此样本运行后的联网动作http://bbs.kafan.cn/forum.php?mo ... ;extra=#pid19964462
这两个网址:
finddelightful.org/pica1/525-direct
finddoubtful.org/pica1/525-direct
nis2011的记录:
类别:入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明,类别
2011/7/5 21:11,高,阻止了 finddelightful.org 的入侵企图,已阻止,不需要操作,Web Attack: Exploit Kit Variant Activity 2,不需要操作,不需要操作,"finddelightful.org (141.136.16.13, 80)",finddelightful.org/pica1/525-direct,"-PC (210.32.., 52881)",141.136.16.13 (141.136.16.13),"TCP, www-http",
2011/7/5 21:11,高,阻止了 finddoubtful.org 的入侵企图,已阻止,不需要操作,Web Attack: Exploit Kit Variant Activity 2,不需要操作,不需要操作,"finddoubtful.org (193.105.154.29, 80)",finddoubtful.org/pica1/525-direct,"-PC (210.32.., 52879)",193.105.154.29 (193.105.154.29),"TCP, www-http", |