SHA256: 9c6b51bc783cec97d1ba7f35d19894ca16687974e5eeab3f2a11d58bb182a8d4
File name: 524509.dll
Detection ratio: 3 / 55
Analysis date: 2015-12-27 03:07:49 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1451185669/
Bkav HW32.Packed.1CA3 20151226
Qihoo-360 HEUR/QVM40.1.Malware.Gen 20151227
Rising PE:Malware.Generic(Thunder)!1.A1C4 [F] 20151226
2015/12/27 11:05:18,C:\Windows\System32\wscript.exe,53,Allowed ;执行应用程序 ("C:\Windows
\System32\WScript.exe" "C:\Users\AA\AppData\Local\Temp\BugDZEesnDij.js" )
2015/12/27 11:05:19,C:\Windows\System32\wscript.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/27 11:05:22,C:\Windows\System32\wscript.exe,48,Allowed ;出站网络访问
2015/12/27 11:06:54,C:\Windows\System32\wscript.exe,53,Allowed ;执行应用程序 (rundll32 C:\Users\f
\AppData\Local\Temp\524509.dll, DllRegisterServer)
2015/12/27 11:06:57,C:\Windows\System32\rundll32.exe,53,Allowed ;执行应用程序 (rundll32 C:\Users
\AA\AppData\Local\Temp\524509.dll, DllRegisterServer)
2015/12/27 11:07:02,C:\Windows\SysWOW64\rundll32.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,api--1-0)
|