kaptanmikro1 1
kaptanmikro1
romegames 1
romegames
mavzermete 1
mavzermete
lHezarfeNl 1
lHezarfeNl
Reklam vermek için turkmmo@gmail.com

Wolfteam Aira Hack | enveter,fly

  • Konuyu başlatan Konuyu başlatan xrhonin
  • Başlangıç tarihi Başlangıç tarihi
  • Cevaplar Cevaplar 10
  • Görüntüleme Görüntüleme 1K
Durum
Üzgünüz bu konu cevaplar için kapatılmıştır...
kanıt

PId Process Name TId Start Start Mem Win32 Start Win32 Start Mem
0x410 svchost.exe 0x67c 0x7c810856 MEM_IMAGE 0x77df9981 MEM_IMAGE
• Modules Loaded
• Windows Api Calls
• DNS Queries
DNS Query Text
rakion.latinocheats.com IN A +
• HTTP Queries
HTTP Query Text
rakion.latinocheats.com GET /index.html HTTP/1.1
• Verdict
Auto Analysis Verdict
Suspicious+
• Description
Suspicious Actions Detected
Modifies the windows host file
• Mutexes Created or Opened
PId Image Name Address Mutex Name
0x5f8 C:\TEST\sample.exe 0x76ee3a34 RasPbFile
0x5f8 C:\TEST\sample.exe 0x771ba3ae _!MSFTHISTORY!_
0x5f8 C:\TEST\sample.exe 0x771bc21c WininetConnectionMutex
0x5f8 C:\TEST\sample.exe 0x771bc23d WininetProxyRegistryMutex
0x5f8 C:\TEST\sample.exe 0x771bc2dd WininetStartupMutex
0x5f8 C:\TEST\sample.exe 0x771d96e1 c:!documents and settings!user!cookies!
0x5f8 C:\TEST\sample.exe 0x771d96e1 c:!documents and settings!user!local settings!history!history.ie5!
0x5f8 C:\TEST\sample.exe 0x771d96e1 c:!documents and settings!user!local settings!temporary internet files!content.ie5!
0x5f8 C:\TEST\sample.exe 0x777904d3 WininetStartupMutex
0x5f8 C:\TEST\sample.exe 0x7c81a838 ShimCacheMutex
• Events Created or Opened
PId Image Name Address Event Name
0x5f8 C:\TEST\sample.exe 0x769c4ec2 Global\userenv: User Profile setup event
0x5f8 C:\TEST\sample.exe 0x77a89422 Global\crypt32LogoffEvent
0x5f8 C:\TEST\sample.exe 0x77de5f48 Global\SvcctrlStartEvent_A3752DX
 
kanıt

PId Process Name TId Start Start Mem Win32 Start Win32 Start Mem
0x410 svchost.exe 0x67c 0x7c810856 MEM_IMAGE 0x77df9981 MEM_IMAGE
• Modules Loaded
• Windows Api Calls
• DNS Queries
DNS Query Text
rakion.latinocheats.com IN A +
• HTTP Queries
HTTP Query Text
rakion.latinocheats.com GET /index.html HTTP/1.1
• Verdict
Auto Analysis Verdict
Suspicious+
• Description
Suspicious Actions Detected
Modifies the windows host file
• Mutexes Created or Opened
PId Image Name Address Mutex Name
0x5f8 C:\TEST\sample.exe 0x76ee3a34 RasPbFile
0x5f8 C:\TEST\sample.exe 0x771ba3ae _!MSFTHISTORY!_
0x5f8 C:\TEST\sample.exe 0x771bc21c WininetConnectionMutex
0x5f8 C:\TEST\sample.exe 0x771bc23d WininetProxyRegistryMutex
0x5f8 C:\TEST\sample.exe 0x771bc2dd WininetStartupMutex
0x5f8 C:\TEST\sample.exe 0x771d96e1 c:!documents and settings!user!cookies!
0x5f8 C:\TEST\sample.exe 0x771d96e1 c:!documents and settings!user!local settings!history!history.ie5!
0x5f8 C:\TEST\sample.exe 0x771d96e1 c:!documents and settings!user!local settings!temporary internet files!content.ie5!
0x5f8 C:\TEST\sample.exe 0x777904d3 WininetStartupMutex
0x5f8 C:\TEST\sample.exe 0x7c81a838 ShimCacheMutex
• Events Created or Opened
PId Image Name Address Event Name
0x5f8 C:\TEST\sample.exe 0x769c4ec2 Global\userenv: User Profile setup event
0x5f8 C:\TEST\sample.exe 0x77a89422 Global\crypt32LogoffEvent
0x5f8 C:\TEST\sample.exe 0x77de5f48 Global\SvcctrlStartEvent_A3752DX


tm içinde log olduğu zaten yazıyo eğer biraz kodlama bilgin olsa içinde hangi trojanın(virüs değil trojan) olduğunuda bilidin... Bu arada bu trojan kodlama dili değil nasıl ve nerden çevirdiysen artık...
 
Durum
Üzgünüz bu konu cevaplar için kapatılmıştır...

Şu an konuyu görüntüleyenler (Toplam : 0, Üye: 0, Misafir: 0)

Geri
Üst