查看: 3828|回复: 23
收起左侧

[病毒样本] 继续被雷倒

[复制链接]
The EQs
发表于 2008-9-30 11:56:35 | 显示全部楼层 |阅读模式
Fortinet
Thank you for submitting sample to Fortinet.
This malformed GIF sample wants to escape the upload file checking process when being uploaded to the php web server (such as CVE-2006-6338). Attacker just uploads it as a image file, and the server will accept it. Then, the attacker could execute it by multi vulnerabilities of the PHP applications. Such as, Rename and Execute it(cve-2006-7070) or Execute it directly (CVE-2008-3117).
The sample you submitted will be detected as DATA/PHPEmb.A!exploit in next update.

Regards,
Kyle

卡巴中国
尊敬的用户,您好!





您上报的样本文件没有问题。非常感谢您将病毒样本提供给我们,有了您的支持我们会做的更好


Kaspersky
Hello,

prc.gif_ - Trojan.PHP.Agent.a

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Vitaly Butuzov
Virus analyst, Kaspersky Lab.


Sophos

Hi Johnson

thank you for your email. The file prc.gif that you sent to us foranalysis is a Trojan, Troj/Phoison-A, further details of which can befound on our web site at

http://www.sophos.com/security/analyses/viruses-and-spyware/trojphoisona.html

and an IDE file that will allow Sophos to detect this is now available on the Databank.


ESET

As such, the file is not malicious -- but the analysis by Fortinet is
correct. Indeed, the file attempts to look like a GIF, most likely as an
attempt to fool AV scanners or filetype-recognition tools. If it is fed
to the PHP interpreter, it displays a few interesting pieces of
information about the server it's running on. That's all, though -- so
I'd classify it as a potentially unsafe application.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
无尽藏海
发表于 2008-9-30 11:58:15 | 显示全部楼层
样本还是发给俄罗斯的好……

诺顿扫描也飞了
嘁。不稀罕~
发表于 2008-9-30 12:00:29 | 显示全部楼层

下面你将继续被雷。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
htyhzd 该用户已被删除
发表于 2008-9-30 12:04:39 | 显示全部楼层

F-secure流量扫描删除

kingmuro
头像被屏蔽
发表于 2008-9-30 12:25:39 | 显示全部楼层
驱逐舰过
Palkia
发表于 2008-9-30 12:38:59 | 显示全部楼层
金山0
nvhaichina
发表于 2008-9-30 12:44:02 | 显示全部楼层
费尔杀了,呵呵
kkgh
发表于 2008-9-30 12:58:42 | 显示全部楼层
费尔   Trojan.PHP.Agent.a.cicm
woai_jolin
发表于 2008-9-30 13:03:48 | 显示全部楼层
手动扫描 已完成并且没有要处理的项目。

结果
已扫描的项目数: 1
检测到的项目数: 0
已修复的项目数: 0
已隔离的项目数: 0
已删除的项目数: 0
尤金卡巴斯基
发表于 2008-9-30 13:32:47 | 显示全部楼层
2008/9/30 13:31:51        已清除        木马程序 Trojan.PHP.Agent.a        G:\Temp\Virus\prc.zip/prc/prc.gif
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-10 10:25 , Processed in 0.373109 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表