SHA256: cdf332133a5a0e8dfa5c930dd55f99021b8bac0762e99e291b8eb7ddbb404933
File name: DE5.tmp.exe
Detection ratio: 6 / 56
Analysis date: 2016-03-10 11:05:25 UTC ( 1 minute ago )
https://www.virustotal.com/en/file/cdf332133a5a0e8dfa5c930dd55f99021b8bac0762e99e291b8eb7ddbb404933/analysis/1457607925/
AegisLab Troj.W32.Gen 20160310
Baidu Win32.Trojan.Kryptik.vz 20160310
ESET-NOD32 a variant of Win32/Kryptik.EQSV 20160310
Malwarebytes Ransom.TeslaCrypt 20160310
Qihoo-360 QVM41.1.Malware.Gen 20160310
Rising PE:Trojan.Kryptik!1.A32E [F] 20160310
骂了几天百度之后,终于……
等两天之后(3天?),IPS终于能拦截这个挂马网页了,之前一直不能拦截只能依靠下载智能分析撑场面
2016/3/10 18:51:08,高,阻止了 localhost 的入侵企图,已阻止,不需要操作,,不需要操作,不需要操作,Web Attack: Angler Exploit Kit Website 6,"localhost (127.0.0.1, 5XXX7)",rec.ohcrappyday.com/topic/69075-psychiatry-saturated-tracts-sweats-toughly-rejoining-efficiency-unraisable/,"localhost (127.0.0.1, XXX0)",localhost (127.0.0.1),"TCP, 端口 5XXX7",,,
关闭IPS之后,下载智能分析继续说我行的我腰好,我可以压更重的担子
|