| 行为描述:        跨进程写入数据 详情信息:
 TargetProcess = C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000cac
 TargetProcess = C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000cac
 TargetProcess = C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000cac
 TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040000, Size = 0x00000020 TargetPID = 0x00000f34
 TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040020, Size = 0x00000034 TargetPID = 0x00000f34
 TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x7ffdb238, Size = 0x00000004 TargetPID = 0x00000f34
 TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040000, Size = 0x00000020 TargetPID = 0x000008f4
 TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x00040020, Size = 0x00000034 TargetPID = 0x000008f4
 TargetProcess = C:\Windows\System32\wscript.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x000008f4
 TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000914
 TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000914
 TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000914
 TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000938
 TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000938
 TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000938
 行为描述:        疑似加密敲诈行为
 详情信息:
 N/A
 行为描述:        修改注册表_修改桌面背景注册表
 详情信息:
 \REGISTRY\USER\S-*\Control Panel\Desktop\WallpaperStyle
 \REGISTRY\USER\S-*\Control Panel\Desktop\Wallpaper
 行为描述:        获取TickCount值
 详情信息:
 TickCount = 143207, SleepMilliseconds = 20.
 TickCount = 143238, SleepMilliseconds = 20.
 TickCount = 143238, SleepMilliseconds = 60000.
 TickCount = 203218, SleepMilliseconds = 60000.
 TickCount = 204171, SleepMilliseconds = 60000.
 TickCount = 205140, SleepMilliseconds = 60000.
 TickCount = 205375, SleepMilliseconds = 60000.
 TickCount = 205609, SleepMilliseconds = 60000.
 TickCount = 205625, SleepMilliseconds = 60000.
 TickCount = 205640, SleepMilliseconds = 60000.
 TickCount = 205656, SleepMilliseconds = 60000.
 TickCount = 205671, SleepMilliseconds = 60000.
 TickCount = 205687, SleepMilliseconds = 60000.
 TickCount = 205703, SleepMilliseconds = 60000.
 TickCount = 205718, SleepMilliseconds = 60000.
 行为描述:        杀掉进程
 详情信息:
 TASKKILL = taskkill /im cmdtool.exe /f
 C:\Windows\System32\regedit.exe
 C:\Windows\System32\ntsd.exe
 行为描述:        在桌面创建文件
 详情信息:
 C:\Users\Administrator\Desktop\money.sbe
 行为描述:        查找文件方式探测虚拟机
 详情信息:
 FindFirstFileEx: FileName = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox Guest Additions\*
 行为描述:        直接获取CPU时钟
 详情信息:
 EAX = 0xc6159f62, EDX = 0x00000075
 EAX = 0xc89d6eeb, EDX = 0x00000075
 EAX = 0xc89d6f37, EDX = 0x00000075
 EAX = 0xc89d6f83, EDX = 0x00000075
 EAX = 0xeb07a573, EDX = 0x00000075
 EAX = 0xfd6b1036, EDX = 0x00000075
 EAX = 0x34c07fda, EDX = 0x00000076
 EAX = 0x7110b0ef, EDX = 0x00000076
 EAX = 0x764b7fa8, EDX = 0x00000076
 EAX = 0x764b7ff4, EDX = 0x00000076
 EAX = 0x043b58c9, EDX = 0x00000078
 EAX = 0x043b5915, EDX = 0x00000078
 EAX = 0x043b5961, EDX = 0x00000078
 EAX = 0x043b59ad, EDX = 0x00000078
 EAX = 0x06ee5929, EDX = 0x00000078
 行为描述:        自删除
 详情信息:
 C:\Users\Administrator\AppData\Local\Temp\HighSpeedCopy\cmdtool.exe
 行为描述:        修改注册表_启动项
 详情信息:
 \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpringBeep
 |