本帖最后由 墨家小子 于 2015-12-21 17:25 编辑
@胖福 这个跟上午那个数字的样本差不多
SHA256: 79a2d192274cbb054a94ad4f6dd3711bba847090281de619bfc2a9a2f163e28d
File name: 356455.exe
Detection ratio: 0 / 54
Analysis date: 2015-12-21 09:18:17 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1450689497/
2015/12/21 17:21:51,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\DD\Desktop\1\356455.exe" )
2015/12/21 17:21:57,C:\Users\DD\Desktop\1\356455.exe,47,Allowed ;创建交换数据流 (C:\Users\DD\Desktop\1\356455.exe:Zone.Identifier)
2015/12/21 17:21:59,C:\Users\DD\Desktop\1\356455.exe,53,Allowed ;执行应用程序 (C:\Users\DD\AppData\Roaming\fhlenacroic.exe)
2015/12/21 17:22:02,C:\Users\DD\Desktop\1\356455.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\cmd.exe" /c DEL C:\Users\DD\Desktop\1\356455.exe)
2015/12/21 17:22:04,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,47,Allowed ;创建交换数据流 (C:\Users\DD\AppData\Roaming\fhlenacroic.exe:Zone.Identifier)
2015/12/21 17:22:05,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,santa_svc)
2015/12/21 17:22:07,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=3760))
2015/12/21 17:22:08,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/21 17:22:14,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/21 17:22:19,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/21 17:22:25,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/21 17:22:30,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/21 17:22:38,C:\Users\DD\AppData\Roaming\fhlenacroic.exe,53,Terminated ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
第一次运行的时候最后会联网,再次测试就没有了,不停重复执行vssadmin.exe |