KIS 2015 missed.
Have sent to Kaspersky Lab.
KSN:
Analysis:
[mw_shl_code=css,true]基本信息
文件名称:
Newygx012.exe
MD5: c2d57d52ede90120bed6b8ad02e09523
文件类型: Autoit
上传时间: 2015-08-28 18:42:58
出品公司: LaoMaoTao.net
版本: 8.14.5.30---8.14.5.30
壳或编译器信息: N/A
子文件信息:
Url.dll / 64019c828c8d925d4e695845e1bc191b / 7z
fbinst.dll / fccff3d5e754a1085fef98eb3e8692e3 / EXE
reg.dll / 30ca3af3fb9db4e3b7ff857bd154aa56 / EXE
cacls.dll / 221236080adab5e029e49183c6bae612 / EXE
LMTset.au3.tbl / 521e64ab4dee031700e2bce59729038b / Unknown
帮助.dat / a5df459f06fba265b05e094683fe3529 / Unknown
AutoItScript / 0164da7127fe531f1f386801bee60531 / Unknown
关键行为
行为描述: 写权限映射文件
详情信息:
CiceroSharedMemDefaultS-*
行为描述: 检测自身是否被调试
详情信息:
N/A
行为描述: 隐藏指定窗口
详情信息:
[Window,Class] = [#32770,#32770]
行为描述: 自删除
详情信息:
C:\Documents and Settings\Administrator\Local Settings\%temp%\1440758885.956730.exe
行为描述: 按名称获取主机地址
详情信息:
127.1
进程行为
行为描述: 隐藏窗口创建进程
详情信息:
ImagePath = , CmdLine = c:\windows\system32\cmd.exe /c c:\docume~1\admini~1\locals~1\temp\fbinst.dll "c:\windows\996e.e\support.im_" output img/* %~nx
ImagePath = , CmdLine = c:\windows\system32\cmd.exe /c ping 127.1 -n 3&del /q "c:\documents and settings\administrator\local settings\%temp%\1440758885.693633.exe"
行为描述: 创建进程
详情信息:
ImagePath = C:\WINDOWS\system32\cmd.exe, CmdLine = C:\WINDOWS\system32\cmd.exe /c C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fbinst.dll "C:\WINDOWS\996E.e\SUPPORT.IM_" output IMG/* %~nx
ImagePath = C:\WINDOWS\system32\cmd.exe, CmdLine = C:\WINDOWS\system32\cmd.exe /c ping 127.1 -n 3&del /q "C:\Documents and Settings\Administrator\Local Settings\%temp%\1440758885.662677.exe"
ImagePath = C:\WINDOWS\system32\ping.exe, CmdLine = ping 127.1 -n 3
行为描述: 创建新文件进程
详情信息:
ImagePath = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fbinst.dll, CmdLine = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fbinst.dll "C:\WINDOWS\996E.e\SUPPORT.IM_" output IMG/* %~nx
行为描述: 枚举进程
详情信息:
N/A
文件行为
行为描述: 写权限映射文件
详情信息:
CiceroSharedMemDefaultS-*
行为描述: 创建可执行文件
详情信息:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fbinst.dll
行为描述: 修改文件内容
详情信息:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aut4.tmp---> Offset = 4096
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dvmwlxl---> Offset = 20480
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aut5.tmp---> Offset = 49152
行为描述: 自删除
详情信息:
C:\Documents and Settings\Administrator\Local Settings\%temp%\1440758885.956730.exe
行为描述: 查找文件
详情信息:
FileName = C:\documents and settings
FileName = C:\Documents and Settings\administrator
FileName = C:\Documents and Settings\Administrator\local settings
FileName = C:\Documents and Settings\Administrator\Local Settings\temp
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\1440758885.765436.exe
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dvmwlxl
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\996E.e
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fbinst.dll
FileName = C:\WINDOWS
FileName = C:\WINDOWS\system32
FileName = C:\WINDOWS\system32\cmd.exe
FileName = C:\DOCUME~1
FileName = C:\DOCUME~1\ADMINI~1
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1
网络行为
行为描述: 按名称获取主机地址
详情信息:
127.1
注册表行为
行为描述: 删除注册表键值_删除启动项
详情信息:
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Run\996E.e
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\996E.e
其他行为
行为描述: 检测自身是否被调试
详情信息:
N/A
行为描述: 创建互斥体
详情信息:
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
SHIMLIB_LOG_MUTEX
行为描述: 隐藏指定窗口
详情信息:
[Window,Class] = [#32770,#32770]
行为描述: 获取系统权限
详情信息:
SE_LOAD_DRIVER_PRIVILEGE
行为描述: 获取TickCount值
详情信息:
TickCount = 486250, SleepMilliseconds = 500.
TickCount = 486281, SleepMilliseconds = 500.
TickCount = 486296, SleepMilliseconds = 500.
TickCount = 486312, SleepMilliseconds = 500.
TickCount = 486328, SleepMilliseconds = 500.
TickCount = 486343, SleepMilliseconds = 500.
TickCount = 486359, SleepMilliseconds = 500.
TickCount = 486390, SleepMilliseconds = 500.
TickCount = 486421, SleepMilliseconds = 500.
TickCount = 486453, SleepMilliseconds = 500.
TickCount = 486484, SleepMilliseconds = 500.
TickCount = 486515, SleepMilliseconds = 500.
TickCount = 486546, SleepMilliseconds = 500.
TickCount = 486578, SleepMilliseconds = 500.
TickCount = 486609, SleepMilliseconds = 500.
行为描述: 枚举窗口
详情信息:
N/A[/mw_shl_code]
运行截图
|