SHA256: 618fb48672885fd760d88fd0341a87e915619426b160992c1b6c5446702810ff
File name: 618fb48672885fd760d88fd0341a87e915619426b160992c1b6c5446702810ff.exe
Detection ratio: 3 / 55
Analysis date: 2015-12-14 09:39:49 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1450085989/
2015/12/14 17:41:23,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\O\Desktop\W\618fb48672885fd760d88fd0341a87e915619426b160992c1b6c5446702810ff.exe" )
2015/12/14 17:41:25,C:\Users\O\Desktop\W\618fb48672885fd760d88fd0341a87e915619426b160992c1b6c5446702810ff.exe,47,Allowed ;创建交换数据流 (C:\Users\O\Desktop\W\618fb48672885fd760d88fd0341a87e915619426b160992c1b6c5446702810ff.exe:Zone.Identifier)
2015/12/14 17:41:29,C:\Users\O\Desktop\W\618fb48672885fd760d88fd0341a87e915619426b160992c1b6c5446702810ff.exe,53,Allowed ;执行应用程序 ("C:\Windows\Microsoft.NET\Framework\v2.0.50727\\RegAsm.exe")
2015/12/14 17:41:32,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,54,Allowed ;接受入站网络数据包
2015/12/14 17:41:34,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 17:41:35,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,48,Allowed ;出站网络访问
2015/12/14 17:41:43,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,53,Allowed ;执行应用程序 (C:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext "C:\Users\O\AppData\Local\Temp\holdermail.txt")
2015/12/14 17:41:53,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,53,Allowed ;执行应用程序 (C:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext "C:\Users\O\AppData\Local\Temp\holderwb.txt")
2015/12/14 17:41:57,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,57,Allowed ;正在以只读方式打开受保护的进程 (explorer.exe(pid=1540))
2015/12/14 17:41:58,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,57,Allowed ;正在以只读方式打开受保护的进程 (iexplore.exe(pid=7076))
2015/12/14 17:42:00,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,57,Allowed ;正在以只读方式打开受保护的进程 (iexplore.exe(pid=6816))
2015/12/14 17:42:01,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,57,Allowed ;正在以只读方式打开受保护的进程 (iexplore.exe(pid=7136))
2015/12/14 17:42:02,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,57,Allowed ;正在以只读方式打开受保护的进程 (iexplore.exe(pid=6968))
2015/12/14 17:42:03,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,57,Allowed ;正在以只读方式打开受保护的进程 (iexplore.exe(pid=6104))
|