关键行为
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0xbcb3286c, EDX = 0x000000b3
EAX = 0xbcb328b8, EDX = 0x000000b3
EAX = 0xbcb32904, EDX = 0x000000b3
EAX = 0xbcb32950, EDX = 0x000000b3
行为描述: 直接调用系统关键API
详情信息:
Index = 0x0000010F, Name: NtWaitForSingleObject, Instruction Address = 0x004469E2
进程行为
行为描述: 创建本地线程
详情信息:
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2628, ThreadID = 2644, StartAddress = 00446900, Parameter = 4CB3A000
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2628, ThreadID = 2648, StartAddress = 00446900, Parameter = 4CB3A280
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2628, ThreadID = 2652, StartAddress = 00446900, Parameter = 4CB3A500
文件行为
行为描述: 查找文件
详情信息:
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\*
其他行为
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0xbcb3286c, EDX = 0x000000b3
EAX = 0xbcb328b8, EDX = 0x000000b3
EAX = 0xbcb32904, EDX = 0x000000b3
EAX = 0xbcb32950, EDX = 0x000000b3
行为描述: 直接调用系统关键API
详情信息:
Index = 0x0000010F, Name: NtWaitForSingleObject, Instruction Address = 0x004469E2
行为描述: 创建事件对象
详情信息:
EventName = DINPUTWINMM
进程树
****.exe (PID: 0x00000a44) |