本帖最后由 呼啸山庄 于 2025-1-4 10:58 编辑
OpenTIP (1和2的)
{
"Filename": "1.3ToDesk.msi",
"FileStatus": "Malware",
"FileType": "msi",
"Sha256": "752699DA7852ED1BF68E993BD9C062F283A1DF618650F397960437E0C388CB9C",
"DetectionsInfo": [
{
"LastDetectDate": "2025-01-04T02:50:35.107Z",
"Zone": "Red",
"DetectionName": "Backdoor.Agent.TCP.C&C"
},
{
"LastDetectDate": "2025-01-04T02:50:35.25Z",
"Zone": "Red",
"DetectionName": "Backdoor.Win32.DragonBreath.sb"
},
{
"LastDetectDate": "2025-01-04T02:50:35.13Z",
"Zone": "Red",
"DetectionName": "Trojan.DLLhijack.TCP.ServerRequest"
},
{
"LastDetectDate": "2025-01-04T02:50:35.243Z",
"Zone": "Red",
"DetectionName": "Trojan.Win32.Inject.sb"
},
{
"LastDetectDate": "2025-01-04T02:50:35.223Z",
"Zone": "Red",
"DetectionName": "Trojan.Win32.Strab.sb"
}
]
}
{
"Filename": "CHomer-Setup.v121.11.24 .exe",
"FileStatus": "Malware",
"FileType": "exe x32",
"Sha256": "800A2DA0B886AEBA9E2A673C62DDBB61A54A0AEF7B5D3F56D21AF08052301147",
"DetectionsInfo": [
{
"LastDetectDate": "2025-01-04T02:50:32.18Z",
"Zone": "Red",
"DetectionName": "Backdoor.Farfli.TCP.ServerRequest"
},
{
"LastDetectDate": "2025-01-04T02:50:32.217Z",
"Zone": "Red",
"DetectionName": "Trojan.Win32.Waldek.sb"
}
]
}
话说,应该会被卡巴的网络相关组件逮住吧?
|