因为最近手机出了问题,就想刷机试着解决,在朋友的推荐下我使用了甜椒刷机助手,,,下下来就被各种杀软查杀
我传到了腾讯哈勃分析系统中,居然是高度风险?!
- 基本信息
- 文件名称:
- tianjiao.exe
- MD5: b31d2160678777f6029da28df7b63f7a
- 文件类型: EXE
- 上传时间: 2018-02-11 17:26:59
- 出品公司: 深圳市网卓信息科技有限公司
- 版本: 3.6.0.3---3.6.0.3
- 壳或编译器信息: PACKER:UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo [Overlay]
- 子文件信息:
- upx_c_d76838aedumpFile / 80633a6961d8565ddb20cdab96564195 / EXE
- 关键行为
- 行为描述: 直接获取CPU时钟
- 详情信息:
- EAX = 0x5cf95fd2, EDX = 0x000000b8
- EAX = 0x82ee84b1, EDX = 0x000000b8
- 行为描述: 获取TickCount值
- 详情信息:
- TickCount = 221675, SleepMilliseconds = 50.
- TickCount = 221800, SleepMilliseconds = 50.
- TickCount = 221831, SleepMilliseconds = 50.
- TickCount = 221893, SleepMilliseconds = 50.
- TickCount = 282171, SleepMilliseconds = 60000.
- TickCount = 282187, SleepMilliseconds = 60000.
- TickCount = 291578, SleepMilliseconds = 60000.
- TickCount = 291593, SleepMilliseconds = 60000.
- TickCount = 292765, SleepMilliseconds = 60000.
- TickCount = 292781, SleepMilliseconds = 60000.
- TickCount = 292812, SleepMilliseconds = 60000.
- TickCount = 305109, SleepMilliseconds = 60000.
- TickCount = 305125, SleepMilliseconds = 60000.
- 进程行为
- 行为描述: 创建本地线程
- 详情信息:
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 2940, StartAddress = 77DC845A, Parameter = 00000000
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 2996, StartAddress = 008F28CD, Parameter = 0139A668
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 3000, StartAddress = 008F28CD, Parameter = 0139A888
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 3004, StartAddress = 008F28CD, Parameter = 013894B8
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 3012, StartAddress = 77E56C7D, Parameter = 001AA940
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 3016, StartAddress = 769AE43B, Parameter = 001AD2E0
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 3020, StartAddress = 719CD33A, Parameter = 001AF680
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2868, ThreadID = 3024, StartAddress = 76B2AEAF, Parameter = 00000000
- 文件行为
- 行为描述: 创建文件
- 详情信息:
- C:\Documents and Settings\Administrator\My Documents\onekeyrom\config\config.ini
- 行为描述: 修改文件内容
- 详情信息:
- C:\Documents and Settings\Administrator\My Documents\onekeyrom\config\config.ini ---> Offset = 0
- C:\Documents and Settings\Administrator\My Documents\onekeyrom\config\config.ini ---> Offset = 51
- 网络行为
- 行为描述: 建立到一个指定的套接字连接
- 详情信息:
- URL: we****om, IP: **.133.40.**:80, SOCKET = 0x0000037c
- URL: we****om, IP: **.133.40.**:80, SOCKET = 0x0000038c
- 行为描述: 按名称获取主机地址
- 详情信息:
- GetAddrInfoW: we****om
- 注册表行为
- 行为描述: 修改注册表
- 详情信息:
- \REGISTRY\USER\S-*\Software\OneKeyRom\ONKEYROM
- \REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\996E\DEBUG\Trace Level
- \REGISTRY\USER\S-*\Software\OneKeyRom\MacAddr
- 行为描述: 删除注册表键值
- 详情信息:
- \REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\996E\DEBUG\Trace Level
- 其他行为
- 行为描述: 创建互斥体
- 详情信息:
- CTF.LBES.MutexDefaultS-*
- CTF.Compart.MutexDefaultS-*
- CTF.Asm.MutexDefaultS-*
- CTF.Layouts.MutexDefaultS-*
- CTF.TMD.MutexDefaultS-*
- CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
- RasPbFile
- MSCTF.Shared.MUTEX.IOH
- MSCTF.Shared.MUTEX.IDL
- 行为描述: 创建事件对象
- 详情信息:
- EventName = DINPUTWINMM
- EventName = Global\crypt32LogoffEvent
- EventName = MSCTF.SendReceive.Event.IDL.IC
- EventName = MSCTF.SendReceiveConection.Event.IDL.IC
- 行为描述: 打开互斥体
- 详情信息:
- ShimCacheMutex
- DBWinMutex
- RasPbFile
- 行为描述: 查找指定窗口
- 详情信息:
- NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
- NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
- 行为描述: 窗口信息
- 详情信息:
- Pid = 2868, Hwnd=0x10344, Text = 甜椒安装向导, ClassName = QWidget.
- 行为描述: 获取TickCount值
- 详情信息:
- TickCount = 221675, SleepMilliseconds = 50.
- TickCount = 221800, SleepMilliseconds = 50.
- TickCount = 221831, SleepMilliseconds = 50.
- TickCount = 221893, SleepMilliseconds = 50.
- TickCount = 282171, SleepMilliseconds = 60000.
- TickCount = 282187, SleepMilliseconds = 60000.
- TickCount = 291578, SleepMilliseconds = 60000.
- TickCount = 291593, SleepMilliseconds = 60000.
- TickCount = 292765, SleepMilliseconds = 60000.
- TickCount = 292781, SleepMilliseconds = 60000.
- TickCount = 292812, SleepMilliseconds = 60000.
- TickCount = 305109, SleepMilliseconds = 60000.
- TickCount = 305125, SleepMilliseconds = 60000.
- 行为描述: 打开事件
- 详情信息:
- HookSwitchHookEnabledEvent
- Global\crypt32LogoffEvent
- MSFT.VSA.COM.DISABLE.2868
- MSFT.VSA.IEC.STATUS.6c736db0
- CTF.ThreadMIConnectionEvent.000007E8.00000000.0000000F
- CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.0000000F
- MSCTF.SendReceiveConection.Event.IOH.IC
- MSCTF.SendReceive.Event.IOH.IC
- 行为描述: 调用Sleep函数
- 详情信息:
- [1]: MilliSeconds = 50.
- [2]: MilliSeconds = 50.
- [3]: MilliSeconds = 60000.
- [4]: MilliSeconds = 0.
- 行为描述: 隐藏指定窗口
- 详情信息:
- [Window,Class] = [甜椒安装向导,QWidget]
- 行为描述: 直接获取CPU时钟
- 详情信息:
- EAX = 0x5cf95fd2, EDX = 0x000000b8
- EAX = 0x82ee84b1, EDX = 0x000000b8
- 进程树
- ****.exe (PID: 0x00000b34)
复制代码 源文件请到甜椒官网上去下载!
|