https://www.virustotal.com/en/fi ... nalysis/1450083824/
SHA256: 81f0271f775bcd84449bf2e5d00d96eabd1868ba3afb6f15e00cc99b0a988f82
File name: 47583932.exe
Detection ratio: 4 / 55
Analysis date: 2015-12-14 09:03:44 UTC ( 0 minutes ago )
2015/12/14 17:01:54,C:\Windows\System32\wscript.exe,53,Allowed ;执行应用程序 ("C:\Users\SS
\AppData\Local\Temp\47583932.exe" )
2015/12/14 17:02:10,C:\Windows\System32\wscript.exe,53,Allowed ;执行应用程序 ("C:\Users\SS
\AppData\Local\Temp\58493820.exe" )
2015/12/14 17:02:14,C:\Users\SS\AppData\Local\Temp\47583932.exe,53,Allowed ;执行应用程序 ("C:
\windows\syswow64\explorer.exe")
2015/12/14 17:02:17,C:\Users\SS\AppData\Local\Temp\58493820.exe,50,Allowed ;使用 DNS 解析服务访
问网络
2015/12/14 17:02:37,C:\Windows\System32\wscript.exe,53,Allowed ;执行应用程序 ("C:\Users\SS
\AppData\Local\Temp\48930492.exe" )
2015/12/14 17:02:39,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,1e0a5f1)
2015/12/14 17:02:43,C:\Users\SS\AppData\Local\Temp\58493820.exe,48,Allowed ;出站网络访问
2015/12/14 17:02:46,C:\Users\SS\AppData\Local\Temp\48930492.exe,50,Allowed ;使用 DNS 解析服务
访问网络
2015/12/14 17:02:50,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (-k netsvcs)
2015/12/14 17:02:53,C:\Users\SS\AppData\Local\Temp\48930492.exe,48,Allowed ;出站网络访问
2015/12/14 17:02:56,C:\Windows\SysWOW64\svchost.exe,48,Blocked ;出站网络访问
2015/12/14 17:02:59,C:\Users\SS\AppData\Local\Temp\48930492.exe,53,Allowed ;执行应用程序 (C:
\windows\system32\cmd.exe /c ""C:\Users\SS\AppData\Local\Temp\13653031.bat" "C:\Users\SS
\AppData\Local\Temp\48930492.exe" ")
|