查看: 3332|回复: 8
收起左侧

[已鉴定] kuaibo.co涉嫌钓鱼qvod---【钓鱼下载伪快播 By :谁谁谁】

[复制链接]
fcerebel
发表于 2010-10-7 19:47:56 | 显示全部楼层 |阅读模式
本帖最后由 谁谁谁 于 2010.10.8 09:36 编辑

hxxp://www.kuaibo.co
涉嫌钓鱼qvod
单单访问网页本身似乎没有问题
但是下载猜测是捆绑病毒了的qvod
金山网盾会报
sy0923
发表于 2010-10-8 23:10:38 | 显示全部楼层
360报
歌歌的人
发表于 2010-10-9 07:13:25 | 显示全部楼层
一切正常
gxczlzz
发表于 2010-10-9 11:44:38 | 显示全部楼层
回复 3楼 歌歌的人 的帖子

你下那个播放器来试试[:27:]
歌歌的人
发表于 2010-10-9 16:19:09 | 显示全部楼层
回复 4楼 gxczlzz 的帖子

BD扫描表示正常的就是播放器
gxczlzz
发表于 2010-10-9 16:51:16 | 显示全部楼层
回复 5楼 歌歌的人 的帖子

前几天上报毒霸,表示非误报
歌歌的人
发表于 2010-10-9 17:00:06 | 显示全部楼层
Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

[size=0.9em]0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
KiaoBoSetup.exe
Submission date:
2010-10-09 08:55:14 (UTC)
Current status:
queued queued analysing finished

Result:
12/ 43 (27.9%)

VT Community

[size=0.8em]not reviewed
[size=0.8em] Safety score: -

Compact
Print results



AntivirusVersionLast UpdateResult
AhnLab-V32010.10.09.002010.10.08-
AntiVir7.10.12.1672010.10.08TR/Downloader.Gen
Antiy-AVL2.0.3.72010.10.09-
Authentium5.2.0.52010.10.09-
Avast4.8.1351.02010.10.09-
Avast55.0.594.02010.10.09-
AVG9.0.0.8512010.10.08-
BitDefender7.22010.10.09-
CAT-QuickHeal11.002010.10.08-
ClamAV0.96.2.0-git2010.10.09Trojan.Downloader-84425
Comodo63272010.10.09Heur.Suspicious
DrWeb5.0.2.033002010.10.09-
Emsisoft5.0.0.502010.10.09Trojan.Win32.Pasta.ls!A2
eSafe7.0.17.02010.10.07-
eTrust-Vet36.1.79012010.10.08-
F-Prot4.6.2.1172010.10.08W32/Blocker-based!Maximus
F-Secure9.0.15370.02010.10.09Suspicious:W32/Malware!Gemini
Fortinet4.2.249.02010.10.09-
GData212010.10.09-
IkarusT3.1.1.90.02010.10.09-
Jiangmin13.0.9002010.10.09-
K7AntiVirus9.65.27072010.10.08-
Kaspersky7.0.0.1252010.10.09-
McAfee5.400.0.11582010.10.09-
McAfee-GW-Edition2010.1C2010.10.08Heuristic.BehavesLike.Win32.Suspicious.L
Microsoft1.62012010.10.09-
NOD3255162010.10.08-
Norman6.06.072010.10.09W32/StartPage.WTF
nProtect2010-10-09.012010.10.09-
Panda10.0.2.72010.10.09-
PCTools7.0.3.52010.10.09-
Prevx3.02010.10.09Medium Risk Malware
Rising22.68.05.002010.10.09-
Sophos4.58.02010.10.09Address Tool Bar
Sunbelt70212010.10.09Trojan.Win32.Generic!BT
SUPERAntiSpyware4.40.0.10062010.10.09Trojan.Agent/Gen-StartPage
Symantec20101.2.0.1612010.10.09-
TheHacker6.7.0.1.0532010.10.08-
TrendMicro9.120.0.10042010.10.08-
TrendMicro-HouseCall9.120.0.10042010.10.09-
VBA323.12.14.12010.10.08-
ViRobot2010.9.25.40602010.10.09-
VirusBuster12.67.9.02010.10.08-
Additional information
Show all
MD5   : 8eb4c3a6912209615bc18e5fdab6413e
SHA1  : af0e8aa4849545dff7de0d4aa402aa0ade378d03
SHA256: 305456211696a48262dd425d8429942bf27d681e1398a10b157b2c8dc2508061
ssdeep: 98304:5YWmR1fjhoBL0qFKcuJCza3Ge2TA9uaZQ/SgBNxeCnHNzTH:5JBL028SUuaMSgnPHZH
File size : 4352801 bytes
First seen: 2010-10-09 08:55:14
Last seen : 2010-10-09 08:55:14
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (F-Prot): NSIS, UTF-8
packers (Kaspersky): Swf2Swc, Swf2Swc, Swf2Swc, Swf2Swc, Swf2Swc
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x3150
timedatestamp....: 0x4A3AB2AC (Thu Jun 18 21:33:32 2009)
machinetype......: 0x14c (I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x5DC4, 0x5E00, 6.51, edf99746478ec4f22d3f839540b0378e
.rdata, 0x7000, 0x129C, 0x1400, 5.05, e1b381c03cad2ee5a1d8b8d88a277d84
.data, 0x9000, 0x25C58, 0x400, 4.80, 72224490b487b215a4fcfaa7237504f6
.ndata, 0x2F000, 0x9000, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e
.rsrc, 0x38000, 0x90E8, 0x9200, 5.02, 1f16946affd9af70dbd5219706ecb769

[[ 8 import(s) ]]
KERNEL32.dll: CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, GetWindowsDirectoryA, SetFileTime, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, CreateFileA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetTempPathA
USER32.dll: EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow
GDI32.dll: SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject
SHELL32.dll: SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation
ADVAPI32.dll: RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA
COMCTL32.dll: ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create
ole32.dll: CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp?PX5=72BDE032214371F26B9542AFDDC07800851F1489
ExifTool:
file metadata
CodeSize: 24064
EntryPoint: 0x3150
FileSize: 4.2 MB
FileType: Win32 EXE
ImageVersion: 6.0
InitializedDataSize: 164864
LinkerVersion: 6.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
PEType: PE32
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2009:06:18 23:33:32+02:00
UninitializedDataSize: 1024
[/td][/td]
Symantec reputation:Suspicious.Insight
VT Community


rasis
发表于 2010-10-14 11:28:14 | 显示全部楼层

KOI9009
发表于 2010-10-14 19:31:37 | 显示全部楼层
瑞星 2011 报钓鱼网站
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-19 12:59 , Processed in 0.133700 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表