行为描述: 创建互斥体
详情信息:
C6F26321_offset
行为描述: 创建事件对象
详情信息:
EventName = Global\crypt32LogoffEvent
行为描述: 加密数据
详情信息:
[CryptEncrypt] Data: 0x001938B0, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x00193AD8, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E2CE8, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E2F08, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E30A0, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E34C0, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E3A40, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E4318, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001A6CE8, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x00199CB8, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001E5C30, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001A61C0, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001A6358, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001DD550, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
[CryptEncrypt] Data: 0x001DDAD0, PlainTextLen: 128, CipherTextLen: 128, Flags: 0x00000000
行为描述: 获取TickCount值
详情信息:
TickCount = 219593, SleepMilliseconds = 1000.
TickCount = 226343, SleepMilliseconds = 5000.
TickCount = 221868, SleepMilliseconds = 150.
行为描述: 打开事件
详情信息:
HookSwitchHookEnabledEvent
Global\crypt32LogoffEvent
\SECURITY\LSA_AUTHENTICATION_INITIALIZED
行为描述: 可执行文件签名信息
详情信息:
C:\Documents and Settings\Administrator\Application Data\BCC6F26321.exe(签名验证: 未通过)
行为描述: 调用Sleep函数
详情信息:
[1]: MilliSeconds = 1000.
[1]: MilliSeconds = 5000.
[2]: MilliSeconds = 150.
[3]: MilliSeconds = 150.
[4]: MilliSeconds = 150.
[5]: MilliSeconds = 150.
[6]: MilliSeconds = 150.
[7]: MilliSeconds = 150.
[8]: MilliSeconds = 150.
[9]: MilliSeconds = 150.
[10]: MilliSeconds = 150.
行为描述: 可执行文件MD5
详情信息:
C:\Documents and Settings\Administrator\Application Data\BCC6F26321.exe ---> b0492e56e1246873173e8f7d32f8a278
行为描述: 打开互斥体
详情信息:
DBWinMutex
ShimCacheMutex
行为描述: 导入密钥
详情信息:
[CryptImportKey] Algorithm: CALG_RSA_KEYX (0x0000a400), Data: 0x00184980, DataLen: 148, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RSA_KEYX (0x0000a400), Data: 0x001A7980, DataLen: 148, Flags: 0x00000000
行为描述: 查找文件方式探测虚拟机
详情信息:
FindFirstFileEx: FileName = C:\Documents and Settings\Administrator\「开始」菜单\程序\Oracle VM VirtualBox Guest Additions\*.*
|