVIRUS SCAN LOG------------------------
  2. 开始于:  2024.3.27-21.46.56
  3. 病毒库版本:  528
  4. 软件版本:  6.29
  5. 引擎版本:  6.27.1100
  6. 记录病毒数量:  0
  7. ------------------------HEZHONG ANTIVIRUS SCAN LOG------------------------
  8.             
  9.             
  10. 扫描文件:D:\IDM\Compressed\Mazoku\Amos.dmg    ......
  11. 扫描文件:D:\IDM\Compressed\Mazoku\Angel.vbs    ......
  12. 扫描文件:D:\IDM\Compressed\Mazoku\Anger.vbs    ......
  13. 扫描文件:D:\IDM\Compressed\Mazoku\Angle.exe    ......-> 发现了:HEUR:Trojan.Generic
  14. 扫描文件:D:\IDM\Compressed\Mazoku\Telecaster.exe    ......
  15. 扫描文件:D:\IDM\Compressed\Mazoku\Telephonk.exe    ......-> 发现了:DL.Trojan.100.a
  16. 扫描文件:D:\IDM\Compressed\Mazoku\#DarkGate\AutoHotkey.exe    ......-> 发现了:DL.Trojan.99.a
  17. 扫描文件:D:\IDM\Compressed\Mazoku\#DarkGate\script.ahk    ......
  18. 扫描文件:D:\IDM\Compressed\Mazoku\#DarkGate\test.txt    ......
  19. 扫描文件:D:\IDM\Compressed\Mazoku\#Vidar\griddlecake.bmp    ......
  20. 扫描文件:D:\IDM\Compressed\Mazoku\#Vidar\podium.cfg    ......
  21. 扫描文件:D:\IDM\Compressed\Mazoku\#Vidar\Setup.exe    ......
  22. 扫描文件:D:\IDM\Compressed\Mazoku\#Vidar\sqlite.dll    ......
  23. 扫描已经完成。耗时10.69秒钟,扫描13文件,扫描3个检测。
复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-4 08:14 , Processed in 0.127294 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表