好友
阅读权限30
听众
最后登录1970-1-1
|
楼主|
wxs513
发表于 2021-10-28 19:41
【1】2021-10-28 18:14:04,病毒防护,WEB扫描,发现病毒Backdoor/PHP.WebShell.br, 已阻止
病毒名称:Backdoor/PHP.WebShell.br
病毒ID:5D3CFDB2809B7119
病毒URL:http://sejaseurei.com/wwo.php
操作结果:已阻止
进程ID:8156
操作进程:C:\Program Files\lsplayerbox\LsBoxHeadless.exe
操作进程命令行:"C:\Program Files\lsplayerbox\LsBoxHeadless.exe" --comment leidian0 --startvm 20160302-aaaa-aaaa-48fb-000000000000 --vrde config
操作进程校验和:aa0b7abb67b0ba07ac9e6d40568cd60ec337c972
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【2】2021-10-28 17:59:37,病毒防护,WEB扫描,发现病毒Backdoor/PHP.WebShell.br, 已阻止
病毒名称:Backdoor/PHP.WebShell.br
病毒ID:5D3CFDB2809B7119
病毒URL:http://hotelsaintpaulos.com/wp-content/themes/sketch/404.php
操作结果:已阻止
进程ID:8156
操作进程:C:\Program Files\lsplayerbox\LsBoxHeadless.exe
操作进程命令行:"C:\Program Files\lsplayerbox\LsBoxHeadless.exe" --comment leidian0 --startvm 20160302-aaaa-aaaa-48fb-000000000000 --vrde config
操作进程校验和:aa0b7abb67b0ba07ac9e6d40568cd60ec337c972
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【3】2021-10-28 17:28:40,病毒防护,WEB扫描,发现病毒Backdoor/PHP.WebShell.br, 已阻止
病毒名称:Backdoor/PHP.WebShell.br
病毒ID:5D3CFDB2809B7119
病毒URL:http://mts2019-002-site12.gtempurl.com/wp-admin/wp-coding.php
操作结果:已阻止
进程ID:8156
操作进程:C:\Program Files\lsplayerbox\LsBoxHeadless.exe
操作进程命令行:"C:\Program Files\lsplayerbox\LsBoxHeadless.exe" --comment leidian0 --startvm 20160302-aaaa-aaaa-48fb-000000000000 --vrde config
操作进程校验和:aa0b7abb67b0ba07ac9e6d40568cd60ec337c972
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【4】2021-10-28 16:34:07,病毒防护,WEB扫描,发现病毒Backdoor/PHP.WebShell.br, 已阻止
病毒名称:Backdoor/PHP.WebShell.br
病毒ID:5D3CFDB2809B7119
病毒URL:http://miwyx.com/wp-good.php
操作结果:已阻止
进程ID:8156
操作进程:C:\Program Files\lsplayerbox\LsBoxHeadless.exe
操作进程命令行:"C:\Program Files\lsplayerbox\LsBoxHeadless.exe" --comment leidian0 --startvm 20160302-aaaa-aaaa-48fb-000000000000 --vrde config
操作进程校验和:aa0b7abb67b0ba07ac9e6d40568cd60ec337c972
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【5】2021-10-28 15:57:56,病毒防护,病毒查杀,自定义扫描, 发现0个风险项目
病毒库时间:2021-10-27 16:13
开始时间:2021-10-28 15:57
总计用时:00:00:04
扫描对象:262
扫描文件:243
发现风险:0
已处理风险:0
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【6】2021-10-28 10:36:18,病毒防护,WEB扫描,发现病毒OMacro/Downloader.apy, 已阻止
病毒名称:OMacro/Downloader.apy
病毒ID:F83D7AF1D4045B45
病毒URL:http://win.kusrini.com/temporadolorum/123.zip
操作结果:已阻止
进程ID:8156
操作进程:C:\Program Files\lsplayerbox\LsBoxHeadless.exe
操作进程命令行:"C:\Program Files\lsplayerbox\LsBoxHeadless.exe" --comment leidian0 --startvm 20160302-aaaa-aaaa-48fb-000000000000 --vrde config
操作进程校验和:aa0b7abb67b0ba07ac9e6d40568cd60ec337c972
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【7】2021-10-28 06:49:47,病毒防护,WEB扫描,发现病毒Backdoor/PHP.WebShell.br, 已阻止
病毒名称:Backdoor/PHP.WebShell.br
病毒ID:5D3CFDB2809B7119
病毒URL:http://hbengineering.in/wwo.php
操作结果:已阻止
进程ID:8156
操作进程:C:\Program Files\lsplayerbox\LsBoxHeadless.exe
操作进程命令行:"C:\Program Files\lsplayerbox\LsBoxHeadless.exe" --comment leidian0 --startvm 20160302-aaaa-aaaa-48fb-000000000000 --vrde config
操作进程校验和:aa0b7abb67b0ba07ac9e6d40568cd60ec337c972
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
|
|