サーチ
キーワードurl
a URL and execute it Download a file form a URL and inject to svchost.exe Uninstall self by deleting itself via cmd.exe マルウェアは、以下のWebサイトにアクセスし、不正リモートユーザからのコマンドを送受信します。 http://{BLOCKED
process その他 マルウェアは、以下を実行します。 It connects to the following URL to download and execute code in memory: http://{BLOCKED}.{BLOCKED}.25.96/XkJO その他 マルウェアは、以下を実行します。 マルウェアは、以下のURLに接続して、メモリ内にコードをダウンロードして実行します
%ProgramData% %System%\WindowsPowerShell\v1.0\powershell.exe Downloads and save files to a specific directory: URL download Link: http://{BLOCKED}.{BLOCKED}.83.140/2.exe Saves to the following directories:
JS_REDIR.BOG redirects to this URL
This URL related to TSPY_ZBOT.LES.
This URL has malicious content.
This URL contains malicious content.
This URL is related to BKDR_DEMTRANC.J.
This URL is related to TROJ_SCAR.AB.
This URL is connected to TROJ_FLYSTUD.EIK.
This URL is connected to TROJ_FLYSTUD.EIK.
This URL is connected to TROJ_FLYSTUD.EIK.
This URL is connected to TROJ_FLYSTUD.EIK
This URL is related to TSPY_ZBOT.CBL.
This URL is related to TSPY_ZBOT.CBL.
This URL is related to TSPY_ZBOT.CBL.
This URL is detected with TROJ_FONCSIR.A
This URL is related to BKDR_DELF.PRC.
This URL is related to BKDR_DELF.PRC.
This URL is related to TROJ_KRYPTIK.SMX.