123
返回列表 发新帖
楼主: 微微的笑
收起左侧

[病毒样本] fakeapp1x

[复制链接]
微微的笑
 楼主| 发表于 昨天 15:55 | 显示全部楼层
驭龙 发表于 2026-1-7 15:42
我最近几天的白天都没在线,抱歉哈,我现在去看看

好的, 我刚刚扫描了还是miss , 可以测试, 地址在pm
驭龙
发表于 昨天 16:04 | 显示全部楼层
本帖最后由 驭龙 于 2026-1-7 16:18 编辑
微微的笑 发表于 2026-1-7 10:54
现在有空吗?我刚抓到了一个报evo的avast,fsp miss的
pm给你了

虽然报毒名变化了,但与EVO报法无关,是Avira本身有问题。

本体现在不杀,解压以后杀黑EXE


报毒名虽然是TR/Drop.Agent.692342,实际上是个APC云杀,也就是说APC确实是无法分析安装包内的文件,需要解压以后才能被云检测。

但根本问题是这个样本的格式应该是特殊处理了,Avira本地引擎根本无法识别格式和拆包,所以才扫描不杀。
[2026-01-07 15:46:26.253] [info] [OndemandScan] [thread id: 6820] Ondemand version: 1.0.2512.3314
[2026-01-07 15:46:26.254] [info] [OndemandScan] [thread id: 6820] Ondemand rdf version: 1.0.2512.3314
[2026-01-07 15:46:26.497] [info] [OndemandScan] [thread id: 6820] Scan of paths {C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897.msi} started.
[2026-01-07 15:46:30.154] [info] [BaseScan] [thread id: 5524] [LocalScanner] The file '\\?\C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897.msi' was checked with Local scanner. Flags: '{Error}{Incomplete}' Status: successful
扫描样本的时候根本没有彻底完成。


[2026-01-07 15:47:29.898] [info] [OndemandScan] [thread id: 6820] Scan of paths {C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\disk1\VC_radist.x64.exe} started.
[2026-01-07 15:47:29.920] [info] [Core] [thread id: 8524] [LocalScanner] Engine returned error 'Archive error, not the specified format' while processing '\\?\C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\disk1\VC_radist.x64.exe'
[2026-01-07 15:47:29.920] [warning] [BaseScan] [thread id: 8524] [LocalScanner] The file '\\?\C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\disk1\VC_radist.x64.exe' was checked with Local scanner. Flags: '{Incomplete}' Status: general processing error (unexpected EOF, unknown format, etc.)

扫描日志显示无法对黑样本的本体进行完整扫描,不支持该格式。


[2026-01-07 15:47:32.221] [info] [Core] [thread id: 8524] [ProtectionCloud] [apcsdk] Setting the proxy server ''
[2026-01-07 15:47:34.331] [info] [BaseScan] [thread id: 8524] [ProtectionCloud] The file '\\?\C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\disk1\VC_radist.x64.exe' was scanned with the Protection Cloud. SHA256: '69234213aede53b678cabf68395f7301ac5fb3813f5b99bca8eed4430b406b53' Requestor: 'OnDemandScan' Flags: '{Detected}' Status: successful
[2026-01-07 15:47:34.331] [info] [BaseScan] [thread id: 8524] [ProtectionCloud] Detection by Protection Cloud: '{TR/Drop.Agent.692342}' File: '\\?\C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\disk1\VC_radist.x64.exe' SHA256:'69234213aede53b678cabf68395f7301ac5fb3813f5b99bca8eed4430b406b53'

TR/Drop.Agent.692342,确实是云报法,只不过已经被分类,而不是最初检测结果。


超级有趣的是更改黑EXE的MD5以后,Avira哑火了,果然是云杀,改哈希就废了。
[2026-01-07 16:13:22.237] [info] [OndemandScan] [thread id: 6820] Ondemand version: 1.0.2512.3314
[2026-01-07 16:13:22.237] [info] [OndemandScan] [thread id: 6820] Ondemand rdf version: 1.0.2512.3314
[2026-01-07 16:13:22.400] [info] [OndemandScan] [thread id: 6820] Scan of paths {C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\VC_radist.x64.exe} started.
[2026-01-07 16:13:26.402] [info] [BaseScan] [thread id: 820] [ProtectionCloud] The file '\\?\C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\VC_radist.x64.exe' was scanned with the Protection Cloud. SHA256: '38ae8ed70d238bd087124599d2903c8aba81593617810809aad20e007af252e7' Requestor: 'OnDemandScan' Flags: '' Status: successful
[2026-01-07 16:13:26.455] [info] [EndpointProtection] [thread id: 820] [OnDemandSummary] Total amount of files to be scanned: 1
[2026-01-07 16:13:26.455] [info] [EndpointProtection] [thread id: 820] [OnDemandSummary] Scanned files: 1
[2026-01-07 16:13:26.455] [info] [EndpointProtection] [thread id: 820] [OnDemandSummary] Detected files: 0
[2026-01-07 16:13:26.455] [info] [EndpointProtection] [thread id: 820] [OnDemandSummary] Scan end status: 2
[2026-01-07 16:13:26.456] [info] [OndemandScan] [thread id: 820] Scan of paths {C:\Users\ltqi\Downloads\ChromeSetupx64B-4897\ChromeSetupx64B-4897\VC_radist.x64.exe} finished in 4055 milliseconds.
[2026-01-07 16:13:26.456] [info] [OndemandScan] [thread id: 820] Total amount of files to be scanned: 1. Scanned files: 1. Clean files: 1. Excluded files: 0. Detected files: 0. Repaired files: 0. Successful remediation: 0. Failed remediation: 0. Error scan files: 0
[2026-01-07 16:13:26.461] [info] [BaseScan] [thread id: 820] [ProtectionCloud] Cloud scan cancelled.

这日志是几个意思?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +3 收起 理由
微微的笑 + 3 感谢解答: )

查看全部评分

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-1-8 22:22 , Processed in 0.076669 second(s), 4 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表