本帖最后由 墨家小子 于 2015-12-25 10:46 编辑
SHA256: 92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a
File name: 92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe
Detection ratio: 4 / 53
Analysis date: 2015-12-25 02:29:05 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1451010545/
2015/12/25 10:38:37,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe" )
2015/12/25 10:38:38,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,53,Allowed ;执行应用程序 (C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe)
2015/12/25 10:38:40,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,System)
2015/12/25 10:38:44,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\cmd.exe" /k attrib "C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe" +s +h)
2015/12/25 10:38:47,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\cmd.exe" /k attrib "C:\Users\AAA\Desktop\1" +s +h)
2015/12/25 10:38:51,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (attrib "C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe" +s +h)
2015/12/25 10:38:53,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,System)
2015/12/25 10:38:56,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,53,Allowed ;执行应用程序 (notepad)
2015/12/25 10:38:59,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (attrib "C:\Users\AAA\Desktop\1" +s +h)
2015/12/25 10:39:02,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,40,Blocked ;以修改权限打开进程或线程 (notepad.exe(pid=7732))
2015/12/25 10:39:03,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,11,Blocked ;记录键盘输入
2015/12/25 10:39:05,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,System)
2015/12/25 10:39:06,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,24,Blocked ;监视剪贴版变更
2015/12/25 10:39:08,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/25 10:39:14,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,48,Blocked ;出站网络访问
建立 出站 网络连接 (TCP)
远程地址=androidtutku.ddns.net(78.163.136.143) 远程端口=1604
2015/12/25 10:39:17,C:\Users\AAA\Desktop\1\92bede1e22a90f8b7de899949099405022d85c6e30838c2c76a0c01771cc1e0a.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,System)
|