https://www.virustotal.com/en/fi ... 23733f1cb/analysis/
SHA256: b18b0a3d999a9d2510c283622ade30836deb59cf1254aea9a05930923733f1cb
File name: egoista.exe
Detection ratio: 2 / 55
Analysis date: 2015-12-08 09:00:54 UTC ( 19 minutes ago )
2015/12/8 17:19:36,C:\PROGRA~2\MICROS~1\OFFICE11\WINWORD.EXE,53,Allowed ;执行应用程序 (cmd /c start %TMP%/suka.exe)
2015/12/8 17:19:40,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\AAAA\AppData\Local\Temp/suka.exe )
2015/12/8 17:19:40,C:\Users\AAAA\AppData\Local\Temp\suka.exe,53,Allowed ;执行应用程序 (\??\C:\windows\system32\conhost.exe 0xffffffff)
2015/12/8 17:19:40,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程 (suka.exe(pid=6944))
2015/12/8 17:19:43,C:\Users\AAAA\AppData\Local\Temp\suka.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/8 17:19:45,C:\Users\AAAA\AppData\Local\Temp\suka.exe,48,Allowed ;出站网络访问
2015/12/8 17:19:56,C:\Users\AAAA\AppData\Local\Temp\suka.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=2980))
|