SHA256: b2c034b3483aaca882f7c533acebf7df5b0e7041e4beca271edbd7537bdeca8d
File name: 27E1.tmp.exe
Detection ratio: 1 / 55
Analysis date: 2016-03-03 02:21:40 UTC ( 1 minute ago )
https://www.virustotal.com/en/file/b2c034b3483aaca882f7c533acebf7df5b0e7041e4beca271edbd7537bdeca8d/analysis/1456971700/
Qihoo-360 HEUR/QVM07.1.Malware.Gen 20160303
1、打开IPS,诺顿拦截,日志:
2016/3/3 10:20:13,高,阻止了 localhost 的入侵企图,已阻止,不需要操作,Web Attack: Mass Injection Website 19,不需要操作,不需要操作,"localhost (127.0.0.1, 2XXX1)",XXenw.com/fastXXne-co-uk-depth-reXXw-reXXle-service-XXive-college-XXments-sXXdily-timely/,"localhost (127.0.0.1, XXX7)",localhost (127.0.0.1),"TCP, 端口 2XXX1",
2016/3/3 10:20:09,高,阻止了 localhost 的入侵企图,已阻止,不需要操作,Web Attack: Mass Injection Website 19,不需要操作,不需要操作,"localhost (127.0.0.1, 2XXX1)",XXnw.com/,"localhost (127.0.0.1, XXX5)",localhost (127.0.0.1),"TCP, 端口 2XXX1",
2、关闭诺顿自动防护、IPS,开启漏洞利用防护,诺顿毫无反应,SSF弹窗拦截:
|