本帖最后由 lsop1349987 于 2025-6-5 23:34 编辑
emsisoft双击 2、3杀衍生 Heur.BZC.WBO.Nioc.1.0AD3083A (B),1、4主防miss
EDR有一堆可疑事件- Behavior AI (EDR) determined a severity of 'Notable' based on the following observed behavior patterns:
- Create HTML Application (HTA) File (MITRE T1218.005)
复制代码- Behavior AI (EDR) determined a severity of 'Notable' based on the following observed behavior patterns:
- Aspnet_compiler.exe execution (MITRE T1127)
- Connections to typical malware back connect ports (MITRE T1571)
- JavaScript or VBScript execution in user directory (MITRE T1059.005, T1059.007)
- JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
- Process launched without image name (MITRE T1036)
复制代码- Behavior AI (EDR) determined a severity of 'Suspicious' based on the following observed behavior patterns:
- PowerShell web request (MITRE T1059.001, T1105)
- MSHTA spawning command shell (MITRE T1218.005, T1059.001, T1059.005)
- Suspicious PowerShell parent process (MITRE T1059.001)
- Non-interactive PowerShell (MITRE T1059.001)
- Command shell spawning suspicious program (MITRE T1059.001, T1059.005, T1218)
- JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
- Mshta execution with URL (MITRE T1218.005)
- Create HTML Application (HTA) File (MITRE T1218.005)
复制代码- Behavior AI (EDR) determined a severity of 'Suspicious' based on the following observed behavior patterns:
- JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
- Mshta execution with URL (MITRE T1218.005)
复制代码- Behavior AI (EDR) determined a severity of 'Suspicious' based on the following observed behavior patterns:
- Suspicious MSHTA execution (MITRE T1218.005)
- JavaScript or VBScript execution involving Temp folder (MITRE T1059.005, T1059.007)
- JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
- MSHTA spwaned by Svchost (MITRE T1218.005)
- Scheduled Task target process from unusual location (MITRE T1053.005)
- Windows script execution via Scheduled Task (MITRE T1053.005, T1059)
- New application in AppCompat (MITRE T1204.002)
复制代码- Behavior AI (EDR) determined a severity of 'Notable' based on the following observed behavior patterns:
- External IP lookup connections (MITRE T1016)
复制代码
|