Bonjours, aujourd'hui je vais vous présenter un petit dossier qui consiste à analyser le comportement des antivirus sur nos script Autoit 3
Pour cela j'ai utiliser le site NoVirusThanks pour analyser les fichiers à tester, ayant tous le même contenu :
Liste des fichiers:
Test.au3 : Script source normale
Test_Obfuscated.au3 : script source Obfuscated
Test_1.exe : script source compilé normalement
Test_2.exe : script source compilé avec option+UPX
Test_3.exe : script source compilé avec option sans UPX
Test_4.exe : script source Obfuscated compilé normalement
Test_5.exe : script source Obfuscated compilé avec option+UPX
Test_6.exe : script source Obfuscated compilé avec option sans UPX
TESTS:
Test.au3 : Script source normale
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.25.56 (GMT 1)
Filename: test.au3
File size: 27 Bytes
MD5 Hash: 0cee70cb81c65e383c9891ddca85b40f
SHA1 Hash: FE98E3013241A16339B2DEAB1098AD7CEDAE86B8
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_Obfuscated.au3 : script source Obfuscated
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.25.57 (GMT 1)
Filename: test_Obfuscated.au3
File size: 2 KB
MD5 Hash: a10c481476c6c5681eeb4a4098f131a0
SHA1 Hash: 099EDA892F02D04302F4449D4BE6A51FD9646880
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_1.exe : script source compilé normalement
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.27.54 (GMT 1)
Filename: test_1.exe
File size: 283 KB
MD5 Hash: c529d5e4cf2ae59d079c26d45ccafbb6
SHA1 Hash: 8037B922ED7A9BDF168E4EB78A28FFFF0BBC0DB5
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_2.exe : script source compilé avec option+UPX
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.32.45 (GMT 1)
Filename: test_2.exe
File size: 283 KB
MD5 Hash: 20e2da471879375575820254b32d62e3
SHA1 Hash: E7BCA8CD97E736D177364B229D25E19FF6E1D7F6
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_3.exe : script source compilé avec option sans UPX
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.33.44 (GMT 1)
Filename: test_3.exe
File size: 598 KB
MD5 Hash: 8098d53cc113c9c1646c1b9de7b927ae
SHA1 Hash: 147817ED54D2C705C8A1096BE7715B4014622DBA
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate:
1 on 24
Detections
a-squared -
Riskware.FraudTool.Win32.MultiVirusCleaner!A2
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_4.exe : script source Obfuscated compilé normalement
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.31.33 (GMT 1)
Filename: Test_4.exe
File size: 287 KB
MD5 Hash: 13e462303761c9c65bddc6ea2f0da902
SHA1 Hash: AED4F4270C1B7C2C6CEAF6B7BE2B539AECB1891F
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_5.exe : script source Obfuscated compilé avec option+UPX
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.37.33 (GMT 1)
Filename: Test_5.exe
File size: 285 KB
MD5 Hash: 3e3e4f578bf95a0f654f2cafbd5e6ed5
SHA1 Hash: 8DE29104591CE479840F6681259CAE26F7F25FE1
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Test_6.exe : script source Obfuscated compilé avec option sans UPX
► Afficher le texte
File Info
Report generated: 9.7.2009 at 19.37.34 (GMT 1)
Filename: Test_6.exe
File size: 600 KB
MD5 Hash: 14963f8defc2e50826adaa6a290c1629
SHA1 Hash: 8FD4A02DA4D23B64462D16C80AC86F4F9F8A16E3
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate:
1 on 24
Detections
a-squared -
Riskware.FraudTool.Win32.MultiVirusCleaner!A2
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
CONCLUSION :
C'est à ne plus rien y comprendre... Pourquoi certains sont detectés et d'autre pas???
Aller petite surprise...
Un script faisait un FileInstall avec une simple image compilé simplement :
► Afficher le texte
File Info
Report generated: 9.7.2009 at 23.19.01 (GMT 1)
Filename: Test_FileInstall_1.exe
File size: 650 KB
MD5 Hash: 447c0d67c915225967e722b09fac26ad
SHA1 Hash: C13079B89E683C1FF16C26A50EE9926E3B71A292
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate:
1 on 24
Detections
a-squared -
Riskware.FraudTool.Win32.MultiVirusCleaner!A2
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
Puis compiler avec option sans UPX:
► Afficher le texte
File Info
Report generated: 9.7.2009 at 23.20.54 (GMT 1)
Filename: Test_FileInstall_2.exe
File size: 650 KB
MD5 Hash: b1aab0d0d2c364fa2f567243689b030f
SHA1 Hash: C9D554E8D4D87A327C3ADDE56F8489E1AF828970
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate:
1 on 24
Detections
a-squared -
Riskware.FraudTool.Win32.MultiVirusCleaner!A2
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
Scan report generated by
NoVirusThanks.org
DE QUOI SEMER LE DOUTE