本帖最后由 安全守护者 于 2017-10-6 15:40 编辑
您提交的样本未发现风险![mw_shl_code=css,true]关键行为
行为描述: 屏蔽窗口关闭消息
详情信息:
hWnd = 0x0001034c, Text = Setup, ClassName = TWindowDisabler-Window.
hWnd = 0x00060334, Text = Setup, ClassName = TApplication.
进程行为
行为描述: 创建进程
详情信息:
[0x00000b00]ImagePath = C:\WINDOWS\system32\rundll32.exe, CmdLine = "C:\WINDOWS\system32\rundll32.exe" "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll" splash
行为描述: 创建新文件进程
详情信息:
[0x00000af0]ImagePath = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-9NJOP.tmp\996E.tmp, CmdLine = "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-9NJOP.tmp\996E.tmp" /SL5="$1033E,322426,57856,C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe"
文件行为
行为描述: 创建文件
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll
行为描述: 创建可执行文件
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll
行为描述: 修改文件内容
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp ---> Offset = 65536
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp ---> Offset = 131072
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp ---> Offset = 196608
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp ---> Offset = 262144
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll ---> Offset = 65536
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll ---> Offset = 131072
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll ---> Offset = 196608
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll ---> Offset = 262144
行为描述: 查找文件
详情信息:
FileName = C:\DOCUME~1
FileName = C:\DOCUME~1\ADMINI~1
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-9NJOP.tmp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-9NJOP.tmp\996E.tmp
FileName = C:\WINDOWS
FileName = C:\WINDOWS\system32
FileName = C:\WINDOWS\system32\rundll32.exe
其他行为
行为描述: 创建互斥体
详情信息:
oleacc-msaa-loaded
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.IOH
MSCTF.Shared.MUTEX.EPK
MSCTF.Shared.MUTEX.EAL
行为描述: 创建事件对象
详情信息:
EventName = Global\userenv: User Profile setup event
EventName = MSCTF.SendReceive.Event.EAL.IC
EventName = MSCTF.SendReceiveConection.Event.EAL.IC
EventName = MSCTF.SendReceive.Event.EPK.IC
EventName = MSCTF.SendReceiveConection.Event.EPK.IC
行为描述: 查找指定窗口
详情信息:
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
行为描述: 打开事件
详情信息:
HookSwitchHookEnabledEvent
CTF.ThreadMIConnectionEvent.000007E8.00000000.0000000F
CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.0000000F
MSCTF.SendReceiveConection.Event.IOH.IC
MSCTF.SendReceive.Event.IOH.IC
CTF.ThreadMIConnectionEvent.000007E8.00000000.00000010
CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.00000010
行为描述: 屏蔽窗口关闭消息
详情信息:
hWnd = 0x0001034c, Text = Setup, ClassName = TWindowDisabler-Window.
hWnd = 0x00060334, Text = Setup, ClassName = TApplication.
行为描述: 枚举窗口
详情信息:
N/A
行为描述: 可执行文件签名信息
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll(签名验证: 未通过)
行为描述: 可执行文件MD5
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\is-9NJOP.tmp\996E.tmp ---> 832dab307e54aa08f4b6cdd9b9720361
C:\Documents and Settings\Administrator\Local Settings\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll ---> 47ffd039668dc2d856e421bcde782d26
行为描述: 打开互斥体
详情信息:
ShimCacheMutex
行为描述: 加载新释放的文件
详情信息:
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-SESTI.tmp\i3R66fPaNEV6pO.dll.
进程树
****.exe (PID: 0x00000a9c)
****.tmp /SL5="$1033E,322426,57856,****.exe" (PID: 0x00000af0)
rundll32.exe i3r66fpanev6po.dll" splash (PID: 0x00000b00)[/mw_shl_code]
|