楼主: QVM360
收起左侧

[病毒样本] 【开放测试】卡饭病毒样本包 第138期

  [复制链接]
yaokai815
发表于 2024-7-5 18:09:42 | 显示全部楼层
卡巴kill all  瑞星实际kill 21x

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +2 收起 理由
dongwenqi + 2 版区有你更精彩: )

查看全部评分

DisaPDB
发表于 2024-7-5 18:18:53 | 显示全部楼层
本帖最后由 DisaPDB 于 2024-7-5 18:28 编辑

火绒6 扫描17x
  1. 病毒库时间:2024-07-02 18:12
  2. 开始时间:2024-07-05 18:25
  3. 总计用时:00:00:03
  4. 扫描对象:102
  5. 扫描文件:27
  6. 发现风险:17
  7. 已处理风险:17
  8. 病毒详情:
  9. 风险路径:C:\Users\Administrator\Desktop\1\106e5d2356c57555ce0aa1c55daae0df8615344336b11e4848663581fd55d73d.js, 病毒名:SVM:TrojanDownloader/JS.MalBehav.gen!B, 病毒ID:73c63ed81b618b07, 处理结果:已处理,删除文件
  10. 风险路径:C:\Users\Administrator\Desktop\1\30225014a390133cd81a5896e070c88313e33c21c6cb40d9fec1600bf9f70f4f.exe, 病毒名:TrojanSpy/MSIL.AgentTesla.mq, 病毒ID:e6db7a4b5c5a5e0b, 处理结果:已处理,删除文件
  11. 风险路径:C:\Users\Administrator\Desktop\1\6eedc70dbeeb29b5f978d19bde0a32b02c54b9c9699c6a3a97e6f20de816c86d.exe, 病毒名:TrojanSpy/MSIL.AgentTesla.mq, 病毒ID:e6db7a4b5c5a5e0b, 处理结果:已处理,删除文件
  12. 风险路径:C:\Users\Administrator\Desktop\1\6f3d9c1d62a29f4a030a0d2bded9600599d301784f5f0b6edfc96fc3b2b404fb.exe >> [NSIS].nsi, 病毒名:HEUR:Trojan/Injector.aa, 病毒ID:f31218ddeade9504, 处理结果:已处理,删除文件
  13. 风险路径:C:\Users\Administrator\Desktop\1\521e56cecd5dd355d23dcf9085f29499dc4580835a69222a13214873971e2dce.xlsx, 病毒名:Exploit/CVE-2017-11882.gen, 病毒ID:21f770a61cebbcbb, 处理结果:已处理,删除文件
  14. 风险路径:C:\Users\Administrator\Desktop\1\74d9431b9ca92014c5d687bc0515de79c81917c3bba3896804d4e6c912d5b024.exe, 病毒名:TrojanSpy/MSIL.AgentTesla.mq, 病毒ID:e6db7a4b5c5a5e0b, 处理结果:已处理,删除文件
  15. 风险路径:C:\Users\Administrator\Desktop\1\97fa3b7bb71b37e59fe1ff289123ca79d25ca799677cc21e338813604d42c858.exe, 病毒名:Trojan/MSIL.Agent.ii, 病毒ID:b072426cb483f718, 处理结果:已处理,删除文件
  16. 风险路径:C:\Users\Administrator\Desktop\1\0aca1a9171ebd9efa63abdf7e85608d23c59cdeef487ce57c0f7883aaae2c308.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:b27d4294cde6a1ec, 处理结果:已处理,删除文件
  17. 风险路径:C:\Users\Administrator\Desktop\1\83e35b5a0251658e0956608fa93f0de64e8d5fe9f9297a1b7b389d4699d79128.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:b27d4294cde6a1ec, 处理结果:已处理,删除文件
  18. 风险路径:C:\Users\Administrator\Desktop\1\98a9a4d2141be1d0bd15beec5785de049f8c6c68c0aa4ab79947690c338c5006.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:b27d4294cde6a1ec, 处理结果:已处理,删除文件
  19. 风险路径:C:\Users\Administrator\Desktop\1\ac1fa54c26a22f25b1d78ab15315f48339eca43645162de8ad9c77d83a7c7f0a.exe, 病毒名:Backdoor/Quasar.a, 病毒ID:90a1718ce39c00e5, 处理结果:已处理,删除文件
  20. 风险路径:C:\Users\Administrator\Desktop\1\1e4b1ea0fe7c16253169b76c22265b085df9bcca509eb39b8597b54bf53a4920.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:b27d4294cde6a1ec, 处理结果:已处理,删除文件
  21. 风险路径:C:\Users\Administrator\Desktop\1\d8ba98fe2f2715873622ec5d987ac06da81077ad593d045b925007680d625025.xlsx, 病毒名:Exploit/CVE-2017-11882.gen, 病毒ID:21f770a61cebbcbb, 处理结果:已处理,删除文件
  22. 风险路径:C:\Users\Administrator\Desktop\1\e4fcf1f6b71043e7c7c32f6954a0a1972696fa1bb9b6543ead14e85626890a11.exe, 病毒名:Backdoor/Quasar.a, 病毒ID:90a1718ce39c00e5, 处理结果:已处理,删除文件
  23. 风险路径:C:\Users\Administrator\Desktop\1\fbd4bb68ae72c7715dcf61c915bdbc48d4d60eb9cd6bae30d74aad3e796663c7.rtf, 病毒名:Exploit/CVE-2018-0798.gen, 病毒ID:cd1a0f4eabeb44ad, 处理结果:已处理,删除文件
  24. 风险路径:C:\Users\Administrator\Desktop\1\d1f4bcbfb1a85bced6286c125412ebba178b093cf08db62ea728a90368f8d4f7.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:b27d4294cde6a1ec, 处理结果:已处理,删除文件
  25. 风险路径:C:\Users\Administrator\Desktop\1\c1f95eb636c1332edbca55f6fd3eb3730ebbe7b95295330984bc5b566c24967f.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:b27d4294cde6a1ec, 处理结果:已处理,删除文件
复制代码
开ADV 再杀3x 合计20/28
  1. 病毒详情:
  2. 风险路径:C:\Users\Administrator\Desktop\1\d23bfe6129eb1b44c79612e9743c286ee15d5024e61796662c3fb86cf0d27141.exe, 病毒名:ADV:TrojanDownloader/MSIL.Generic!meteor, 病毒ID:476941e6840b7d84, 处理结果:已处理,删除文件
  3. 风险路径:C:\Users\Administrator\Desktop\1\ee16dfcd62cdbb1e8da2ff16272f9a75395d1587dbd2ac1417a37fb17c36d56d.exe, 病毒名:ADV:TrojanDownloader/MSIL.Generic!meteor, 病毒ID:476941e6840b7d84, 处理结果:已处理,删除文件
  4. 风险路径:C:\Users\Administrator\Desktop\1\77ccc61481c9fa009dfb6af2f6293b604312d440df4338e757ad2df844d10e0b.exe, 病毒名:ADV:TrojanSpy/MSIL.Stealer!meteor, 病毒ID:4a7ffd6cc7dd1ce4, 处理结果:已处理,删除文件
复制代码

驭龙
发表于 2024-7-5 18:27:06 | 显示全部楼层
本帖最后由 驭龙 于 2024-7-5 18:39 编辑

ESET报到扫描杀23个,外加ELG一个


2024/7/5 18:34:58;
ESET LiveGuard;
file;D:\virus\27x (2024-07-05)\1\7d84dcf2dd227761c0eb67814538c2d2eb6de133e7ad1977e6756f76742c9084.js;
ESET LiveGuard trojan;deleted;
511998D50A6780C570DD0C920BA1DFEAE2D27A43;
2024/7/5 15:33:53



Version of detection engine: 29507P (20240705)
Date: 2024/7/5  Time: 18:29:53
Scanned disks, folders and files: D:\virus\27x (2024-07-05)
D:\virus\27x (2024-07-05)\1\ac1fa54c26a22f25b1d78ab15315f48339eca43645162de8ad9c77d83a7c7f0a.exe - a variant of MSIL/Agent.AAZ trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\0aca1a9171ebd9efa63abdf7e85608d23c59cdeef487ce57c0f7883aaae2c308.exe » AUTOIT » script.bin - a variant of Win32/Injector.Autoit.GDC trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\106e5d2356c57555ce0aa1c55daae0df8615344336b11e4848663581fd55d73d.js - JS/Kryptik.CTH trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\15f84dc497c0b5c757f8fcc090e88adbfd25d506c267bd8c76f92824856931c4.exe - a variant of MSIL/Kryptik.ALWQ trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\c1f95eb636c1332edbca55f6fd3eb3730ebbe7b95295330984bc5b566c24967f.exe - a variant of Generik.CCPXUUW trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\1e4b1ea0fe7c16253169b76c22265b085df9bcca509eb39b8597b54bf53a4920.exe - a variant of Win32/GenCBL.DEI trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\30225014a390133cd81a5896e070c88313e33c21c6cb40d9fec1600bf9f70f4f.exe - a variant of MSIL/Kryptik.ALWS trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\521e56cecd5dd355d23dcf9085f29499dc4580835a69222a13214873971e2dce.xlsx » ZIP » xl/embeddings/RdohipV4U.nTh - probably a variant of Win32/Exploit.CVE-2017-11882.C trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\6eedc70dbeeb29b5f978d19bde0a32b02c54b9c9699c6a3a97e6f20de816c86d.exe - a variant of MSIL/Kryptik.ALWP trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\d1f4bcbfb1a85bced6286c125412ebba178b093cf08db62ea728a90368f8d4f7.exe » AUTOIT » script.bin - a variant of Win32/Injector.Autoit.GDC trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\6f3d9c1d62a29f4a030a0d2bded9600599d301784f5f0b6edfc96fc3b2b404fb.exe » NSIS » Script.nsi - NSIS/Injector.BXN trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\d23bfe6129eb1b44c79612e9743c286ee15d5024e61796662c3fb86cf0d27141.exe - MSIL/TrojanDownloader.Agent.QXG trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\d8ba98fe2f2715873622ec5d987ac06da81077ad593d045b925007680d625025.xlsx » ZIP » xl/embeddings/t4rjm.f9Fv - probably a variant of Win32/Exploit.CVE-2017-11882.C trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\74d9431b9ca92014c5d687bc0515de79c81917c3bba3896804d4e6c912d5b024.exe - a variant of MSIL/Kryptik.ALWS trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\e4fcf1f6b71043e7c7c32f6954a0a1972696fa1bb9b6543ead14e85626890a11.exe - a variant of MSIL/Agent.AAZ trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\77ccc61481c9fa009dfb6af2f6293b604312d440df4338e757ad2df844d10e0b.exe - a variant of MSIL/Kryptik.ALWS trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\ee16dfcd62cdbb1e8da2ff16272f9a75395d1587dbd2ac1417a37fb17c36d56d.exe - a variant of MSIL/TrojanDownloader.Agent.QSR trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\fbd4bb68ae72c7715dcf61c915bdbc48d4d60eb9cd6bae30d74aad3e796663c7.rtf - Win32/Exploit.CVE-2017-11882.BOR trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\83e35b5a0251658e0956608fa93f0de64e8d5fe9f9297a1b7b389d4699d79128.exe » AUTOIT » script.bin - a variant of Win32/Injector.Autoit.GCM trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\97fa3b7bb71b37e59fe1ff289123ca79d25ca799677cc21e338813604d42c858.exe - a variant of MSIL/Kryptik.ALTA trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\98a9a4d2141be1d0bd15beec5785de049f8c6c68c0aa4ab79947690c338c5006.exe » AUTOIT » script.bin - a variant of Win32/Injector.Autoit.GCP trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\a1b94e324beb19da2cabb254652df7c75dfcdad3c099012bb10e06448198d204.vbs - VBS/Agent.SCS trojan - cleaned by deleting [1]
D:\virus\27x (2024-07-05)\1\a71d5cbad432ffbddff485ec8fcfb60f5eecac7e59aaf6d4d1e92052e2a3c40b.exe - a variant of MSIL/Agent.BYB trojan - cleaned by deleting [1]
Number of scanned objects: 82
Number of detections: 23
Number of cleaned objects: 23
Time of completion: 18:30:47  Total scanning time: 54 sec (00:00:54)
Notes:
[1] Object has been deleted as it only contained the virus body.


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
真小读者
发表于 2024-7-5 18:28:52 | 显示全部楼层
本帖最后由 真小读者 于 2024-7-5 18:34 编辑

金山安全终端 22X


剩余



  1. 扫描时间:[2024-07-05 18:29:41]
  2. 扫描用时:[00:00:08]
  3. 扫描类型:自定义查杀
  4. 扫描文件总数:57
  5. 扫描速度:7文件/秒
  6. 发现威胁:22个
  7. 清除威胁:22个
  8. =============================================
  9. [2024-07-05 18:29:41]
  10. 威胁:D:\下载\27x (2024-07-05)\1\0aca1a9171ebd9efa63abdf7e85608d23c59cdeef487ce57c0f7883aaae2c308.exe
  11. 类型:Win32.HeurC.KVM007.a.(kcloud)
  12. 处理方式:已删除

  13. [2024-07-05 18:29:41]
  14. 威胁:D:\下载\27x (2024-07-05)\1\3722989fb37d2b30e4e04404660ee6757fe8dc872540ddf57e5c04b8f6307315.xls
  15. 类型:HEUR/CVE-2017-0199
  16. 处理方式:已删除

  17. [2024-07-05 18:29:41]
  18. 威胁:D:\下载\27x (2024-07-05)\1\521e56cecd5dd355d23dcf9085f29499dc4580835a69222a13214873971e2dce.xlsx
  19. 类型:EXP/CVE-2017-11882.Gen
  20. 处理方式:已修复

  21. [2024-07-05 18:29:41]
  22. 威胁:D:\下载\27x (2024-07-05)\1\b407cd499a77383c21bc590bca7ac0e44ed224aa39ac73ea0e904170891b3684.xls
  23. 类型:HEUR/CVE-2017-0199
  24. 处理方式:已删除

  25. [2024-07-05 18:29:41]
  26. 威胁:D:\下载\27x (2024-07-05)\1\d8ba98fe2f2715873622ec5d987ac06da81077ad593d045b925007680d625025.xlsx
  27. 类型:EXP/CVE-2017-11882.Gen
  28. 处理方式:已修复

  29. [2024-07-05 18:29:41]
  30. 威胁:D:\下载\27x (2024-07-05)\1\15f84dc497c0b5c757f8fcc090e88adbfd25d506c267bd8c76f92824856931c4.exe
  31. 类型:MSIL.Trojan.Crypt.gen.(kcloud)
  32. 处理方式:已删除

  33. [2024-07-05 18:29:41]
  34. 威胁:D:\下载\27x (2024-07-05)\1\1e4b1ea0fe7c16253169b76c22265b085df9bcca509eb39b8597b54bf53a4920.exe
  35. 类型:Win32.Trojan.Strab.pef.(kcloud)
  36. 处理方式:已删除

  37. [2024-07-05 18:29:41]
  38. 威胁:D:\下载\27x (2024-07-05)\1\30225014a390133cd81a5896e070c88313e33c21c6cb40d9fec1600bf9f70f4f.exe
  39. 类型:MSIL.Trojan.Crypt.gen.(kcloud)
  40. 处理方式:已删除

  41. [2024-07-05 18:29:41]
  42. 威胁:D:\下载\27x (2024-07-05)\1\6eedc70dbeeb29b5f978d19bde0a32b02c54b9c9699c6a3a97e6f20de816c86d.exe
  43. 类型:MSIL.Trojan-Spy.Noon.gen.(kcloud)
  44. 处理方式:已删除

  45. [2024-07-05 18:29:41]
  46. 威胁:D:\下载\27x (2024-07-05)\1\745e1721c0c15e4284e29a83b11de4baaacec818e4ddc15dbb7c90fff6fbe130.exe
  47. 类型:Win32.Troj.Unknown.a.(kcloud)
  48. 处理方式:已删除

  49. [2024-07-05 18:29:41]
  50. 威胁:D:\下载\27x (2024-07-05)\1\74d9431b9ca92014c5d687bc0515de79c81917c3bba3896804d4e6c912d5b024.exe
  51. 类型:MSIL.Trojan.Crypt.gen.(kcloud)
  52. 处理方式:已删除

  53. [2024-07-05 18:29:41]
  54. 威胁:D:\下载\27x (2024-07-05)\1\77ccc61481c9fa009dfb6af2f6293b604312d440df4338e757ad2df844d10e0b.exe
  55. 类型:MSIL.Trojan-Spy.Stealer.gen.(kcloud)
  56. 处理方式:已删除

  57. [2024-07-05 18:29:41]
  58. 威胁:D:\下载\27x (2024-07-05)\1\83e35b5a0251658e0956608fa93f0de64e8d5fe9f9297a1b7b389d4699d79128.exe
  59. 类型:Win32.HeurC.KVM007.a.(kcloud)
  60. 处理方式:已删除

  61. [2024-07-05 18:29:41]
  62. 威胁:D:\下载\27x (2024-07-05)\1\97fa3b7bb71b37e59fe1ff289123ca79d25ca799677cc21e338813604d42c858.exe
  63. 类型:MSIL.Trojan.Crypt.gen.(kcloud)
  64. 处理方式:已删除

  65. [2024-07-05 18:29:41]
  66. 威胁:D:\下载\27x (2024-07-05)\1\98a9a4d2141be1d0bd15beec5785de049f8c6c68c0aa4ab79947690c338c5006.exe
  67. 类型:Win32.HeurC.KVM007.a.(kcloud)
  68. 处理方式:已删除

  69. [2024-07-05 18:29:41]
  70. 威胁:D:\下载\27x (2024-07-05)\1\a71d5cbad432ffbddff485ec8fcfb60f5eecac7e59aaf6d4d1e92052e2a3c40b.exe
  71. 类型:MSIL.Backdoor.Quasar.gen.(kcloud)
  72. 处理方式:已删除

  73. [2024-07-05 18:29:41]
  74. 威胁:D:\下载\27x (2024-07-05)\1\ac1fa54c26a22f25b1d78ab15315f48339eca43645162de8ad9c77d83a7c7f0a.exe
  75. 类型:MSIL.Backdoor.Quasar.gen.(kcloud)
  76. 处理方式:已删除

  77. [2024-07-05 18:29:41]
  78. 威胁:D:\下载\27x (2024-07-05)\1\c1f95eb636c1332edbca55f6fd3eb3730ebbe7b95295330984bc5b566c24967f.exe
  79. 类型:Win32.HeurC.KVM007.a.(kcloud)
  80. 处理方式:已删除

  81. [2024-07-05 18:29:41]
  82. 威胁:D:\下载\27x (2024-07-05)\1\d1f4bcbfb1a85bced6286c125412ebba178b093cf08db62ea728a90368f8d4f7.exe
  83. 类型:Win32.HeurC.KVM007.a.(kcloud)
  84. 处理方式:已删除

  85. [2024-07-05 18:29:41]
  86. 威胁:D:\下载\27x (2024-07-05)\1\d23bfe6129eb1b44c79612e9743c286ee15d5024e61796662c3fb86cf0d27141.exe
  87. 类型:MSIL.Trojan-PSW.Azorult.gen.(kcloud)
  88. 处理方式:已删除

  89. [2024-07-05 18:29:41]
  90. 威胁:D:\下载\27x (2024-07-05)\1\e4fcf1f6b71043e7c7c32f6954a0a1972696fa1bb9b6543ead14e85626890a11.exe
  91. 类型:MSIL.Backdoor.Quasar.gen.(kcloud)
  92. 处理方式:已删除

  93. [2024-07-05 18:29:41]
  94. 威胁:D:\下载\27x (2024-07-05)\1\ee16dfcd62cdbb1e8da2ff16272f9a75395d1587dbd2ac1417a37fb17c36d56d.exe
  95. 类型:MSIL.Trojan-PSW.Agensla.gen.(kcloud)
  96. 处理方式:已删除

复制代码


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
孤勇者
发表于 2024-7-5 19:05:02 | 显示全部楼层
本帖最后由 孤勇者 于 2024-7-5 19:09 编辑

卡巴斯基kill all

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
chyraymond
头像被屏蔽
发表于 2024-7-5 19:06:02 | 显示全部楼层
提示: 该帖被管理员或版主屏蔽
BitterLotus
发表于 2024-7-5 19:23:44 | 显示全部楼层
本帖最后由 BitterLotus 于 2024-7-5 19:38 编辑

di 解压 23x + 双击 3x

剩余745e1721c0c15e4284e29a83b11de4baaacec818e4ddc15dbb7c90fff6fbe130.exe

keen-qv 该用户已被删除
发表于 2024-7-5 19:27:07 | 显示全部楼层

双击测试很给力,辛苦分享
swizzer
发表于 2024-7-5 19:45:42 | 显示全部楼层
本帖最后由 swizzer 于 2024-7-5 20:01 编辑

娱个乐

智量 17x

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
StarlitFuture
发表于 2024-7-5 19:46:03 | 显示全部楼层
本帖最后由 StarlitFuture 于 2024-7-5 20:06 编辑

COMODO 2025 KILL 8,剩余入沙

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 11:35 , Processed in 0.089954 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表