我去,蜘蛛这是做好事不留名么?刚刚才发现之前双击的样本2并不是自己退出的,而是被逼无奈,可蜘蛛UI日志完全没有警报,日志上才显示是AMSI检测到感染,所以2样本才无法运行
Application: D:\12345\EXE样本5X_52\Samp(2).exe:9572
Scan object: <Buffer>
Verdict: infected (1)
Result: detected
Scan time: 19.210300 ms
id: 7800, timestamp: 09:10:24.108, type: PsDelete (17), flags: 1 (wait: 1)
sid: S-1-5-21-1235750953-3939464979-3339888586-1001, cid: 9572/3904:\Device\HarddiskVolume5\12345\EXE样本5X_52\Samp(2).exe
context: start addr: 0xd7fbce, image: 0xd60000:\Device\HarddiskVolume5\12345\EXE样本5X_52\Samp(2).exe
terminated win process: \Device\HarddiskVolume5\12345\EXE样本5X_52\Samp(2).exe:9572
fileinfo: size: 793088, easize: 40, attr: 0x20, buildtime: 13.07.2019 03:31:29.000, ctime: 29.08.2019 08:50:30.708, atime: 29.08.2019 08:50:30.723, mtime: 28.08.2019 10:13:01.392, descr: , ver: , company: , oname:
file sha1: adfb2216ada01cee0d9b91d7f96631c349770223
file sha256: 1548a3aeda9a7d456843cf70579660197140a25f7db1773f11f446f7362a1804
status: unsigned, pe32, new_pe, dot_net / unsigned / unknown / unknown
id: 7800 ==> undefined [1], time: 0.272300 ms |