又是易语言哎.....是个勒索么?
基本信息
文件名称:
Email_Tools_1.0.exe
MD5: 15426c7ef693c662375ef748e72079f7
文件类型: EXE
上传时间: 2019-09-06 19:18:03
出品公司: N/A
版本: 2.0.0.5---2.0.0.5
壳或编译器信息: COMPILER:Microsoft Visual C++ 6.0 [Overlay]
关键行为
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0x93fe0e15, EDX = 0x000000b4
EAX = 0x93fe0e61, EDX = 0x000000b4
EAX = 0x93fe0ead, EDX = 0x000000b4
EAX = 0x93fe0ef9, EDX = 0x000000b4
EAX = 0x93fe0f45, EDX = 0x000000b4
EAX = 0x93fe0f91, EDX = 0x000000b4
EAX = 0x93fe0fdd, EDX = 0x000000b4
EAX = 0x93fe1029, EDX = 0x000000b4
EAX = 0x93fe1075, EDX = 0x000000b4
EAX = 0x93fe10c1, EDX = 0x000000b4
行为描述: 获取TickCount值
详情信息:
TickCount = 241910, SleepMilliseconds = 20.
TickCount = 241941, SleepMilliseconds = 20.
文件行为
行为描述: 查找文件
详情信息:
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh-CN
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh-Hans
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.CHS
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.CH
其他行为
行为描述: 创建互斥体
详情信息:
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.IOH
MSCTF.Shared.MUTEX.MJJ
行为描述: 创建事件对象
详情信息:
EventName = Global\CnDebugFlushEvent
EventName = MSCTF.SendReceive.Event.MJJ.IC
EventName = MSCTF.SendReceiveConection.Event.MJJ.IC
行为描述: 打开互斥体
详情信息:
ShimCacheMutex
行为描述: 查找指定窗口
详情信息:
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
行为描述: 窗口信息
详情信息:
Pid = 2456, Hwnd=0x10348, Text = Cancel, ClassName = TButton.
Pid = 2456, Hwnd=0x10346, Text = OK, ClassName = TButton.
Pid = 2456, Hwnd=0x10342, Text = Exe Lock, ClassName = TFormPassDialog.
行为描述: 获取TickCount值
详情信息:
TickCount = 241910, SleepMilliseconds = 20.
TickCount = 241941, SleepMilliseconds = 20.
行为描述: 打开事件
详情信息:
HookSwitchHookEnabledEvent
CTF.ThreadMIConnectionEvent.000007E8.00000000.00000010
CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.00000010
MSCTF.SendReceiveConection.Event.IOH.IC
MSCTF.SendReceive.Event.IOH.IC
行为描述: 枚举窗口
详情信息:
N/A
行为描述: 调用Sleep函数
详情信息:
[1]: MilliSeconds = 20.
行为描述: 隐藏指定窗口
详情信息:
[Window,Class] = [Exe Lock,TFormPassDialog]
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0x93fe0e15, EDX = 0x000000b4
EAX = 0x93fe0e61, EDX = 0x000000b4
EAX = 0x93fe0ead, EDX = 0x000000b4
EAX = 0x93fe0ef9, EDX = 0x000000b4
EAX = 0x93fe0f45, EDX = 0x000000b4
EAX = 0x93fe0f91, EDX = 0x000000b4
EAX = 0x93fe0fdd, EDX = 0x000000b4
EAX = 0x93fe1029, EDX = 0x000000b4
EAX = 0x93fe1075, EDX = 0x000000b4
EAX = 0x93fe10c1, EDX = 0x000000b4
进程树
|