| 本帖最后由 lsop1349987 于 2025-6-5 23:34 编辑 
 emsisoft双击 2、3杀衍生 Heur.BZC.WBO.Nioc.1.0AD3083A (B),1、4主防miss
 EDR有一堆可疑事件
 复制代码Behavior AI (EDR) determined a severity of 'Notable' based on the following observed behavior patterns:
Create HTML Application (HTA) File (MITRE T1218.005)
复制代码Behavior AI (EDR) determined a severity of 'Notable' based on the following observed behavior patterns:
Aspnet_compiler.exe execution (MITRE T1127)
Connections to typical malware back connect ports (MITRE T1571)
JavaScript or VBScript execution in user directory (MITRE T1059.005, T1059.007)
JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
Process launched without image name (MITRE T1036)
复制代码Behavior AI (EDR) determined a severity of 'Suspicious' based on the following observed behavior patterns:
PowerShell web request (MITRE T1059.001, T1105)
MSHTA spawning command shell (MITRE T1218.005, T1059.001, T1059.005)
Suspicious PowerShell parent process (MITRE T1059.001)
Non-interactive PowerShell (MITRE T1059.001)
Command shell spawning suspicious program (MITRE T1059.001, T1059.005, T1218)
JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
Mshta execution with URL (MITRE T1218.005)
Create HTML Application (HTA) File (MITRE T1218.005)
复制代码Behavior AI (EDR) determined a severity of 'Suspicious' based on the following observed behavior patterns:
JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
Mshta execution with URL (MITRE T1218.005)
复制代码Behavior AI (EDR) determined a severity of 'Suspicious' based on the following observed behavior patterns:
Suspicious MSHTA execution (MITRE T1218.005)
JavaScript or VBScript execution involving Temp folder (MITRE T1059.005, T1059.007)
JavaScript or VBScript file execution (MITRE T1059.005, T1059.007)
MSHTA spwaned by Svchost (MITRE T1218.005)
Scheduled Task target process from unusual location (MITRE T1053.005)
Windows script execution via Scheduled Task (MITRE T1053.005, T1059)
New application in AppCompat (MITRE T1204.002)
复制代码Behavior AI (EDR) determined a severity of 'Notable' based on the following observed behavior patterns:
External IP lookup connections (MITRE T1016)
 
 
 
 |