查看: 2904|回复: 11
收起左侧

[求助] 用过threatexpert的来评价下

[复制链接]
jefffire
头像被屏蔽
发表于 2008-8-26 22:25:59 | 显示全部楼层 |阅读模式
theartexpert我用了一下,发现它对病毒的分析比较到位可以和手工分析媲美了。它运行原理有谁清楚啊??
hum
发表于 2008-8-26 22:34:28 | 显示全部楼层
我估计
上传样本后会被ThreatExpert服务器在虚拟环境下运行(使用沙盘,虚拟机等)
并且监视他的一些动作
然后写出报告发给你,上传的样本加入PC TOOLS杀软的病毒库

[ 本帖最后由 hum 于 2008-8-26 22:37 编辑 ]
yager 该用户已被删除
发表于 2008-8-26 22:36:42 | 显示全部楼层
我怎么只看到什么MD5

文件名什么的
jefffire
头像被屏蔽
 楼主| 发表于 2008-8-26 22:36:45 | 显示全部楼层
就一沙盘?我还以为它用了VMware之类的虚拟机再加上入侵检测
hum
发表于 2008-8-26 22:37:43 | 显示全部楼层

回复 4楼 jefffire 的帖子

就是在虚拟环境运行。
不一定是沙盘
jefffire
头像被屏蔽
 楼主| 发表于 2008-8-26 22:47:18 | 显示全部楼层
不可能只看到MD5啊,它有详细报告的
yager 该用户已被删除
发表于 2008-8-26 23:04:46 | 显示全部楼层
Submission Summary:
Submission details:
Submission received: 25 August 2008, 10:17:25
Processing time: 4 min 47 sec
Submitted sample:
File MD5: 0x75393CC2B2EA6AD931DACB95338DC1F9
Filesize: 264,084 bytes


Technical Details:


File System Modifications

The following file was created in the system:
# Filename(s) File Size File MD5
1 [file and pathname of the sample #1]  264,084 bytes 0x75393CC2B2EA6AD931DACB95338DC1F9
嘁。不稀罕~
发表于 2008-8-26 23:07:25 | 显示全部楼层

回复 3楼 yager 的帖子

因为你上传的样本没有威胁。。。或者无法执行。。。当然无法给你更详细的信息。。。
yager 该用户已被删除
发表于 2008-8-26 23:44:44 | 显示全部楼层
What's been found        Severity Level
Contains characteristics of an identified security risk.       


Technical Details:


        Possible Security Risk

    * Attention! The following threat category was identified:

Threat Category        Description
        A malicious backdoor trojan that runs in the background and allows remote access to the compromised system


        File System Modifications

    * The following file was created in the system:

#        Filename(s)        File Size        File MD5        Alias
1         [file and pathname of the sample #1]         211,456 bytes         0xA8F263E0C2CDC105B6736F62720BB562         Backdoor.Win32.Delf.jpi [Kaspersky Lab]
hum
发表于 2008-8-27 08:36:49 | 显示全部楼层
Possible Security Risk

Attention! The following threat category was identified:
Threat Category        Description
        A malicious backdoor trojan that runs in the background and allows remote access to the compromised system


        File System Modifications

The following file was created in the system:
#        Filename(s)        File Size        File MD5        Alias
1        [file and pathname of the sample #1]
%Windir%\XP professional.exe         716,288 bytes        0x93D0CA4131148FCF2F999A9E57DB4819        Backdoor.Win32.Hupigon.btrm [Kaspersky Lab]
Mal/Behav-058 [Sophos]



        Memory Modifications

There were new processes created in the system:
Process Name        Process Filename        Main Module Size
xp professional.exe        %Windir%\xp professional.exe        745,472 bytes
[filename of the sample #1]        [file and pathname of the sample #1]        745,472 bytes

There was a new service created in the system:
Service Name        Display Name        Status        Service Filename
XP professional        XP professional        "Stopped"        %Windir%\XP professional.exe



        Registry Modifications

The following Registry Keys were created:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XP professional
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XP professional\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\XP professional
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\XP professional\Security
The newly created Registry Values are:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XP professional\Security]
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XP professional]
Type = 0x00000110
Start = 0x00000002
ErrorControl = 0x00000000
ImagePath = "%Windir%\XP professional.exe"
DisplayName = "XP professional"
ObjectName = "LocalSystem"
Description = "XP professional����"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\XP professional\Security]
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\XP professional]
Type = 0x00000110
Start = 0x00000002
ErrorControl = 0x00000000
ImagePath = "%Windir%\XP professional.exe"
DisplayName = "XP professional"
ObjectName = "LocalSystem"
Description = "XP professional����"
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-13 17:37 , Processed in 0.134911 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表