我Windows 7系统是MSE,而且是一个月前的特征库,同时无法单独关闭文件监控,不能测主防,所以彻底关闭监控,双击样本
样本成功注入
成功添加启动项
恢复MSE监控,注销系统,重新登录,一个月之前的MSE特征库无法杀样本的衍生物。
但Zbot对MSE的注入攻击可能失败了,MSE安然无恙。
同时MSE发动多次遥测
BEGIN BM telemetry
GUID:{39E85D1B-C00C-A30E-7746-C53417994A4A}
TelemetryName:Behavior:Win32/OpenExplorerProcess
SignatureID:23862338556417
ProcessID:964
ProcessCreationTime:130908312975287171
SessionID:2
CreationTime:11-01-2015 14:01:37
ImagePath:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
END BM telemetry
Internal signature match:subtype=Persist, sigseq=0x00000555038C655E, signame=#PERSIST_HSTR:UnsignedNSIS, cached=false, resource="C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe"
BEGIN BM telemetry
GUID:{BB8842DA-AD80-7BF0-2118-43034213287D}
TelemetryName:Behavior:Win32/MultiInjector
SignatureID:59046271144977
ProcessID:964
ProcessCreationTime:130908312975287171
SessionID:2
CreationTime:11-01-2015 14:01:37
ImagePath:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
TargetFileName:C:\Windows\System32\taskhost.exe
END BM telemetry
Internal signature match:subtype=Persist, sigseq=0x00000555038C655E, signame=#PERSIST_HSTR:UnsignedNSIS, cached=false, resource="C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe"
BEGIN BM telemetry
GUID:{67A343EA-87EC-6748-DCD9-09B082121CF9}
TelemetryName:Behavior:Win32/AppdataInjector
SignatureID:76639094139797
ProcessID:964
ProcessCreationTime:130908312975287171
SessionID:2
CreationTime:11-01-2015 14:01:37
ImagePath:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
TargetFileName:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
END BM telemetry
Internal signature match:subtype=Persist, sigseq=0x00000555038C655E, signame=#PERSIST_HSTR:UnsignedNSIS, cached=false, resource="C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe"
BEGIN BM telemetry
GUID:{2FD33AAC-CBE1-5054-8228-E128EEF336C4}
TelemetryName:Behavior:Win32/InjectedRemoteThreadExplorer
SignatureID:23861090166086
ProcessID:964
ProcessCreationTime:130908312975287171
SessionID:2
CreationTime:11-01-2015 14:01:37
ImagePath:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
TargetFileName:C:\Windows\explorer.exe
END BM telemetry
Internal signature match:subtype=Persist, sigseq=0x00000555038C655E, signame=#PERSIST_HSTR:UnsignedNSIS, cached=false, resource="C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe"
BEGIN BM telemetry
GUID:{F16FD492-ED83-3E49-5F52-63BD5A0A1789}
TelemetryName:Behavior:Win32/MultiInjector2
SignatureID:76637621234586
ProcessID:964
ProcessCreationTime:130908312975287171
SessionID:2
CreationTime:11-01-2015 14:01:37
ImagePath:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
TargetFileName:C:\Windows\System32\taskhost.exe
END BM telemetry
Internal signature match:subtype=Persist, sigseq=0x00000555038C655E, signame=#PERSIST_HSTR:UnsignedNSIS, cached=false, resource="C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe"
BEGIN BM telemetry
GUID:{7B3E2170-B6F7-9A0F-352B-AB4D11D0062E}
TelemetryName:Behavior:Win32/InjectRemoteThreadInMSAV
SignatureID:129414677452474
ProcessID:964
ProcessCreationTime:130908312975287171
SessionID:2
CreationTime:11-01-2015 14:01:37
ImagePath:C:\Users\win7\AppData\Roaming\Ywuwu\qeytroe.exe
TargetFileName:C:\Program Files\Microsoft Security Client\msseces.exe
END BM telemetry |