本帖最后由 驭龙 于 2015-4-13 08:30 编辑
最新消息,昨天MA的7秒破壳虽然没有彻底成功,但是它昨天自动反馈了,今天早上直接云秒杀一号壳
Internal signature match:subtype=Lowfi, sigseq=0x00000555288A1648, signame=#Lowfi:AGGREGATOR:MiurefThemCom, resource="\Device\HarddiskVolume6\infected\测DrWeb\测DrWeb\59[1]"
2015-04-13T00:19:45.450Z Dynamic signature received
Dynamic Signature has been received
Dynamic Signature Type:Signature Update
Signature Path:D:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\04b95d9711b1bb80762190acbe38faf678f07d2e
Dynamic Signature Compilation Timestamp:01-01-1601 08:02:22
Persistence Type:VDM Version
Source Version:282312693121025
Expiration Version:282312693121025
Internal signature match:subtype=Lowfi, sigseq=0x8000757880CBC550, signame=Backdoor:Win32/Zegost.DD, resource="\Device\HarddiskVolume6\infected\测DrWeb\测DrWeb\59[2]"
Internal signature match:subtype=Lowfi, sigseq=0x000005556C4BBC3F, signame=#Lowfi:HSTR:AutoSig_188, resource="\Device\HarddiskVolume6\infected\测DrWeb\测DrWeb\59[2]"
BEGIN BM telemetry
GUID:{387152E3-49BA-A6AB-EA7E-23CF8E87AD76}
TelemetryName:Behavior:Win32/DroppedKnownMalware
SignatureID:41453017067075
ProcessID:1708
ProcessCreationTime:130733579666946275
SessionID:1
CreationTime:04-13-2015 08:19:54
ImagePath:D:\Program Files\7-Zip\7zG.exe
ImagePathHash:CFD6E7BF357E91ED919190EA0C8EC3BB12DC48B151ABC327A80A0A8F7B73FB73
TargetFileName:G:\infected\测DrWeb\测DrWeb\59[1]
END BM telemetry
Internal signature match:subtype=Lowfi, sigseq=0x00000555288A1648, signame=#Lowfi:AGGREGATOR:MiurefThemCom, resource="\\?\G:\infected\测DrWeb\测DrWeb\59[1]"
Begin Resource Scan
Scan ID:{BEB59997-2C55-43E5-AA91-E32EB29A4596}
Scan Source:3
Start Time:04-13-2015 08:19:54
End Time:04-13-2015 08:20:03
Explicit resource to scan
Resource Schema:file
Resource Path:G:\infected\测DrWeb\测DrWeb\59[1]
Result Count:1
Threat Name:Trojan:Win32/Pocyx.A!plock
ID:2147692433
Severity:5
Number of Resources:1
Resource Schema:file
Resource Path:G:\infected\测DrWeb\测DrWeb\59[1]
Extended Info:42227738951119
End Scan |