Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Подпомагане на АВ програмите с дефиниции,откриване на нови заплахи - част 9

Featured Replies

Пратих целия архив на Касперски,ЕСЕТ, Нортън

(: Ванка при експлойт паковете не всички файлове са зли

  • Отговори 1,3k
  • Прегледи 83,4k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Следващите коментари, които нямат връзка с темата заминават в коша! @engineer не е тук мястото в тази тема да ревеш и оплакваш като "ощипана мома" относно подписа ти!

  • mihnev_sz

  • ivan_baroveca
    ivan_baroveca

    AVIRA-File ID Filename Size (Byte) Result 2575220 AV sucks.pdf 9.18 KB UNDER ANALYSIS F-SECURE Thank you for your submission. Your file has been uploaded to our Sample Management Systems.

Публикувани изображения

  • Автор

(: Ванка при експлойт паковете не всички файлове са зли

Колко реално са заплахите в архива?

Колко реално са заплахите в архива?

The structure of this crimeware is quite complex and has a repertoire of 13 (thirteen) exploits by default included in the package and include:

MDAC for MSIE

MS009-02 for MSIE

ActiveX pack. Funciona en MSIE

compareTo for Firefox

JNO (JS navigator Object Code) for Firefox

MS06-006 for Firefox

Font tags for Firefox

Telnet for Opera

PDF collab.getIcon for all browser

PDF Util.Printf for all browser

PDF collab.collectEmailInfo for all browser

PDF Doc.media.newPlayer for all browser

Java calendar for all browser

Obviously, like any service that is offered in a market model, and it's crimeware including this, the "provider" secure the support, updates and cleanup of the package if necessary. All business!

From a historical standpoint, Eleonore Exploit Pack updatesare:

In June 2009 is available to the public the sale of Eleonore Exploit Pack v1.0 containing MDAC exploits, MS009-02, Snapshot, Telnet (for opera), PDF collab.getIcon, Util.Printf PDF, PDF collab.collectEmailInfo. Its value was in principle not of USD 599.

In July 2009 is updated to version 1.1 and adds two more exploits: Font tags that explodes in Firefox 3.5 and DirectX DirectShow that explodes in IE 6 and 7. Furthermore, there are improvements in encryption scripts. Its value was USD 500, and the previous version under the price to USD 300.

During the month of July, add the exploit Spreadsheet, PDF files are changed, eliminating the capture of images and adds the ability to upload a file through the admin panel itself. The version is called 1.2 and its cost is set at USD 700.

After a period of three months without updates in October is version 1.3, incorporating more features in the package fraudulent. Among them, some "improvements" exploits for Internet Explorer and adds Java D&E. The cost of this version was USD 1000.

In November began the marketing of version 1.3.1, which exploits continue to refine and, inter alia, add a Robots.txt file to improve the indexing and prevent certain folders are displayed. The price remained at USD 1000.

Б***и цените(: Не знам със сигурност колко са -по желание на клиента ги добавят.KAV WKS лови само

screenshot1162010.jpg

Редактирано от Гост (преглед на промените)

Eleonore Exploit Pack

http://www.skatafka.com/download.php?file=2ea0863f84ed571041ffc9b1a5ccbce3

2213810I.jpg

hxxp://dox.bg/files/dw?a=3f7c8366e2 :)

hxxp://dox.bg/files/dw?a=3f7c8366e2 :)

Нещо не бачка.

21057cc07890c976.png4d27712dd4ffeaaa.pngd287c552c6a85b2b.png

п.п.На единия шот пише, че съм му позволил да стартира преди, но това е, защото опитах да го стартирам направо от Opera, а не направих шотове, затова го свалих и стартирах отново.:(

Фалшив онлайн скенер.->>

firtullgone.com/uy/
- MDL 2010/06/11_07:42 c8b208cada9b96d1.png Ще кача файла и в скатафката, за да не изчезне бързо.:)
http://www.skatafka.com/download.php?file=2128c618e056591c116ed5798b33a460

Фалшив онлайн скенер.->>

firtullgone.com/uy/
- MDL 2010/06/11_07:42 c8b208cada9b96d1.png Ще кача файла и в скатафката, за да не изчезне бързо.:)
http://www.skatafka.com/download.php?file=2128c618e056591c116ed5798b33a460

Trojan.Win32.Tdss.bfop според Касперски

2214117E.jpg

Trojan.Win32.Tdss.bfop според Касперски

2214117E.jpg

rи при мен е същото веднага го хвана и го унищожи ;)

Ще кача файла и в скатафката, за да не изчезне бързо.;)

http://www.skatafka.com/download.php?file=2128c618e056591c116ed5798b33a460

аваст мълчи sad.gif

http://www.skatafka.com/download.php?file=a1e4e57a8036db61a0f3d2c03953e60f

avsss0.jpg

Virustotal 1/41

http://www.skatafka.com/download.php?file=a1e4e57a8036db61a0f3d2c03953e60f

avsss0.jpg

Virustotal 1/41

Пратих го на Касперски, Аваст, ЕСЕТ, Нортън и Авира :ph34r:

Hello,

This message is generated by automatic letter reception system. The report contains information on what the verdicts on the files (if any in the letter) makes antivirus with latest updates. Letter will be passed to the virus analyst.

av_sucks.pdf

This file is in process.

Best Regards, Kaspersky Lab

Редактирано от ivan_baroveca (преглед на промените)

Пратих го на Касперски, Аваст, ЕСЕТ, Нортън и Авира :)

Hello,

This message is generated by automatic letter reception system. The report contains information on what the verdicts on the files (if any in the letter) makes antivirus with latest updates. Letter will be passed to the virus analyst.

av_sucks.pdf

This file is in process.

Best Regards, Kaspersky Lab

Горе шота на колегата е от KAV

avsss0.jpg

Ето и KIS 2011

2215899C.jpg

Засичат го и двете макар и с евристика.

Редактирано от nikssi (преглед на промените)

Unique exploit pack(DBD)

http://www.skatafka.com/download.php?file=46309d3e6deb985abff5e1227fbbdc4b

Virustotal 0/41

Unique exploit pack(DBD)

http://www.skatafka.com/download.php?file=46309d3e6deb985abff5e1227fbbdc4b

Virustotal 0/41

Hello,

This message is generated by automatic letter reception system. The report contains information on what the verdicts on the files (if any in the letter) makes antivirus with latest updates. Letter will be passed to the virus analyst.

ff.php,

ie.php,

ie7.php,

op9.php

No malicious code were found in these files.

Best Regards, Kaspersky Lab

Пратих ги и на Нортън, ЕСЕТ.

Hello,

This message is generated by automatic letter reception system. The report contains information on what the verdicts on the files (if any in the letter) makes antivirus with latest updates. Letter will be passed to the virus analyst.

ff.php,

ie.php,

ie7.php,

op9.php

No malicious code were found in these files.

Best Regards, Kaspersky Lab

Пратих ги и на Нортън, ЕСЕТ.

Абе я някой които разбира от PHP да ни обясни има ли им нещо на тия файлове?Прикачам ie7.php като текст-вътре гледам някакви base64 кодировки,ама не ми говорят нищо(:

Ето отговор от Касперски, който получих за онзи файл av_sucks.pdf

Hello,

av_sucks.pdf - Exploit.JS.Pdfka.clo

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

The answer is relevant to the latest bases from update sources.

hййp://www.skatafka.com/download.php?file=a7f654bd9ccfed9fa4ff5959804b4771 :cool:

hййp://www.skatafka.com/download.php?file=0d8febdc223f9bf2648884452f158b6e :cool:

Давам линк към фейк антивирус hййp://download.idg.bg/show.php?nid=6790 Около 25мв е а Касперски пищи като луд а МБАМ не го лови !

А вече стават и нагли

Ето и реакцията му

Давам линк към фейк антивирус hййp://download.idg.bg/show.php?nid=6790 Около 25мв е а Касперски пищи като луд а МБАМ не го лови !

А вече стават и нагли

Ето и реакцията му

Norton мълчи.

hййp://www.skatafka.com/download.php?file=a7f654bd9ccfed9fa4ff5959804b4771 ;)

hййp://www.skatafka.com/download.php?file=0d8febdc223f9bf2648884452f158b6e :lol6:

Hello,

This message is generated by automatic letter reception system. The report contains information on what the verdicts on the files (if any in the letter) makes antivirus with latest updates. Letter will be passed to the virus analyst.

adobe__flash__player.exe

This file is in process.

Best Regards, Kaspersky Lab

2i0zzf6.jpg

Гост
Тази тема е заключена за нови отговори.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.