-

  • (114)
  •     (21)
  •     (15)
  •     (12)
  •     (10)
  •     (10)
  •     (10)
  •     (5)
  •     (4)
  • 2014 (68)
  • (51)
  • (34)
  • (18)
  • (17)
  • (17)
  • (16)
  • (11)
  • (10)
  • (7)
  • - (5)
  • (4)
  • (3)
  • (3)
  • (3)
  • (2)
  • (2)
  • (2)
  • (2)
  • (1)
  • (1)
  • (1)
  • TV (1)
  • TV- (1)
  • (1)
  • (1)
  • (0)
  • (38)
  • (7114)
  •     (644)
  •     (141)
  •     (126)
  •     (123)
  •     (75)
  •    - (64)
  •     "." (22)
  •     (17)
  •     (16)
  •     (13)
  •     (10)
  •     (9)
  •     (8)
  •     (6)
  •     (5)
  •     (4)
  •     (4)
  •    - (3)
  •     (2)
  •     (2)
  •     (2)
  •    C (1)
  •    A (1)
  •     (676)
  •     (52)
  •     (47)
  •     (28)
  •     + (26)
  •     Drops (251)
  •     (31)
  •     (29)
  •     (14)
  •     (458)
  •     (68)
  •     (115)
  •     (34)
  •     (789)
  •     (970)
  •     (1)
  •     (760)
  •     (256)
  •     (228)
  •     (2)
  •     (30)
  •     (285)
  •     . (1)
  •     (10)
  •     (263)
  •     (961)
  •     (144)
  •     (23)
  •     (3)
  •     (80)
  •     (303)
  •     (50)
  •     (50)
  •     (5)
  •     (227)
  •     (31)
  •     (1764)
  •     (90)
  •     (123)
  •     (74)
  •     (96)
  •     (193)
  •     (320)
  •     (167)
  •     (128)
  •     (257)
  •     (6)
  •     (40)
  •     (982)
  •     (557)
  •     (288)
  •     (33)
  •     (3)
  •     (6)
  •     (42)
  • (8)
  • (9)
  • (22)
  • (2)
  • (862)
  •     (94)
  •     (75)
  •     (56)
  •     (42)
  •     (28)
  •     (23)
  •     (21)
  •     (21)
  •     (15)
  •     (7)
  •     (6)
  •     (5)
  •     (5)
  •     (4)
  •     (2)
  •     (2)
  •     (1)
  •     (1)
  •     (1)
  •     (48)
  •     (58)
  •     (16)
  •     (312)
  •     (53)
  •     (13)
  •     (14)
  •     (123)
  • (3)
  • (9)
  •     (3)
  • (8)
  • (5)
  • (9)
  • (275)
  •     (4)
  • (3)
  • (62)
  • (9)
  • (10)
  • (1)
  • (12)
  • (3)
  • (120)
  • (20)
  • (2)
  • (1)
  • (164)
  •     (6)
  •    - (5)
  •     (1)
  •    - (9)
  • (2)
  • (4)
  • (1)

 -

   _

 - e-mail

 

 -

( : 1) _63

 -

 LiveInternet.ru:
: 02.02.2012
: 9137
: 177
: 9339

:

.


: (1), (4), (2), (164), (11), (17), (1), (2), (16), (51), (20), 2014(68), (17), (120), (2), (18), (3), (12), (2), (34), (1), (10), (4), (9), (62), (0), (1), (3), (2), (3), (10), (275), (9), (5), (8), (9), (3), (862), - (5), (3), (2), (22), (9), (114), (7), (1), (8), (7114), (38), (1), (1), (2), (1), TV- (1), TV (1)
(0)

,

, 31 2017 . 22:12 +
70 [ + !]

, ,

 

, Brooklyn Ocean Parkway . . , .

 



(0)

: M.E.Doc ,

, 05 2017 . 16:37 +
rss_rss_hh_new [ + !]

: M.E.Doc ,

M.E.Doc . , , , - Trojan.Encoder.12544, NePetya, Petya.A, ExPetya WannaCry-2, M.E.Doc.

, Trojan.Encoder.12544 M.E.Doc, Intellect Service. M.E.Doc ZvitPublishedObjects.Server.MeCom , Windows: HKCU\SOFTWARE\WC.



, - Trojan.Encoder.12703. Dr.Web, , , Trojan.Encoder.12703 ProgramData\Medoc\Medoc\ezvit.exe, M.E.Doc:



id: 425036, timestamp: 15:41:42.606, type: PsCreate (16), flags: 1 (wait: 1), cid: 1184/5796:\Device\HarddiskVolume3\ProgramData\Medoc\Medoc\ezvit.exe

source context: start addr: 0x7fef06cbeb4, image: 0x7fef05e0000:\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll

created process: \Device\HarddiskVolume3\ProgramData\Medoc\Medoc\ezvit.exe:1184 --> \Device\HarddiskVolume3\Windows\System32\cmd.exe:6328

bitness: 64, ilevel: high, sesion id: 1, type: 0, reason: 1, new: 1, dbg: 0, wsl: 0

curdir: C:\Users\user\Desktop\, cmd: "cmd.exe" /c %temp%\wc.exe -ed BgIAAACkAABSU0ExAAgAAAEAAQCr+LiQCtQgJttD2PcKVqWiavOlEAwD/cOOzvRhZi8mvPJFSgIcsEwH8Tm4UlpOeS18o EJeJ18jAcSujh5hH1YJwAcIBnGg7tVkw9P2CfiiEj68mS1XKpy0v0lgIkPDw7eah2xX2LMLk87P75rE6 UGTrbd7TFQRKcNkC2ltgpnOmKIRMmQjdB0whF2g9o+Tfg/3Y2IICNYDnJl7U4IdVwTMpDFVE+q1l+Ad9 2ldDiHvBoiz1an9FQJMRSVfaVOXJvImGddTMZUkMo535xFGEgkjSDKZGH44phsDClwbOuA/gVJVktXvD X0ZmyXvpdH2fliUn23hQ44tKSOgFAnqNAra

status: signed_microsoft, script_vm, spc / signed_microsoft / clean

id: 425036 ==> allowed [2], time: 0.285438 ms

2017-Jun-27 15:41:42.626500 [7608] [INF] [4480] [arkdll]

id: 425037, timestamp: 15:41:42.626, type: PsCreate (16), flags: 1 (wait: 1), cid: 692/2996:\Device\HarddiskVolume3\Windows\System32\csrss.exe

source context: start addr: 0x7fefcfc4c7c, image: 0x7fefcfc0000:\Device\HarddiskVolume3\Windows\System32\csrsrv.dll

created process: \Device\HarddiskVolume3\Windows\System32\csrss.exe:692 --> \Device\HarddiskVolume3\Windows\System32\conhost.exe:7144

bitness: 64, ilevel: high, sesion id: 1, type: 0, reason: 0, new: 0, dbg: 0, wsl: 0

curdir: C:\windows\system32\, cmd: \??\C:\windows\system32\conhost.exe "1955116396976855329-15661177171169773728-1552245407-149017856018122784351593218185"

status: signed_microsoft, spc / signed_microsoft / clean

id: 425037 ==> allowed [2], time: 0.270931 ms

2017-Jun-27 15:41:43.854500 [7608] [INF] [4480] [arkdll]

id: 425045, timestamp: 15:41:43.782, type: PsCreate (16), flags: 1 (wait: 1), cid: 1340/1612:\Device\HarddiskVolume3\Windows\System32\cmd.exe

source context: start addr: 0x4a1f90b4, image: 0x4a1f0000:\Device\HarddiskVolume3\Windows\System32\cmd.exe

created process: \Device\HarddiskVolume3\Windows\System32\cmd.exe:1340 --> \Device\HarddiskVolume3\Users\user\AppData\Local\Temp\wc.exe:3648

bitness: 64, ilevel: high, sesion id: 1, type: 0, reason: 1, new: 1, dbg: 0, wsl: 0

curdir: C:\Users\user\Desktop\, cmd: C:\Users\user\AppData\Local\Temp\wc.exe -ed BgIAAACkAABSU0ExAAgAAAEAAQCr+LiQCtQgJttD2PcKVqWiavOlEAwD/cOOzvRhZi8mvPJFSgIcsEwH8Tm4UlpOeS18oE JeJ18jAcSujh5hH1YJwAcIBnGg7tVkw9P2CfiiEj68mS1XKpy0v0lgIkPDw7eah2xX2LMLk87P75rE6U GTrbd7TFQRKcNkC2ltgpnOmKIRMmQjdB0whF2g9o+Tfg/3Y2IICNYDnJl7U4IdVwTMpDFVE+q1l+Ad92 ldDiHvBoiz1an9FQJMRSVfaVOXJvImGddTMZUkMo535xFGEgkjSDKZGH44phsDClwbOuA/gVJVktXvDX 0ZmyXvpdH2fliUn23hQ44tKSOgFAnqNAra

fileinfo: size: 3880448, easize: 0, attr: 0x2020, buildtime: 01.01.2016 02:25:26.000, ctime: 27.06.2017 15:41:42.196, atime: 27.06.2017 15:41:42.196, mtime: 27.06.2017 15:41:42.196, descr: wc, ver: 1.0.0.0, company: , oname: wc.exe

hash: 7716a209006baa90227046e998b004468af2b1d6 status: unsigned, pe32, new_pe / unsigned / unknown

id: 425045 ==> undefined [1], time: 54.639770 ms


ZvitPublishedObjects.dll , . , , M.E.Doc, ZvitPublishedObjects.dll, . , :

  • ;
  • ;
  • ;
  • , ;
  • .


M.E.Doc rundll32.exe #1:



-, NePetya, Petya.A, ExPetya WannaCry-2 (Trojan.Encoder.12544).

, Reuters, M.E.Doc , . , , , M.E.Doc . Dr.Web BackDoor.Medoc.



P.S. Petya : www.rbc.ru/technology_and_media/04/07/2017/595bb1bc9a7947bc8356a6a3
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/332444/



(0)

: "" ""?

, 17 2017 . 16:54 +
Akmaya [ + !]

: "" ""?

1363237261_oboi-knigi-5 (700x393, 24Kb) : "" ""?

!

!)
.

1. "" ""? , - "".

2. ""? ? ""!

3. : "" ""? ! "" 1- . . " ", " " .

4. ! "" ""! "" " ". .

5. "", - "". , , !

6. " " , " ". " ".

7. "" - ! " " - . -, -. " ", " ?" - .

8. " " (- , ), " " (, , ). , !

9. ! "", ""? - , . "", , "".

10. ! ! , , "". - .

11. : "" "" " "? ! "" "" "" "", "" ... "" , .

12. , "", !

13. "" "" .

14. , : "" ""? : (- !) ( !). , " " " ".

15. , , " ". !

16. " ?" - . , : " " - " ", " " - " ". : " ?".

17. "" "". "" - , "" - , .

18. " ?"- ", !" - ! , . " ?/ ?", . - " ?/ ?", . , .

19. : ( ), ( ), ( ), ( ), ( ).

20. ? ! : , , . " " - .

21. "-E", "-E" - ! "" !

22. ! (?) (?) ! (?) (?) ! . " ", ", " . , .

23. : " ( , ). ( , )".

24. , : -, , , , , , , . , !

25. . " ?" - ! ! " , ".

26. "", .


Oksana Bezborodova

!))








 : [1]