本帖最后由 willjjyu 于 2018-3-3 19:44 编辑
- <b>基本信息</b>
- 文件名称:
- <b>flashplayer28pp_va_install[1.3].exe</b>
- MD5: 6f366f9a0d1bed530ea58c1873afef57
- 文件类型: EXE
- 上传时间: 2018-03-03 19:40:07
- 出品公司: N/A
- 版本: N/A
- 壳或编译器信息: PACKER:UPX V2.00-V3.00 -> Markus Oberhumer & Laszlo Molnar & John Reiser *
- 子文件信息:
- upx30_52bae088dumpFile / 83a35d02ed0d12abd86d4ff0d746769d / EXE
- <b><font color="#ff0000">关键行为</font></b>
- <font color="#ff0000">行为描述: 在桌面创建文件
- 详情信息:
- C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe
- C:\Documents and Settings\Administrator\桌面\funny.exe
- C:\Documents and Settings\Administrator\桌面\AD.exe
- C:\Documents and Settings\Administrator\桌面\Flash.exe
- C:\Documents and Settings\Administrator\桌面\Locks.exe
- 行为描述: 杀掉进程
- 详情信息:
- TASKKILL = taskkill /f /t /im HipsTray.exe</font>
- <b>进程行为</b>
- 行为描述: 创建进程
- 详情信息:
- [0x00000b14]ImagePath = C:\WINDOWS\system32\cmd.exe, CmdLine = "C:\WINDOWS\system32\cmd" /c ""C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.bat" "C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe""
- [0x00000b34]ImagePath = C:\WINDOWS\system32\tasklist.exe, CmdLine = tasklist
- [0x00000b3c]ImagePath = C:\WINDOWS\system32\findstr.exe, CmdLine = findstr /i HipsTray.exe
- [0x00000be0]ImagePath = C:\WINDOWS\system32\taskkill.exe, CmdLine = taskkill /f /t /im HipsTray.exe
- 行为描述: 创建本地线程
- 详情信息:
- TargetProcess: tasklist.exe, InheritedFromPID = 2836, ProcessID = 2868, ThreadID = 2896, StartAddress = 77E56C7D, Parameter = 000EAAD0
- TargetProcess: tasklist.exe, InheritedFromPID = 2836, ProcessID = 2868, ThreadID = 2900, StartAddress = 769AE43B, Parameter = 000ED460
- TargetProcess: tasklist.exe, InheritedFromPID = 2836, ProcessID = 2868, ThreadID = 2908, StartAddress = 77E56C7D, Parameter = 000EDB08
- TargetProcess: taskkill.exe, InheritedFromPID = 2836, ProcessID = 3040, ThreadID = 3084, StartAddress = 77E56C7D, Parameter = 000EAB88
- TargetProcess: taskkill.exe, InheritedFromPID = 2836, ProcessID = 3040, ThreadID = 3088, StartAddress = 769AE43B, Parameter = 000ED3E8
- TargetProcess: taskkill.exe, InheritedFromPID = 2836, ProcessID = 3040, ThreadID = 3092, StartAddress = 77E56C7D, Parameter = 000EDBA0
- 行为描述: 杀掉进程
- 详情信息:
- TASKKILL = taskkill /f /t /im HipsTray.exe
- <b>文件行为</b>
- 行为描述: 创建文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\7.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.bat
- 行为描述: 创建可执行文件
- 详情信息:
- C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe
- C:\Documents and Settings\Administrator\桌面\funny.exe
- C:\Documents and Settings\Administrator\桌面\AD.exe
- C:\Documents and Settings\Administrator\桌面\Flash.exe
- C:\Documents and Settings\Administrator\桌面\Locks.exe
- 行为描述: 修改脚本文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.bat ---> Offset = 0
- 行为描述: 查找文件
- 详情信息:
- FileName = C:\DOCUME~1
- FileName = C:\DOCUME~1\ADMINI~1
- FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1
- FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
- FileName = C:\Documents and Settings
- FileName = C:\Documents and Settings\Administrator
- FileName = C:\Documents and Settings\Administrator\Local Settings
- FileName = C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe
- FileName = C:\WINDOWS
- FileName = C:\WINDOWS\system32
- FileName = C:\WINDOWS\system32\cmd.exe
- FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
- FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
- FileName = C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.bat
- FileName = C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp
- 行为描述: 删除文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.tmp
- 行为描述: 在桌面创建文件
- 详情信息:
- C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe
- C:\Documents and Settings\Administrator\桌面\funny.exe
- C:\Documents and Settings\Administrator\桌面\AD.exe
- C:\Documents and Settings\Administrator\桌面\Flash.exe
- C:\Documents and Settings\Administrator\桌面\Locks.exe
- 行为描述: 修改文件内容
- 详情信息:
- C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe ---> Offset = 0
- C:\Documents and Settings\Administrator\桌面\funny.exe ---> Offset = 0
- C:\Documents and Settings\Administrator\桌面\AD.exe ---> Offset = 0
- C:\Documents and Settings\Administrator\桌面\Flash.exe ---> Offset = 0
- C:\Documents and Settings\Administrator\桌面\Locks.exe ---> Offset = 0
- <b>其他行为</b>
- 行为描述: 创建互斥体
- 详情信息:
- CTF.LBES.MutexDefaultS-*
- CTF.Compart.MutexDefaultS-*
- CTF.Asm.MutexDefaultS-*
- CTF.Layouts.MutexDefaultS-*
- CTF.TMD.MutexDefaultS-*
- CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
- MSCTF.Shared.MUTEX.IOH
- MSCTF.Shared.MUTEX.IBL
- 行为描述: 创建事件对象
- 详情信息:
- EventName = DINPUTWINMM
- EventName = MSCTF.SendReceiveConection.Event.IBL.IC
- EventName = MSCTF.SendReceive.Event.IBL.IC
- 行为描述: 查找指定窗口
- 详情信息:
- NtUserFindWindowEx: [Class,Window] = [,]
- NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
- NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
- 行为描述: 打开事件
- 详情信息:
- HookSwitchHookEnabledEvent
- MSFT.VSA.COM.DISABLE.2868
- MSFT.VSA.IEC.STATUS.6c736db0
- MSFT.VSA.COM.DISABLE.3040
- _fCanRegisterWithShellService
- CTF.ThreadMIConnectionEvent.000007E8.00000000.0000000F
- CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.0000000F
- MSCTF.SendReceiveConection.Event.IOH.IC
- MSCTF.SendReceive.Event.IOH.IC
- 行为描述: 调整进程token权限
- 详情信息:
- SE_DEBUG_PRIVILEGE
- SE_SYSTEMTIME_PRIVILEGE
- SE_LOAD_DRIVER_PRIVILEGE
- 行为描述: 枚举窗口
- 详情信息:
- N/A
- 行为描述: 可执行文件签名信息
- 详情信息:
- C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe(签名验证: 未通过)
- C:\Documents and Settings\Administrator\桌面\funny.exe(签名验证: 未通过)
- C:\Documents and Settings\Administrator\桌面\AD.exe(签名验证: 未通过)
- C:\Documents and Settings\Administrator\桌面\Flash.exe(签名验证: 未通过)
- C:\Documents and Settings\Administrator\桌面\Locks.exe(签名验证: 未通过)
- 行为描述: 调用Sleep函数
- 详情信息:
- [1]: MilliSeconds = 10.
- [2]: MilliSeconds = 10.
- [3]: MilliSeconds = 10.
- [4]: MilliSeconds = 10.
- [5]: MilliSeconds = 10.
- [6]: MilliSeconds = 10.
- [7]: MilliSeconds = 10.
- [8]: MilliSeconds = 10.
- [9]: MilliSeconds = 10.
- [10]: MilliSeconds = 10.
- 行为描述: 可执行文件MD5
- 详情信息:
- C:\Documents and Settings\Administrator\桌面\AdobeFlashPlayer-part1.exe ---> 958f7260d707e8b3579407e0f9fb815c
- C:\Documents and Settings\Administrator\桌面\funny.exe ---> aafdf50e3fbcc3179033ee4fada60ef3
- C:\Documents and Settings\Administrator\桌面\AD.exe ---> fc9379011a041c2d2e1a6e43a211d9ab
- C:\Documents and Settings\Administrator\桌面\Flash.exe ---> 8333b26b25bdef985b56427ad3ad196d
- C:\Documents and Settings\Administrator\桌面\Locks.exe ---> 97240a4ed13a61469da8529136a419ac
- 行为描述: 打开互斥体
- 详情信息:
- ShimCacheMutex
- 行为描述: 样本控制台输出内容
- 详情信息:
- N/A
- 进程树
- ****.exe (PID: 0x00000ad8)
- cmd.exe cmd" /c "6.bat" ****.exe"" (PID: 0x00000b14)
- tasklist.exe (PID: 0x00000b34)
- findstr.exe (PID: 0x00000b3c)
- taskkill.exe (PID: 0x00000be0)
复制代码
|