本帖最后由 墨家小子 于 2015-12-8 16:51 编辑
SHA256: 590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5
File name: Постановление суда.scr
Detection ratio: 1 / 55
Analysis date: 2015-12-08 08:38:24 UTC ( 6 minutes ago )
https://www.virustotal.com/en/fi ... 65a7d32c5/analysis/
2015/12/8 16:47:30,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr" /S)
2015/12/8 16:47:39,C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/8 16:47:41,C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr,48,Allowed ;出站网络访问
2015/12/8 16:48:46,C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\cmd.exe" /c move /Y "C:\Users\AAAA\AppData\Local\Temp\tmp4311.tmp" "C:\windows\system32\bmkujmw.dll")
2015/12/8 16:48:52,C:\Windows\SysWOW64\cmd.exe,41,Allowed ;修改受保护的文件 (C:\Windows\SysWOW64\bmkujmw.dll)
2015/12/8 16:48:56,C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr,53,Blocked ;执行应用程序 ("C:\windows\SysWOW64\cmd.exe" /c reg add "HKLM\System\CurrentControlSet\Services\Goizcuop" /ve /f)
2015/12/8 16:49:00,C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr,53,Blocked ;执行应用程序 (C:\windows\system32\rundll32.exe "C:\windows\system32\bmkujmw.dll",EntryPointA Goizcuop INST)
2015/12/8 16:49:12,C:\Users\AAAA\Desktop\AA\590a4dedb34956e454d384e882440e731d50a83a819cfef000596d165a7d32c5.scr,53,Blocked ;执行应用程序 ("C:\windows\system32\cmd.exe" /c ping -n 1 127.0.0.1 && del "C:\Users\AAAA\Desktop\AA\590A4D~1.SCR" >> NUL)
|