不是质量一般,你是的样本出来时间长了点,都入库了
HMPA:
SSF:
2015/12/31 13:25:48,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\1\2015-12-31-malware\Rig-EK-flash-exploit (2).exe" )
2015/12/31 13:25:51,C:\Users\AAA\Desktop\1\2015-12-31-malware\Rig-EK-flash-exploit (2).exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\cscript.exe" C:\Users\AAA\AppData\Local\Temp\xvmvykydhfmymjmzbbq.vbs)
2015/12/31 13:25:51,C:\Windows\SysWOW64\cscript.exe,53,Allowed ;执行应用程序 (\??\C:\windows\system32\conhost.exe 0xffffffff)
2015/12/31 13:25:51,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程 (cscript.exe(pid=6768))
2015/12/31 13:25:54,C:\Users\AAA\Desktop\1\2015-12-31-malware\Rig-EK-flash-exploit (2).exe,53,Allowed ;执行应用程序 (C:\Users\AAA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe)
2015/12/31 13:25:57,C:\Users\AAA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe,53,Allowed ;执行应用程序 (C:\windows\SysWOW64\explorer.exe)
2015/12/31 13:25:59,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=6916))
2015/12/31 13:26:01,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ShadowsocksR_1829439101)
2015/12/31 13:26:02,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,IDMan)
2015/12/31 13:26:03,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,aetfbzf)
2015/12/31 13:26:37,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ShadowsocksR_1829439101)
2015/12/31 13:26:38,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,IDMan)
2015/12/31 13:26:39,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,alujtxoh)
|