基本信息
文件名称:
2017.2.6.zip
MD5: 0db26c86b1125f163fce6f67250e2079
文件类型: zip
上传时间: 2017-02-06 16:38:55
出品公司: N/A
版本: N/A
壳或编译器信息: COMPILER:Microsoft Visual Studio .NET 2005 -- 2008 -> Microsoft Corporation [Overlay] *
漏洞检测结果: CVE-2015-2545.doc%
子文件信息: 详情
关键行为
行为描述: 修改原系统的EXE文件
详情信息:
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
C:\Documents and Settings\Administrator\Application Data\SogouExplorer\Temp\sogouexplorerup.exe
C:\Documents and Settings\Administrator\Application Data\SogouPY\SogouExplorer.exe
C:\Documents and Settings\Administrator\Application Data\Tencent\QQ\commonf_inst\TXSSOSetup.exe
C:\Documents and Settings\Administrator\Application Data\Tencent\QQ\SafeBase\QQSafeUD.exe
C:\Documents and Settings\Administrator\Application Data\Tencent\QQ\STemp\SetupEx~0\QQSetupEx.exe
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-01.Ransom.Cerber.exe%
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-03.Trojan.Puddpopsmc.exe%
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-04.Ransom.Kovter.exe%
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-05.Ransom.Locky.exe%
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-07.Trojan.FakeSkype.exe%
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-08.PUP.Ceeh.exe%
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\2017.2.6-09.Ransom.CryptoShield.exe%
行为描述: 修改注册表_启动项
详情信息:
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CTS
行为描述: 获取TickCount值
详情信息:
TickCount = 5439878, SleepMilliseconds = 3.
TickCount = 5439987, SleepMilliseconds = 3.
TickCount = 5441721, SleepMilliseconds = 3.
TickCount = 5441737, SleepMilliseconds = 3.
TickCount = 5443103, SleepMilliseconds = 25.
TickCount = 5444506, SleepMilliseconds = 100.
TickCount = 5444753, SleepMilliseconds = 3.
TickCount = 5444815, SleepMilliseconds = 3.
TickCount = 5444831, SleepMilliseconds = 3.
TickCount = 5445143, SleepMilliseconds = 3.
TickCount = 5445346, SleepMilliseconds = 3.
TickCount = 5445378, SleepMilliseconds = 3.
TickCount = 5445440, SleepMilliseconds = 3.
TickCount = 5445456, SleepMilliseconds = 3.
TickCount = 5445471, SleepMilliseconds = 3.
行为描述: 获取窗口截图信息
详情信息:
Foreground window Info: HWND = 0x00000000, DC = 0x30010203.
Foreground window Info: HWND = 0x00000000, DC = 0xa9010535.
Foreground window Info: HWND = 0x00000000, DC = 0xae010056.
Foreground window Info: HWND = 0x00000000, DC = 0x24010699.
行为描述: 在根目录创建自运行文件
详情信息:
C:\autorun.inf
C:\DiskD\autorun.inf
C:\DiskX\autorun.inf
行为描述: 设置特殊文件夹属性
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\ytmp
行为描述: 查找文件方式探测虚拟机
详情信息:
FindFirstFileEx: FileName = C:\Documents and Settings\Administrator\Local Settings\Application Data\VMware\*
FindFirstFileEx: FileName = C:\Documents and Settings\Administrator\Local Settings\Temp\VMwareDnD\*
FindFirstFileEx: FileName = C:\Documents and Settings\Administrator\Local Settings\Application Data\VMware\*.lnk
FindFirstFileEx: FileName = C:\Documents and Settings\Administrator\Local Settings\Temp\VMwareDnD\*.lnk
FindFirstFileEx: FileName = C:\Documents and Settings\All Users\Application Data\VMware\*.lnk
FindFirstFileEx: FileName = C:\Documents and Settings\All Users\Application Data\VMware\*
FindFirstFileEx: FileName = C:\Documents and Settings\root\Local Settings\Application Data\VMware\*.lnk
FindFirstFileEx: FileName = C:\Documents and Settings\root\Local Settings\Application Data\VMware\*
FindFirstFileEx: FileName = C:\Program Files\Common Files\VMware\*.lnk
FindFirstFileEx: FileName = C:\Program Files\Common Files\VMware\*
FindFirstFileEx: FileName = C:\Program Files\VMware\*.lnk
FindFirstFileEx: FileName = C:\Program Files\VMware\*
FindFirstFileEx: FileName = C:\WINDOWS\Temp\vmware-SYSTEM\*.lnk
FindFirstFileEx: FileName = C:\WINDOWS\Temp\vmware-SYSTEM\* |