本帖最后由 墨家小子 于 2016-1-11 17:42 编辑
SHA256: dffde400ad3d2af2bbd61c58bed9dcf7e3e37cec6210c9841d8ed5dc9117343d
File name: q5f21a2e0e3c.exe
Detection ratio: 9 / 53
Analysis date: 2016-01-11 09:20:38 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1452504038/
HMPA对于注入执行代码一贯的拦截态度
[mw_shl_code=css,true]2016/1/11 17:36:57,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop
\1\q5f21a2e0e3c.exe" )
2016/1/11 17:36:59,C:\Users\AA\Desktop\1\q5f21a2e0e3c.exe,53,Allowed ;执行应用程序 (C:\Users\f
\Desktop\1\q5f21a2e0e3c.exe)
2016/1/11 17:37:01,C:\Users\AA\Desktop\1\q5f21a2e0e3c.exe,53,Allowed ;执行应用程序 (C:\windows
\SYSTEM32\explorer.exe)
2016/1/11 17:37:04,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (cmd.exe /c
makecab "C:\windows\SysWOW64\bthudtask.exe" "C:\Users\AA\AppData\Roaming\cabfile.cab")
2016/1/11 17:37:07,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (makecab "C:
\windows\SysWOW64\bthudtask.exe" "C:\Users\AA\AppData\Roaming\cabfile.cab")
2016/1/11 17:37:09,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (cmd.exe /c wusa
"C:\Users\AA\AppData\Roaming\cabfile.cab" /extract:"C:\windows\SysWOW64\setup")
2016/1/11 17:37:10,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (wusa "C:\Users\f
\AppData\Roaming\cabfile.cab" /extract:"C:\windows\SysWOW64\setup")
2016/1/11 17:37:11,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 ("C:\windows
\system32\wusa.exe" "C:\Users\AA\AppData\Roaming\cabfile.cab" /extract:"C:\windows
\SysWOW64\setup")
2016/1/11 17:37:12,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 ("C:\windows
\SysWOW64\wusa.exe" "C:\Users\AA\AppData\Roaming\cabfile.cab" /extract:"C:\windows
\SysWOW64\setup")
2016/1/11 17:37:14,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (cmd.exe /c
makecab "C:\Users\AA\AppData\Roaming\newdev.dll" "C:\Users\AA\AppData\Roaming\cabfile.cab")
2016/1/11 17:37:15,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (makecab "C:\Users\f
\AppData\Roaming\newdev.dll" "C:\Users\AA\AppData\Roaming\cabfile.cab")
2016/1/11 17:37:17,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (cmd.exe /c wusa
"C:\Users\AA\AppData\Roaming\cabfile.cab" /extract:"C:\windows\SysWOW64\setup")
2016/1/11 17:37:18,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (wusa "C:\Users\f
\AppData\Roaming\cabfile.cab" /extract:"C:\windows\SysWOW64\setup")
2016/1/11 17:37:20,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 ("C:\windows
\system32\wusa.exe" "C:\Users\AA\AppData\Roaming\cabfile.cab" /extract:"C:\windows
\SysWOW64\setup")
2016/1/11 17:37:21,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 ("C:\windows
\SysWOW64\wusa.exe" "C:\Users\AA\AppData\Roaming\cabfile.cab" /extract:"C:\windows
\SysWOW64\setup")
2016/1/11 17:37:32,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 ("C:\windows
\SysWOW64\setup\bthudtask.exe" )
2016/1/11 17:37:32,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程
(bthudtask.exe(pid=9152))
2016/1/11 17:37:35,C:\Windows\SysWOW64\setup\bthudtask.exe,53,Allowed ;执行应用程序 (C:\Users
\AA\Desktop\1\q5f21a2e0e3c.exe)
2016/1/11 17:37:36,C:\Users\AA\Desktop\1\q5f21a2e0e3c.exe,53,Allowed ;执行应用程序 (C:\Users\f
\Desktop\1\q5f21a2e0e3c.exe)
2016/1/11 17:37:38,C:\Users\AA\Desktop\1\q5f21a2e0e3c.exe,53,Allowed ;执行应用程序 (C:\windows
\SYSTEM32\explorer.exe)
2016/1/11 17:37:43,C:\Windows\SysWOW64\explorer.exe,47,Allowed ;创建交换数据流 (C:\Windows
\SysWOW64\SPlayer\SPlayer.exe:Zone.Identifier)
2016/1/11 17:37:48,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:37:52,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (C:\windows
\SYSTEM32\tasklist.exe)
2016/1/11 17:37:52,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程
(tasklist.exe(pid=9732))
2016/1/11 17:37:56,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:37:58,C:\Windows\SysWOW64\tasklist.exe,53,Allowed ;执行应用程序 (C:\windows
\SYSTEM32\explorer.exe)
2016/1/11 17:38:01,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (C:\windows
\SYSTEM32\svchost.exe)
2016/1/11 17:38:04,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:06,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:07,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:10,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:12,C:\Windows\SysWOW64\svchost.exe,41,Blocked ;修改受保护的文件 (C:\Users\f
\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VAULT.hta)
2016/1/11 17:38:17,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:24,C:\Windows\SysWOW64\svchost.exe,53,Blocked ;执行应用程序 (wmic process call
create "vssadmin.exe delete shadows /all /quiet")
2016/1/11 17:38:26,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:27,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:29,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:31,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:33,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:35,C:\Windows\SysWOW64\tasklist.exe,26,Blocked ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
2016/1/11 17:38:38,C:\Windows\SysWOW64\tasklist.exe,26,Terminated ;修改受保护的注册表键 (HKLM
\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\Explorer\Run,SPlayer)
[/mw_shl_code] |