查看: 4812|回复: 29
收起左侧

[衍生物系列之1] 一个木马+8个衍生物 你能杀多少

[复制链接]
xpn282
发表于 2007-4-26 01:35:12 | 显示全部楼层 |阅读模式
在沙盘运行一个木马,,它共生成8个东西(3个EXE,3个TMP,3个DLL),,你能杀多少啊??

还有就是木马样本会联网哦...没防火墙的话..不要乱试哦(防火墙终于派上用场了)..



2007-04-26 01:15:52 创建文件
操作:允许
进程路径:F:\病毒样本\毒包\update16.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe

2007-04-26 01:15:52 创建文件
操作:允许
进程路径:F:\病毒样本\毒包\update16.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\drive\C\WINDOWS\Ruanyi05.dll

2007-04-26 01:16:16 运行应用程序
操作:允许
进程路径:F:\病毒样本\毒包\update16.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe

2007-04-26 01:16:17 创建文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\nsiD.tmp

2007-04-26 01:16:17 创建文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\nsiE.tmp

2007-04-26 01:16:17 修改文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\nsiE.tmp

2007-04-26 01:16:17 创建文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\DiskFree_mt01.8.exe

2007-04-26 01:16:26 运行应用程序
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\DiskFree_mt01.8.exe

2007-04-26 01:16:26 创建文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\live.exe

2007-04-26 01:16:26 创建文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\DiskFree_mt01.8.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\nswF.tmp

2007-04-26 01:16:35 运行应用程序
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\Ruanyi05.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\live.exe

2007-04-26 01:16:35 创建文件
操作:允许
进程路径:D:\Sandboxie\Sandbox\DefaultBox\user\current\Local Settings\Temp\live.exe
文件路径:D:\Sandboxie\Sandbox\DefaultBox\drive\C\WINDOWS\system32\Webmail.dll



木马样本的查杀
AntivirusVersionUpdateResult
AhnLab-V32007.4.26.004.25.2007 [td]no virus found
AntiVir7.4.0.1504.25.2007TR/Dldr.Barbs.A.5
Authentium4.93.804.24.2007W32/Dropper.EBA
Avast4.7.981.004.25.2007Win32:Singu-N
AVG7.5.0.46404.25.2007Dropper.Agent.DIU
BitDefender7.204.25.2007Trojan.Downloader.Barbs.A
CAT-QuickHeal9.0004.25.2007(Suspicious) - DNAScan
ClamAVdevel-2007041604.25.2007 [td]no virus found
DrWeb4.3304.25.2007Trojan.MulDrop.6129
eSafe7.0.15.004.25.2007Suspicious Trojan/Worm
eTrust-Vet30.7.359404.25.2007 [td]no virus found
Ewido4.004.25.2007 [td]no virus found
FileAdvisor104.25.2007 [td]no virus found
Fortinet2.85.0.004.25.2007W32/Agent.BEW!tr
F-Prot4.3.2.4804.25.2007W32/Dropper.EBA
F-Secure6.70.13030.004.25.2007Trojan-Dropper.Win32.Agent.bew
IkarusT3.1.1.504.25.2007Trojan-Spy.Win32.Banker.to
Kaspersky4.0.2.2404.25.2007Trojan-Dropper.Win32.Agent.bew
McAfee501704.25.2007Generic Downloader.d
Microsoft1.240504.25.2007 [td]no virus found
NOD32v2221804.25.2007 [td]no virus found
Norman5.80.0204.25.2007 [td]no virus found
Panda9.0.0.404.25.2007Suspicious file
Prevx1V204.25.2007Trojan.Updatex
Sophos4.16.004.23.2007 [td]no virus found
Sunbelt2.2.907.004.19.2007VIPRE.Suspicious
Symantec1004.25.2007 [td]no virus found
TheHacker6.1.6.09504.15.2007Trojan/Dropper.Agent.bew
VBA323.11.404.25.2007Trojan.Popwin
VirusBuster4.3.7:904.25.2007Trojan.DR.Agent.TJR
Webwasher-Gateway6.0.104.25.2007Trojan.Dldr.Barbs.A.5



目前对8个衍生物的查杀:   AVK2006杀2个     红伞杀3个

[ 本帖最后由 xpn282 于 2007-4-26 16:05 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lanvin
发表于 2007-4-26 01:43:57 | 显示全部楼层
嘟嘟这么晚还搞样本?
lanvin
发表于 2007-4-26 01:45:35 | 显示全部楼层
等等开着影子看看eq的表现



Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\8个衍生物.rar'
C:\Documents and Settings\Administrator\桌面\8个衍生物.rar
  [0] Archive type: RAR
  --> DiskFree_mt01.8.exe
      [DETECTION] Is the Trojan horse TR/Drop.Adfun
  --> live.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Boran.AC.2
  --> Webmail.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Boran.AC.2
      [WARNING]   The file was ignored!



Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\木马样本.rar'
C:\Documents and Settings\Administrator\桌面\木马样本.rar
  [0] Archive type: RAR
  --> update16.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Barbs.A.5
      [WARNING]   The file was ignored!





eq拦截了第一步,后面的出现了运行错误没有继续
图没有抓
闪了睡觉去

[ 本帖最后由 lanvin 于 2007-4-26 01:57 编辑 ]
dyw1021
头像被屏蔽
发表于 2007-4-26 01:46:58 | 显示全部楼层
费尔也只杀了两个!~~~~~~~~~~~~~~~~~~
xpn282
 楼主| 发表于 2007-4-26 01:59:49 | 显示全部楼层
NOD32既然连样本都不杀[:27:]

睡觉咯...大家慢慢杀...觉得杀爽了再睡也不迟
couldsst
发表于 2007-4-26 02:22:08 | 显示全部楼层
VirusBuster  只对妈妈有兴趣她生的小孩没有一个喜欢
The EQs
发表于 2007-4-26 03:40:27 | 显示全部楼层

没人给eset上报。。。。当然不杀。。不要大惊小怪的。

Scan performed at: 2007-4-26 3:40:11
Scanning Log
NOD32 version 2218 (20070425) NT
Command line: C:\Documents and Settings\EQ2\桌面\8个衍生物.rar C:\Documents and Settings\EQ2\桌面\木马样本.rar
Operating memory - is OK

Date: 26.4.2007  Time: 03:40:16
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\8个衍生物.rar; C:\Documents and Settings\EQ2\桌面\木马样本.rar
C:\Documents and Settings\EQ2\桌面\8个衍生物.rar ?RAR ?Ruanyi05.exe ?NSIS ?DiskFree_mt01.8.exe ?NSIS ?ieagent-dist.exe - Win32/TrojanDownloader.Adload.NDE trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\8个衍生物.rar ?RAR ?DiskFree_mt01.8.exe ?NSIS ?ieagent-dist.exe - Win32/TrojanDownloader.Adload.NDE trojan - was a part of the deleted object
Number of scanned files: 12
Number of threats found: 2
Number of files cleaned: 1
Time of completion: 03:40:18 Total scanning time: 2 sec (00:00:02)
mofunzone
发表于 2007-4-26 06:47:05 | 显示全部楼层
看了楼上的言论就好笑,既然叫best hur还需要上报
p.s lz喜欢把0kb的样本也算一个吗?

[ 本帖最后由 mofunzone 于 2007-4-25 14:49 编辑 ]
solcroft
发表于 2007-4-26 06:59:19 | 显示全部楼层

回复 #7 EQ2 的帖子

原来还有这种杀软,用户不上报便不能查杀,NOD32病毒实验室的这种小白分析师聘了等于白聘
The EQs
发表于 2007-4-26 07:14:03 | 显示全部楼层

回复 #9 solcroft 的帖子

我倒想听听不上报怎么能查杀???难道分析师自己能预知???除了那些报壳的能查杀外。。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-27 08:47 , Processed in 0.132217 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表