
- 文件检测评级:
- 高度风险
- 文件名称: ABC.exe
- 基本信息
- 文件名称:
- ABC.exe
- MD5: de07473a624179e027a4e4cae93e2f82
- 文件类型: EXE
- 上传时间: 2018-10-01 21:28:30
- 出品公司: N/A
- 版本: 1.0.0.0
- 壳或编译器信息: PACKER:UPX V2.00-V3.00 -> Markus Oberhumer & Laszlo Molnar & John Reiser [Overlay] *
- 子文件信息: 详情
- 关键行为
- 行为描述: 修改用户密码
- 详情信息:
- ImagePath = , CmdLine = cmd.exe /c net user %username% "
- ImagePath = , CmdLine = cmd.exe /c net user %username% XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXIXXXXXXXXXXXXXXXJKLJKLJLKJLJKLXJKLJXKLXJKLJDGJDKSLHGSDKHGLSDKLSDGHJHKLDSJHLK;DSJHKLHJDSHLKKLtaiwan
- 行为描述: 设置特殊文件夹属性
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
- C:\Documents and Settings\Administrator\Local Settings\History
- C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
- C:\Documents and Settings\Administrator\Cookies
- 行为描述: 查找PE资源信息
- 详情信息:
- (FindResourceA) hModule = 0x00400000, ResName: F, ResType:
- 行为描述: 获取TickCount值
- 详情信息:
- TickCount = 285515, SleepMilliseconds = 60000.
- TickCount = 285546, SleepMilliseconds = 60000.
- TickCount = 285562, SleepMilliseconds = 60000.
- TickCount = 285578, SleepMilliseconds = 60000.
- TickCount = 285625, SleepMilliseconds = 60000.
- TickCount = 285656, SleepMilliseconds = 60000.
- TickCount = 285640, SleepMilliseconds = 60000.
- TickCount = 285671, SleepMilliseconds = 60000.
- TickCount = 285703, SleepMilliseconds = 60000.
- TickCount = 285718, SleepMilliseconds = 60000.
- TickCount = 285750, SleepMilliseconds = 60000.
- TickCount = 285765, SleepMilliseconds = 60000.
- TickCount = 285781, SleepMilliseconds = 60000.
- TickCount = 285796, SleepMilliseconds = 60000.
- TickCount = 285812, SleepMilliseconds = 60000.
- 进程行为
- 行为描述: 隐藏窗口创建进程
- 详情信息:
- ImagePath = , CmdLine = "C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp\ABC.bat" "C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe"
- ImagePath = , CmdLine = cmd.exe /c net user %username% "
- 行为描述: 创建进程
- 详情信息:
- [0x00000bc4]ImagePath = C:\WINDOWS\system32\cmd.exe, CmdLine = cmd /c ""C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp\ABC.bat" "C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe""
- 行为描述: 创建本地线程
- 详情信息:
- TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2904, ThreadID = 3008, StartAddress = 765E964D, Parameter = 001C6550
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3028, StartAddress = 77C0A341, Parameter = 003FCC68
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3032, StartAddress = 77C0A341, Parameter = 003FCC68
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3048, StartAddress = 071238B3, Parameter = 012E0828
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3052, StartAddress = 071238B3, Parameter = 012E0978
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3056, StartAddress = 071238B3, Parameter = 012E0AC8
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3060, StartAddress = 071238B3, Parameter = 012E0C18
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3064, StartAddress = 071238B3, Parameter = 012E0DB0
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3068, StartAddress = 071238B3, Parameter = 012E0F00
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3084, StartAddress = 7C947EBB, Parameter = 00000000
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3088, StartAddress = 7C93059A, Parameter = 001FC250
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3092, StartAddress = 7C949B6F, Parameter = 00000000
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3096, StartAddress = 77DC845A, Parameter = 00000000
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3100, StartAddress = 77E56C7D, Parameter = 0023DD20
- TargetProcess: A.exe, InheritedFromPID = 3012, ProcessID = 3020, ThreadID = 3104, StartAddress = 769AE43B, Parameter = 001FC4B0
- 行为描述: 创建新文件进程
- 详情信息:
- [0x00000bcc]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = .\A.EXE
- [0x00000c30]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000c78]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000c9c]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000d4c]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000da8]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000e18]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000e6c]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000eac]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000ed8]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- [0x00000f20]ImagePath = C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe, CmdLine = A.exe /K
- 文件行为
- 行为描述: 创建文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp
- C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp\ABC.bat
- C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe
- C:\Documents and Settings\Administrator\Local Settings\%temp%\USA.mp3
- C:\Documents and Settings\Administrator\Local Settings\Temp\9.tmp
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML.bak
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML.done
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
- 行为描述: 创建可执行文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe
- 行为描述: 修改脚本文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp\ABC.bat ---> Offset = 0
- 行为描述: 覆盖已有文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML
- 行为描述: 复制文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML.bak ---> C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML
- 行为描述: 删除文件
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML.done
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML.bak
- 行为描述: 查找文件
- 详情信息:
- FileName = C:\DOCUME~1
- FileName = C:\DOCUME~1\ADMINI~1
- FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1
- FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
- FileName = C:\Documents and Settings
- FileName = C:\Documents and Settings\Administrator
- FileName = C:\Documents and Settings\Administrator\Local Settings
- FileName = C:\Documents and Settings\Administrator\My Documents
- FileName = C:\Documents and Settings\All Users
- FileName = C:\Documents and Settings\All Users\Documents
- FileName = C:\Documents and Settings\Administrator\桌面
- FileName = C:\Documents and Settings\All Users\桌面
- FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
- FileName = C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp
- FileName = C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp\ABC.bat
- 行为描述: 设置特殊文件夹属性
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
- C:\Documents and Settings\Administrator\Local Settings\History
- C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
- C:\Documents and Settings\Administrator\Cookies
- 行为描述: 修改文件内容
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe ---> Offset = 0
- C:\Documents and Settings\Administrator\Local Settings\%temp%\USA.mp3 ---> Offset = 0
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML.bak ---> Offset = 0
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML ---> Offset = 0
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML ---> Offset = 0
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML ---> Offset = 38
- 注册表行为
- 行为描述: 修改注册表
- 详情信息:
- \REGISTRY\USER\S-*\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\Administrator\Local Settings\Temp\8.tmp\ABC.bat
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\General\UniqueID
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\General\ComputerName
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\Namespace\LocalBase
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\Namespace\DTDFile
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\Namespace\LocalDelta
- \REGISTRY\USER\S-*\Software\Microsoft\Windows Media\WMSDK\Namespace\RemoteDelta
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMS\ProxyStyle
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMS\ProxyName
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMS\ProxyPort
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMS\ProxyBypass
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMS\ProxyExclude
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP\ProxyStyle
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP\ProxyName
- 行为描述: 删除注册表键值
- 详情信息:
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
- \REGISTRY\USER\S-*\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache\1
- 行为描述: 删除注册表键
- 详情信息:
- \REGISTRY\USER\S-*\Software\Microsoft\MediaPlayer\Health\{B379A02E-86A5-46CF-959C-F760BC09D4CF}\
- 其他行为
- 行为描述: 调整进程token权限
- 详情信息:
- SE_LOAD_DRIVER_PRIVILEGE
- 行为描述: 创建互斥体
- 详情信息:
- CTF.LBES.MutexDefaultS-*
- CTF.Compart.MutexDefaultS-*
- CTF.Asm.MutexDefaultS-*
- CTF.Layouts.MutexDefaultS-*
- CTF.TMD.MutexDefaultS-*
- CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
- Local\ZonesCounterMutex
- Local\ZoneAttributeCacheCounterMutex
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
- AMResourceMutex2
- VideoRenderer
- eed3bd3a-a1ad-4e99-987b-d7cb3fcfa7f0 - S-*
- MSCTF.Shared.MUTEX.IOH
- 行为描述: 创建事件对象
- 详情信息:
- EventName = DINPUTWINMM
- EventName = Global\crypt32LogoffEvent
- EventName = {D6D6C847-CA28-498A-850E-52AB4128FCB6}
- EventName = {31535143-948E-4B30-A155-CBCA4E220EEC}
- EventName = {2E9227F1-A1A4-443A-B9C9-455BEED49F98}
- EventName = {C75381F3-1028-40FF-998A-649BF0EBA4F8}
- EventName = {FB3BF503-72D7-4A9A-84E5-8988946BCB21}
- EventName = {75E2C828-51A0-4EF7-AEFF-51CBFEC1F59F}
- EventName = {7294D2F7-684A-494A-8D3C-27D9E9179EFD}
- EventName = {61FA50B2-DD2B-47F5-8EBC-047AD4F0C35B}
- EventName = {9CB90512-E42C-4AF7-BC5C-09149E86BFE0}
- EventName = {74EBE5CE-29E4-408E-972D-BFD22917D57E}
- EventName = {B379A02E-86A5-46CF-959C-F760BC09D4CF}
- 行为描述: 查找指定窗口
- 详情信息:
- NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
- 行为描述: 隐藏指定窗口
- 详情信息:
- [Window,Class] = [工程1,ThunderRT6Main]
- [Window,Class] = [Form1,ThunderRT6FormDC]
- 行为描述: 打开事件
- 详情信息:
- HookSwitchHookEnabledEvent
- _fCanRegisterWithShellService
- \SECURITY\LSA_AUTHENTICATION_INITIALIZED
- Global\crypt32LogoffEvent
- WMPPERF_APP_END_OF_LAUNCH
- MSFT.VSA.COM.DISABLE.3020
- MSFT.VSA.IEC.STATUS.6c736db0
- {D6D6C847-CA28-498A-850E-52AB4128FCB6}
- MSFT.VSA.COM.DISABLE.3120
- {31535143-948E-4B30-A155-CBCA4E220EEC}
- MSFT.VSA.COM.DISABLE.3192
- {2E9227F1-A1A4-443A-B9C9-455BEED49F98}
- MSFT.VSA.COM.DISABLE.3228
- Global\SvcctrlStartEvent_A3752DX
- {C75381F3-1028-40FF-998A-649BF0EBA4F8}
- 行为描述: 获取TickCount值
- 详情信息:
- TickCount = 285515, SleepMilliseconds = 60000.
- TickCount = 285546, SleepMilliseconds = 60000.
- TickCount = 285562, SleepMilliseconds = 60000.
- TickCount = 285578, SleepMilliseconds = 60000.
- TickCount = 285625, SleepMilliseconds = 60000.
- TickCount = 285656, SleepMilliseconds = 60000.
- TickCount = 285640, SleepMilliseconds = 60000.
- TickCount = 285671, SleepMilliseconds = 60000.
- TickCount = 285703, SleepMilliseconds = 60000.
- TickCount = 285718, SleepMilliseconds = 60000.
- TickCount = 285750, SleepMilliseconds = 60000.
- TickCount = 285765, SleepMilliseconds = 60000.
- TickCount = 285781, SleepMilliseconds = 60000.
- TickCount = 285796, SleepMilliseconds = 60000.
- TickCount = 285812, SleepMilliseconds = 60000.
- 行为描述: 获取光标位置
- 详情信息:
- CursorPos = (80,18468), SleepMilliseconds = 60000.
- CursorPos = (6373,26501), SleepMilliseconds = 60000.
- CursorPos = (19208,15725), SleepMilliseconds = 60000.
- CursorPos = (11517,29359), SleepMilliseconds = 60000.
- CursorPos = (27001,24465), SleepMilliseconds = 60000.
- CursorPos = (5744,28146), SleepMilliseconds = 60000.
- CursorPos = (23320,16828), SleepMilliseconds = 60000.
- CursorPos = (10000,492), SleepMilliseconds = 60000.
- CursorPos = (3034,11943), SleepMilliseconds = 60000.
- CursorPos = (4866,5437), SleepMilliseconds = 60000.
- CursorPos = (32430,14605), SleepMilliseconds = 60000.
- CursorPos = (3941,154), SleepMilliseconds = 60000.
- CursorPos = (331,12383), SleepMilliseconds = 60000.
- CursorPos = (17460,18717), SleepMilliseconds = 60000.
- CursorPos = (19757,19896), SleepMilliseconds = 60000.
- 行为描述: 窗口信息
- 详情信息:
- Pid = 3872, Hwnd=0x3051a, Text = 确定, ClassName = Button.
- Pid = 3872, Hwnd=0x20528, Text = Run-time error "5": Invalid procedure call or argument, ClassName = Static.
- Pid = 3872, Hwnd=0x404de, Text = 工程1, ClassName = #32770.
- 行为描述: 查找PE资源信息
- 详情信息:
- (FindResourceA) hModule = 0x00400000, ResName: F, ResType:
- 行为描述: 可执行文件签名信息
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe(签名验证: 未通过)
- 行为描述: 调用Sleep函数
- 详情信息:
- [1]: MilliSeconds = 25.
- [2]: MilliSeconds = 25.
- [3]: MilliSeconds = 25.
- [4]: MilliSeconds = 25.
- [5]: MilliSeconds = 25.
- [6]: MilliSeconds = 25.
- [7]: MilliSeconds = 25.
- [8]: MilliSeconds = 25.
- [9]: MilliSeconds = 25.
- [10]: MilliSeconds = 25.
- [1]: MilliSeconds = 60000.
- [2]: MilliSeconds = 0.
- [3]: MilliSeconds = 0.
- [4]: MilliSeconds = 250.
- 行为描述: 修改用户密码
- 详情信息:
- ImagePath = , CmdLine = cmd.exe /c net user %username% "
- ImagePath = , CmdLine = cmd.exe /c net user %username% XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXIXXXXXXXXXXXXXXXJKLJKLJLKJLJKLXJKLJXKLXJKLJDGJDKSLHGSDKHGLSDKLSDGHJHKLDSJHLK;DSJHKLHJDSHLKKLtaiwan
- 行为描述: 可执行文件MD5
- 详情信息:
- C:\Documents and Settings\Administrator\Local Settings\%temp%\A.exe ---> 241979930dd9495293352954e25b2bbc
- 行为描述: 打开互斥体
- 详情信息:
- ShimCacheMutex
- Local\!IETld!Mutex
- MutexToProtectNamespace
- Local\_!MSFTHISTORY!_
- Local\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
- Local\c:!documents and settings!administrator!cookies!
- Local\c:!documents and settings!administrator!local settings!history!history.ie5!
- 进程树
- ****.exe (PID: 0x00000b58)
- -cmd.exe (PID: 0x00000bc4)
- --a.exe (PID: 0x00000bcc)
复制代码
|