行为描述: 跨进程写入数据
详情信息:
TargetProcess = C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000cac
TargetProcess = C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000cac
TargetProcess = C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000cac
TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040000, Size = 0x00000020 TargetPID = 0x00000f34
TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040020, Size = 0x00000034 TargetPID = 0x00000f34
TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x7ffdb238, Size = 0x00000004 TargetPID = 0x00000f34
TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040000, Size = 0x00000020 TargetPID = 0x000008f4
TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040020, Size = 0x00000034 TargetPID = 0x000008f4
TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x000008f4
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000914
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000914
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000914
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000938
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000938
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000938
行为描述: 疑似加密敲诈行为
详情信息:
N/A
行为描述: 修改注册表_修改桌面背景注册表
详情信息:
\REGISTRY\USER\S-*\Control Panel\Desktop\WallpaperStyle
\REGISTRY\USER\S-*\Control Panel\Desktop\Wallpaper
行为描述: 获取TickCount值
详情信息:
TickCount = 143207, SleepMilliseconds = 20.
TickCount = 143238, SleepMilliseconds = 20.
TickCount = 143238, SleepMilliseconds = 60000.
TickCount = 203218, SleepMilliseconds = 60000.
TickCount = 204171, SleepMilliseconds = 60000.
TickCount = 205140, SleepMilliseconds = 60000.
TickCount = 205375, SleepMilliseconds = 60000.
TickCount = 205609, SleepMilliseconds = 60000.
TickCount = 205625, SleepMilliseconds = 60000.
TickCount = 205640, SleepMilliseconds = 60000.
TickCount = 205656, SleepMilliseconds = 60000.
TickCount = 205671, SleepMilliseconds = 60000.
TickCount = 205687, SleepMilliseconds = 60000.
TickCount = 205703, SleepMilliseconds = 60000.
TickCount = 205718, SleepMilliseconds = 60000.
行为描述: 杀掉进程
详情信息:
TASKKILL = taskkill /im cmdtool.exe /f
C:\Windows\System32\regedit.exe
C:\Windows\System32\ntsd.exe
行为描述: 在桌面创建文件
详情信息:
C:\Users\Administrator\Desktop\money.sbe
行为描述: 查找文件方式探测虚拟机
详情信息:
FindFirstFileEx: FileName = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox Guest Additions\*
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0xc6159f62, EDX = 0x00000075
EAX = 0xc89d6eeb, EDX = 0x00000075
EAX = 0xc89d6f37, EDX = 0x00000075
EAX = 0xc89d6f83, EDX = 0x00000075
EAX = 0xeb07a573, EDX = 0x00000075
EAX = 0xfd6b1036, EDX = 0x00000075
EAX = 0x34c07fda, EDX = 0x00000076
EAX = 0x7110b0ef, EDX = 0x00000076
EAX = 0x764b7fa8, EDX = 0x00000076
EAX = 0x764b7ff4, EDX = 0x00000076
EAX = 0x043b58c9, EDX = 0x00000078
EAX = 0x043b5915, EDX = 0x00000078
EAX = 0x043b5961, EDX = 0x00000078
EAX = 0x043b59ad, EDX = 0x00000078
EAX = 0x06ee5929, EDX = 0x00000078
行为描述: 自删除
详情信息:
C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe
行为描述: 修改注册表_启动项
详情信息:
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpringBeep |