SHA256: 9b2900b94ecb9791a0db09b611d317914bcc620fd65a38025f861d767ab03afd
File name: 4727.tmp.exe
Detection ratio: 2 / 55
Analysis date: 2016-02-28 00:57:43 UTC ( 0 minutes ago )
https://www.virustotal.com/en/file/9b2900b94ecb9791a0db09b611d317914bcc620fd65a38025f861d767ab03afd/analysis/1456621063/
Bkav HW32.Packed.EFD4 20160227
GData Win32.Application.Systweak.M 20160227
今天进挂马网页,网页很快就跳转了,然后会有提示下载木马
https://www.virustotal.com/en/file/94e2bd29322cfcaf818d676cd08b0644a35b1f826864d40aff4321387ae07463/analysis/1456621230/
https://www.virustotal.com/en/file/c0905f90a1abe93bc84086c10fe9716de26dccce46e5252f4e7475a35a169e5e/analysis/1456621258/
IPS昨晚的拦截日志:
2016/2/27 22:53:29,高,阻止了 localhost 的入侵企图,已阻止,不需要操作,,不需要操作,不需要操作,Web Attack: Angler Exploit Kit Flash Exploit 6,"localhost (127.0.0.1, 2XXX8)",quicksearch.franklintnrealestatelistings.com/present.zvz?speak=&close=QkahT&hear=QHRVaCQnEV&world=MyEE8oNRK&continue=&love=we1wp&teacher=&audience=1UArIkyiPf&range=ZsftXnKY&John=c,"localhost (127.0.0.1, XXX9)",localhost (127.0.0.1),"TCP, 端口 2XXX8"
|