本帖最后由 墨家小子 于 2016-1-1 21:25 编辑
SHA256: b0156f250ccf0fae2776fdd7b8b840668add42e62d3fe7975401aed24e52de4d
File name: 8CB6.tmp
Detection ratio: 14 / 54
Analysis date: 2016-01-01 13:05:22 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1451653522/
这个Web Attack: Exploit Toolkit Website 16是什么?
[mw_shl_code=css,true]2016/1/1 21:02:01,C:\Program Files (x86)\Internet Explorer\iexplore.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\Low\8CB6.tmp")
2016/1/1 21:02:12,C:\Users\AA\AppData\Local\Temp\Low\8CB6.tmp,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\cmd.exe" /c "C:\Users\AA\AppData\Local\Temp\Low\8CB6.tmp")
2016/1/1 21:02:33,C:\Program Files (x86)\Internet Explorer\iexplore.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\Low\33E4.tmp")
2016/1/1 21:02:36,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\Low\8CB6.tmp)
2016/1/1 21:02:40,C:\Users\AA\AppData\Local\Temp\Low\33E4.tmp,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\cmd.exe" /c "C:\Users\AA\AppData\Local\Temp\Low\33E4.tmp")
2016/1/1 21:02:50,C:\Users\AA\AppData\Local\Temp\Low\8CB6.tmp,53,Allowed ;执行应用程序 ("C:\Windows\System32\cscript.exe" C:\Users\AA\AppData\Local\Temp\besvxyuzvttthfrrgwmmihl.vbs)
2016/1/1 21:02:53,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\Low\33E4.tmp)
2016/1/1 21:03:01,C:\Users\AA\AppData\Local\Temp\Low\8CB6.tmp,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe)
2016/1/1 21:03:09,C:\Users\AA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe,53,Allowed ;执行应用程序 (C:\windows\SysWOW64\explorer.exe)
2016/1/1 21:03:17,C:\Users\AA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe,39,Blocked ;注册驱动程序或服务
2016/1/1 21:03:27,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (svchost.exe(pid=808))
2016/1/1 21:03:35,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ShadowsocksR_1829439101)
2016/1/1 21:03:43,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,IDMan)
2016/1/1 21:03:50,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,mhdx)
2016/1/1 21:04:25,C:\Windows\SysWOW64\explorer.exe,26,Terminated ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ShadowsocksR_1829439101)
[/mw_shl_code] |