本帖最后由 GreatMOLA 于 2023-8-23 11:50 编辑
下载:https://we.tl/t-HOazHSngFn
https://www.virustotal.com/gui/file/4222303a43daea00b3cb9515dcb48b60d71a28152da00de9747e9eea850b2da1?nocache=1
https://tria.ge/230823-d673zahd77/behavioral1
来源:ht:tsp/www.telegramv.com/telegram_desktop/
——————————————————————————
- 高级威胁防护阻止了一个恶意进程。进程路径: C:\Windows\System32\netsh.exe. 威胁名称: ATC.SuspiciousBehavior.53FACB6C4A3C8E4F.
复制代码- 高级威胁防护已开始对恶意进程执行清除操作。进程路径: C:\Windows\System32\netsh.exe. 威胁名称: ATC.SuspiciousBehavior.53FACB6C4A3C8E4F.
复制代码
——————————————————————————
- Remote address:
- 101.226.26.128:443
- Request
- GET /miaking77%40163.com%2F9E864580A9644FA0A274205784B8659A?download=T.jpg&Signature=58UUftbLkbYUDh2FMAiGcGkIFUABH%2F9bd%2B%2Bq4NpNbS8%3D&Expires=1692769217&NOSAccessKeyId=e7d1acab859342789faa85a4b0cb4c83 HTTP/1.1
- Cache-Control: no-cache
- Host: bucket-ynote-online-cdn.note.youdao.com
- Connection: Keep-Alive
- Response
- HTTP/1.1 200 OK
- Server: Tengine
- Content-Type: application/octet-stream
- Content-Length: 759059
- Connection: keep-alive
- Date: Mon, 21 Aug 2023 05:03:32 GMT
- Content-Disposition: attachment; filename="T.jpg"; filename*=UTF-8''T.jpg
- Etag: 151bde5194396bdb8cda5511f2cb7dcf
- Last-Modified: Mon, 21 Aug 2023 12:33:06 Asia/Shanghai
- X-Nos-Object-Name: miaking77%40163.com%2F9E864580A9644FA0A274205784B8659A
- X-Nos-Request-Id: 7f63a6ac-fc19-40a8-99be-1766b0e4b596
- X-Nos-Requesttype: GetObject
- X-Nos-Storage-Class: STANDARD
- Ali-Swift-Global-Savetime: 1692594212
- Via: cache28.l2cn1832[0,0,206-0,H], cache47.l2cn1832[1,0], vcache9.cn3775[0,16,200-0,H], vcache1.cn3775[20,0]
- Age: 167808
- X-Cache: HIT TCP_HIT dirn:11:7526803 mlen:0
- X-Swift-SaveTime: Wed, 23 Aug 2023 02:03:34 GMT
- X-Swift-CacheTime: 2429998
- Access-Control-Allow-Origin: https://note.youdao.com
- cdn-user-ip: 154.61.71.13
- cdn-source: ali
- cdn-ip: 101.226.26.128
- Timing-Allow-Origin: *
- EagleId: 65e21a9516927620200125372e
复制代码
|