[mw_shl_code=css,true]行为描述: 获取窗口截图信息
详情信息:
Foreground window Info: HWND = 0x00000000, DC = 0x380103c8.
进程行为
行为描述: 创建本地线程
详情信息:
TargetProcess: WINWORD.EXE, InheritedFromPID = 2008, ProcessID = 1336, ThreadID = 1312, StartAddress = 77E56C7D, Parameter = 001A6630
TargetProcess: WINWORD.EXE, InheritedFromPID = 2008, ProcessID = 1336, ThreadID = 1304, StartAddress = 769AE43B, Parameter = 001A97E8
TargetProcess: WINWORD.EXE, InheritedFromPID = 2008, ProcessID = 1336, ThreadID = 420, StartAddress = 77E56C7D, Parameter = 001AA6B8
行为描述: 创建文件
详情信息:
C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dotm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRS{A24201CD-99B0-43DE-A674-6214E00BCF83}.tmp
C:\Documents and Settings\Administrator\Local Settings\%temp%\1462097931.578815.docx
行为描述: 修改文件内容
详情信息:
C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dotm ---> Offset = 0
C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dotm ---> Offset = 54
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRS{A24201CD-99B0-43DE-A674-6214E00BCF83}.tmp ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\%temp%\1462097931.631946.docx ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\%temp%\1462097931.632290.docx ---> Offset = 54
C:\Documents and Settings\Administrator\Local Settings\%temp%\1462097931.632633.docx ---> Offset = 0
行为描述: 查找文件
详情信息:
FileName = C:\WINDOWS
FileName = C:\WINDOWS\WinSxS
FileName = C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
FileName = C:\Program Files
FileName = C:\Program Files\Microsoft Office 2007
FileName = C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
FileName = C:\WINDOWS\Microsoft.NET\Framework\\*
FileName = C:\Program Files\Microsoft Office 2007\Office12\Normal.dotm
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\Normal.dotm
FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\桌面
FileName = C:\Documents and Settings\Administrator\Application Data
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates
行为描述: 复制文件
详情信息:
C:\Program Files\Microsoft Office 2007\Office12\OPA12.BAK ---> C:\Program Files\Microsoft Office 2007\Office12\opa12.dat
行为描述: 修改注册表
详情信息:
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\pj&
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109030000000000000000F01FEC\Usage\ProductFiles
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Common\LanguageResources\EnabledLanguages\2052
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Common\LanguageResources\EnabledLanguages\1033
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109030000000000000000F01FEC\Usage\WORDFiles
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\MTTT
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\.s&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\>u&
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4080110900063D11C8EF10054038389C\Usage\WORDFiles
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\2w&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\aw&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\~x&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\)y&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\&y&
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4080110900063D11C8EF10054038389C\Usage\ProductNonBootFiles
行为描述: 删除注册表键值
详情信息:
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\.s&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\>u&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\2w&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\aw&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\~x&
\REGISTRY\USER\S-*\Software\Microsoft\Office\12.0\Word\Resiliency\StartupItems\)y&
行为描述: 创建互斥体
详情信息:
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.GCompartListMUTEX.DefaultS-*
MSCTF.Shared.MUTEX.APH
MSCTF.Shared.MUTEX.EGF
行为描述: 创建事件对象
详情信息:
EventName = Local\PrimaryWord12Mutex_S-*
EventName = MSCTF.SendReceive.Event.EGF.IC
EventName = MSCTF.SendReceiveConection.Event.EGF.IC
EventName = Global\WatsonDataAccess
行为描述: 查找指定窗口
详情信息:
NtUserFindWindowEx: [Class,Window] = [mspim_wnd32,]
NtUserFindWindowEx: [Class,Window] = [MSOBALLOON,]
NtUserFindWindowEx: [Class,Window] = [MsoHelp10,]
NtUserFindWindowEx: [Class,Window] = [AgentAnim,]
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
行为描述: 调整进程token权限
详情信息:
SE_LOAD_DRIVER_PRIVILEGE
行为描述: 窗口信息
详情信息:
Pid = 1336, Hwnd=0x3018a, Text = MsoDockTop, ClassName = MsoCommandBarDock.
Pid = 1336, Hwnd=0x201ac, Text = Ribbon, ClassName = MsoCommandBar.
Pid = 1336, Hwnd=0x201ae, Text = MsoDockBottom, ClassName = MsoCommandBarDock.
Pid = 1336, Hwnd=0x201a6, Text = 状态栏, ClassName = MsoCommandBar.
Pid = 1336, Hwnd=0x101b8, Text = 状态栏, ClassName = MsoWorkPane.
Pid = 1336, Hwnd=0x3016c, Text = MsoWorkPane, ClassName = MsoWorkPane.
Pid = 1336, Hwnd=0x201a8, Text = MsoWorkPane, ClassName = MsoWorkPane.
Pid = 1336, Hwnd=0x20198, Text = Microsoft Word, ClassName = OpusApp.
Pid = 1336, Hwnd=0x4016e, Text = Microsoft Office Word, ClassName = bosa_sdm_Microsoft Office Word 12.0.
Pid = 1336, Hwnd=0x101c2, Text = Ribbon, ClassName = MsoWorkPane.
行为描述: 获取窗口截图信息
详情信息:
Foreground window Info: HWND = 0x00000000, DC = 0x380103c8.
行为描述: 隐藏指定窗口
详情信息:
[Window,Class] = [,ThunderRT6Main]
[/mw_shl_code] |