本帖最后由 cect258 于 2018-9-25 20:57 编辑
关键行为
行为描述: 跨进程写入数据
详情信息:
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000438
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000438
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x7ffd4238, Size = 0x00000004 TargetPID = 0x00000438
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050000, Size = 0x00000020 TargetPID = 0x00000b40
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x00050020, Size = 0x00000034 TargetPID = 0x00000b40
TargetProcess = C:\Windows\System32\cmd.exe, WriteAddress = 0x7ffdf238, Size = 0x00000004 TargetPID = 0x00000b40
TargetProcess = C:\Windows\System32\%temp%\****.exe, WriteAddress = 0x00040000, Size = 0x00000020 TargetPID = 0x00000c58
TargetProcess = C:\Windows\System32\%temp%\****.exe, WriteAddress = 0x00040020, Size = 0x00000034 TargetPID = 0x00000c58
TargetProcess = C:\Windows\System32\%temp%\****.exe, WriteAddress = 0x7ffdc238, Size = 0x00000004 TargetPID = 0x00000c58
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0xc8807d77, EDX = 0x0000039e
EAX = 0xc8807dc3, EDX = 0x0000039e
EAX = 0xcb337d3f, EDX = 0x0000039e
EAX = 0xcb337d8b, EDX = 0x0000039e
EAX = 0xeabf8458, EDX = 0x0000039e
EAX = 0xf7e820ae, EDX = 0x0000039e
EAX = 0x2f3d9052, EDX = 0x0000039f
EAX = 0x2f3d909e, EDX = 0x0000039f
EAX = 0x3f192c24, EDX = 0x0000039f
EAX = 0x3f192c70, EDX = 0x0000039f
行为描述: 获取TickCount值
详情信息:
TickCount = 1110251, SleepMilliseconds = 1.
TickCount = 1110266, SleepMilliseconds = 1.
TickCount = 1110376, SleepMilliseconds = 1.
TickCount = 1110501, SleepMilliseconds = 1.
TickCount = 1110626, SleepMilliseconds = 1.
TickCount = 1110751, SleepMilliseconds = 1.
TickCount = 1110922, SleepMilliseconds = 1.
TickCount = 1111047, SleepMilliseconds = 1.
TickCount = 1111172, SleepMilliseconds = 1.
TickCount = 1111297, SleepMilliseconds = 1.
TickCount = 1111422, SleepMilliseconds = 1.
TickCount = 1111547, SleepMilliseconds = 1.
TickCount = 1111672, SleepMilliseconds = 1.
TickCount = 1111797, SleepMilliseconds = 1.
TickCount = 1111922, SleepMilliseconds = 1.
|