本帖最后由 761773275 于 2023-1-15 13:33 编辑
SOPHOS 主防杀
这是勒索!!!生成了勒索信
- C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe 中的勒索软件已阻止
复制代码- 勒索軟體:
- family_id: 93f5f3f5-3483-ead7-8e97-3881e8c71524
- process_version: 8
- thumbprint: 0a6cb192aa673ce60f05919d316f156867d487dcb0589c347e6ab0788d951d2a
- type: CryptoGuard
- process_pid: 10212
- version: 3.9.0.1391
- uid: [object Object]
- app_name: Java(TM) Platform SE binary
- process_alias_path: $programfiles\Java\jre1.8.0_351\bin\javaw.exe
- process_name: Java(TM) Platform SE binary
- details: Mitigation CryptoGuard V5
- Policy CryptoGuard
- Timestamp 2023-01-15T04:43:16
- Platform 10.0.19044/x64 v1391 06_55*
- PID 10212
- Enabled 0000000000000001
- Application C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe
- Created 2023-01-15T04:42:14
- Modified 2023-01-15T04:42:14
- Description Java(TM) Platform SE binary 8
- Filename C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe
- Detection Generic.Ransom.C
- 1*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\AppBlue.png.gg
- Overwritten L0, Read T4096 H4096|^238, Write T10752 H10256|^263 #1,r2
- 2*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\AppBlue.png
- Opened L10242, Read T10752|100% H10242|^4312 #2,w1
- 3 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\AppBlue.png.gg
- Created L0 #3
- 4 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-utility-l1-1-0.dll
- Opened, Deleted L21936, Read T4096|18% H4096|^935075 #4,r6
- 5 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-utility-l1-1-0.dll.gg
- Overwritten L0, Read T4096 H4096|^47268, Write T22016 H21952|^60203 #5,r6
- 6 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-utility-l1-1-0.dll
- Opened L21936, Read T22016|100% H21936|^1338466 #6,w5
- 7 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-utility-l1-1-0.dll.gg
- Created L0 #7
- 8 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-time-l1-1-0.dll
- Opened, Deleted L21936, Read T4096|18% H4096|^934526 #8,r10
- 9 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-time-l1-1-0.dll.gg
- Overwritten L0, Read T4096 H4096|^47218, Write T22016 H21952|^37782 #9,r10
- 10 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-time-l1-1-0.dll
- Opened L21936, Read T22016|100% H21936|^974867 #10,w9
- 11 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-time-l1-1-0.dll.gg
- Created L0 #11
- 12 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-string-l1-1-0.dll
- Opened, Deleted L26032, Read T4096|15% H4096|^935074 #12,r14
- 13*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-string-l1-1-0.dll.gg
- Overwritten L0, Read T4096 H4096|^47340, Write T26112 H13760|^239 #13,r14
- 14*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-string-l1-1-0.dll
- Opened L26032, Read T26112|100% H26032|^1016481 #14,w13
- 15 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-string-l1-1-0.dll.gg
- Created L0 #15
- 16 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-stdio-l1-1-0.dll
- Opened, Deleted L26032, Read T4096|15% H4096|^935058 #16,r18
- 29*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-private-l1-1-0.dll.gg
- Overwritten L0, Read T4096 H4096|^47100, Write T75264 H28672|^250 #29,r30
- 30*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-private-l1-1-0.dll
- Opened L75184, Read T75264|100% H32768|^852523 #30,w29
- 57*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-convert-l1-1-0.dll.gg
- Overwritten L0, Read T4096 H4096|^47450, Write T26112 H13760|^279 #59,r60
- 58*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-convert-l1-1-0.dll
- Opened L26032, Read T26112|100% H26032|^1417191 #60,w59
- 181*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\adal.dll.gg
- Overwritten L0, Read T4096 H4096|^533, Write T1514496 H24576|^266 #183,r184
- 182*C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\adal.dll
- Opened L1514376, Read T1514496|100% H32768|^237473 #184,w183
- Process Trace
- 1 C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212] *
- "C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe" -jar "C:\Users\Leung\Desktop\bypass.jar"
- 2 C:\Windows\explorer.exe [5872] *
- Dropped Files
- 1 C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c83e4.timestamp
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\Desktop\keygen.txt
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\ProgramData\Microsoft\User Account Pictures\guest.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\ProgramData\Microsoft\User Account Pictures\user-192.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\ProgramData\Microsoft\User Account Pictures\user-32.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\ProgramData\Microsoft\User Account Pictures\user-40.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\ProgramData\Microsoft\User Account Pictures\user-48.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\ProgramData\Microsoft\User Account Pictures\user.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\adal.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\alertIcon.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\alertIconWhite.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-console-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-console-l1-2-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-datetime-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-debug-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-errorhandling-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-fibers-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-file-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-file-l1-2-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-file-l2-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-handle-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-heap-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-interlocked-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-libraryloader-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-localization-l1-2-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-memory-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-namedpipe-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-processenvironment-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-processthreads-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-processthreads-l1-1-1.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-profile-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-rtlsupport-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-string-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-synch-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-synch-l1-2-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-sysinfo-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-timezone-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-core-util-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-conio-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-convert-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-environment-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-filesystem-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-heap-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-locale-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-math-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-multibyte-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-private-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-process-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-runtime-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-stdio-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-string-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-time-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\api-ms-win-crt-utility-l1-1-0.dll.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\AppData\Local\Microsoft\OneDrive\22.248.1127.0001\AppBlue.png.gg
- Dropped by C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\Desktop\bypass.jar
- Dropped by C:\Windows\explorer.exe [5872]
- Read by C:\Windows\System32\smartscreen.exe [4948]
- C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe [10212]
- 1 C:\Users\Leung\Desktop\jre-8u351-windows-x64.exe
- Dropped by C:\Windows\explorer.exe [5872]
- Read by C:\Windows\System32\svchost.exe [10652]
- C:\Windows\System32\svchost.exe [9772]
- C:\Windows\explorer.exe [5872]
- C:\Windows\System32\csrss.exe [500]
- C:\Windows\System32\csrss.exe [588]
- C:\Windows\System32\SearchProtocolHost.exe [5920]
- C:\Windows\System32\smartscreen.exe [4948]
- C:\Users\Leung\Desktop\jre-8u351-windows-x64.exe [11680]
- C:\Windows\System32\consent.exe [7572]
- 1 C:\Users\Leung\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db
- Dropped by C:\Windows\explorer.exe [5872]
- Read by C:\Windows\System32\svchost.exe [3360]
- C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe [6676]
- Thumbprint
- 0a6cb192aa673ce60f05919d316f156867d487dcb0589c347e6ab0788d951d2a
- Digital signature certificate process based thumbprint
- 4f9e408cbb68bfa08cc4e272836b85936608f8efda70323949fd86522c93e7a0
- Cryptoguard folder based thumbprint (level 1)
- 5d4c869d9e7e194f96a340d10c46c7337aaeb558c8366ba662d4753fc751dea9
- Cryptoguard folder based thumbprint (level 2)
- 6b0b207b4bff9f597fa76c5a1e274bc12fbf2e2beeb875ba7f21c128847447df
- Cryptoguard algorithm based thumbprint
- 84f7d87d196dd22fba497924009a8e5f98e448b32c6733135c79ef616eab11e3
- process_path: C:\Program Files\Java\jre1.8.0_351\bin\javaw.exe
复制代码
|