查看: 3301|回复: 10
收起左侧

[已鉴定] PCSL 可疑恶意网站每日分析 20081014

 关闭 [复制链接]
lanvin
发表于 2008-10-14 21:24:10 | 显示全部楼层 |阅读模式
hxxp://www.alpha-accz.ws/image.jpg.exe
hxxp://www.alpha-accz.ws/ri0t.exe
hxxp://virus-labs2009.com/distrib/1/virlab_install.exe
hxxp://125.91.10.231/js/suen.exe
hxxp://download.a-a-v-2008.com:8080/AAVSetup.exe
hxxp://www.lastwmpupdate.com/download.php?id=1684
hxxp://www.lastwmpupdate.com/download.php?id=417
hxxp://www.lastwmpupdate.com/download.php?id=1161
hxxp://www.lastwmpupdate.com/download.php?id=1640
hxxp://www.lastwmpupdate.com/download.php?id=1464

评分

参与人数 1人气 +1 收起 理由
电影结束了 + 1 给蕃茄老大加个分。。。辛苦了~

查看全部评分

wangjay1980
发表于 2008-10-14 21:28:52 | 显示全部楼层
HXXP真不爽
qigang
发表于 2008-10-14 21:36:19 | 显示全部楼层
今天几个体积较大。
wangjay1980
发表于 2008-10-14 21:37:17 | 显示全部楼层
剩余TO KL
zjsxsycj
发表于 2008-10-14 21:43:27 | 显示全部楼层
点击下载样本
virus

. sshot-5.jpg

[ 本帖最后由 zjsxsycj 于 2008-10-14 21:54 编辑 ]

评分

参与人数 1经验 +10 收起 理由
lanvin + 10 版区有你更精彩: )

查看全部评分

Palkia
发表于 2008-10-14 21:49:01 | 显示全部楼层
病毒        2008-10-14  21:48:10        病毒在文件C:\Documents and Settings\Administrator\桌面\suen.exe.td中        Win32.Parite.d.1436        处理成功(操作:删除)
电影结束了
发表于 2008-10-14 21:50:08 | 显示全部楼层
"Infections"
"File";"Infection";"Result"
"F:\新建文件夹 (2)\image.jpg.exe";"Trojan horse BackDoor.Ircbot.FQH";"Infected"
"F:\新建文件夹 (2)\ri0t.exe";"Trojan horse BackDoor.Ircbot.FQH";"Infected"
"F:\新建文件夹 (2)\suen.exe";"Trojan horse Flooder.H";"Infected"
"F:\新建文件夹 (2)\virlab_install.exe";"Trojan horse Generic_c.YOW";"Infected"
"F:\新建文件夹 (2)\virlab_install.exe:\$JF\VirRL2009.exe";"Trojan horse Generic_c.YOW";"Infected"
电影结束了
发表于 2008-10-14 21:51:28 | 显示全部楼层
hxxp://www.alpha-accz.ws/image.jpg.exe
hxxp://www.alpha-accz.ws/ri0t.exe

MD5 相同~

评分

参与人数 1人气 +1 收起 理由
lanvin + 1 回礼了

查看全部评分

wangjay1980
发表于 2008-10-14 22:00:28 | 显示全部楼层
Dear Sir Wangjay!

setup(1).exe_, setup(2).exe_, setup(3).exe_, setup(4).exe_, setup.exe_ - Trojan-Downloader.Win32.Zlob.rtg

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

This sample very good!

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

--
Best regards, Andrey Ladikov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
Kitman
发表于 2008-10-14 22:20:44 | 显示全部楼层
Warning: The content of this website is part of a unwanted category: Malware

Requested URL:         http://virus-labs2009.com/distrib/1/virlab_install.exe


Generated by AntiVir WebGuard 8.0.15.0, WCDB 7.0.1014.1230
Warning: The content of this website is part of a unwanted category: Malware

Requested URL:         http://download.a-a-v-2008.com:8080/AAVSetup.exe


Generated by AntiVir WebGuard 8.0.15.0, WCDB 7.0.1014.1230


Begin scan in 'C:\Users\TOSHIBA\Desktop\setup.exe'
Begin scan in 'C:\Users\TOSHIBA\Desktop\suen.exe'
C:\Users\TOSHIBA\Desktop\suen.exe
    [DETECTION] Contains code of the W32/Parite Windows virus
    [NOTE]      A backup was created as '4959a979.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
Begin scan in 'C:\Users\TOSHIBA\Desktop\image.jpg.exe'
C:\Users\TOSHIBA\Desktop\image.jpg.exe
    [DETECTION] Contains recognition pattern of the WORM/Rbot.210944 worm
    [NOTE]      A backup was created as '4955a971.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
Begin scan in 'C:\Users\TOSHIBA\Desktop\ri0t.exe'
C:\Users\TOSHIBA\Desktop\ri0t.exe
    [DETECTION] Contains recognition pattern of the WORM/Rbot.210944 worm
    [NOTE]      A backup was created as '4924a96d.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!

suen.part1.rar

488.28 KB, 下载次数: 29

suen.part2.rar

168.92 KB, 下载次数: 29

image.jpg.rar

132.89 KB, 下载次数: 29

setup.rar

10.98 KB, 下载次数: 40

评分

参与人数 1经验 +10 收起 理由
lanvin + 10 感谢支持,欢迎常来: )

查看全部评分

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-15 13:47 , Processed in 0.131997 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表