HMPA kill。- Mitigation CryptoGuard
- Timestamp 2021-07-19T15:06:52
- Platform 6.1.7601/x64 v907 06_3d%
- PID 3780
- Application D:\$aa\1\Hive\Hive.exe
- Created 2021-07-19T15:06:39
- Description Hive.exe
- Filename D:\$aa\1\Hive\Hive.exe
- Detection Generic.Ransom.C
- 1*C:\Program Files\Common Files\Apple\Mobile Device Support\api-ms-win-core-console-l1-1-0.dll.5B9euTOJdoGAmjdOfX9zfQBSujLUB3U_jQvdbdtoNWQ.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\api-ms-win-core-console-l1-1-0.dll)
- Opened L19136, Read T17920|92% H16384|^102800, Write T17920|92% H16384|^263 #1,1
- 2*C:\Program Files\Common Files\Apple\Mobile Device Support\api-ms-win-core-datetime-l1-1-0.dll.5B9euTOJdoGAmjdOfX9zffIQ7oimL_VjKF8DKBLa-F4.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\api-ms-win-core-datetime-l1-1-0.dll)
- Opened L18624, Read T17920|94% H16384|^99361, Write T17920|94% H16384|^301 #2,2
- 3*C:\Program Files\Common Files\Apple\Mobile Device Support\YSUtilities.dll.5B9euTOJdoGAmjdOfX9zfX5DHTsF0wU64K6MszjuzQw.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\YSUtilities.dll)
- Opened L34616, Read T34816|100% H30920|^442688, Write T34816|100% H30920|^267 #3,3
- 4*C:\Program Files\Common Files\Apple\Mobile Device Support\OutlookChangeNotifierAddIn.dll.5B9euTOJdoGAmjdOfX9zfWc6aKX8WREWjF__U9muYyw.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\OutlookChangeNotifierAddIn.dll)
- Opened L261432, Read T82432|31% H10686|^184007, Write T82432|31% H10686|^261 #5,5
- 5 C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.sys.5B9euTOJdoGAmjdOfX9zfanDN5AvcFQCACVCWA9TexY.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.sys)
- Opened L23040, Read T22016|95% H20480|^592610, Write T22016|95% H20480|^219 #6,6
- 6 C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.cat.5B9euTOJdoGAmjdOfX9zfZuUGsj5MPEaB6zzt6b6rFQ.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.cat)
- Opened L14353, Read T13312|89% H12288|^130846, Write T13312|89% H12288|^252 #8,8
- 7 C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.sys.5B9euTOJdoGAmjdOfX9zfeN4KzVVr51cviElKfla-GE.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.sys)
- Opened L54784, Read T54784|100% H31872|^332263, Write T54784|100% H31872|^227 #9,9
- 8 C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaaplrc.dll.5B9euTOJdoGAmjdOfX9zfSC5r_N-W39u3q3uJiDm8Dk.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaaplrc.dll)
- Opened L6112072, Read T160768|2% H8192, Write T156160|2% H8192 #10
- 9 C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\WdfCoInstaller01009.dll.5B9euTOJdoGAmjdOfX9zfcXDyyCKPhA7GlkqcmAUVT0.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\WdfCoInstaller01009.dll)
- Opened L1721576, Read T174592|10% H8192, Write T174592|10% H8192 #11
- 10 C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.cat.5B9euTOJdoGAmjdOfX9zfZYLTGt3jWQcSkdvtf6ben0.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.cat)
- Opened L10247, Read T8704|80% H8192|^55861, Write T8704|80% H8192|^212 #12,12
- 11 C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.inf.5B9euTOJdoGAmjdOfX9zfeH5R9c1veJr8guAQuf0Bjg.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.inf)
- Opened L4215, Read T4608|100% H4215|^38415, Write T4608|100% H4215|^255 #13,13
- 12 C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.inf.5B9euTOJdoGAmjdOfX9zfVsF7aEjZhQLgXrN03eB0jk.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.inf)
- Opened L5729, Read T6144|100% H5729|^34761, Write T6144|100% H5729|^231 #14,14
- 13 C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\zh_CN.lproj\Error.strings.5B9euTOJdoGAmjdOfX9zfY8x9Hbta-0LNo7t1m1SeQQ.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\zh_CN.lproj\Error.strings)
- Opened L6700, Read T7168|100% H6700|^357242, Write T7168|100% H6700|^267 #15,15
- 14 C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\zh_TW.lproj\Error.strings.5B9euTOJdoGAmjdOfX9zfbH4Hh6CrQUpjqLIrx93QxE.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\zh_TW.lproj\Error.strings)
- Opened L6644, Read T6656|100% H6644|^359995, Write T6656|100% H6644|^259 #16,16
- 15 C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\vi.lproj\Error.strings.5B9euTOJdoGAmjdOfX9zfUp1tqORf-IoMplol4VEUy4.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\vi.lproj\Error.strings)
- Opened L7810, Read T8192|100% H7810|^479668, Write T8192|100% H7810|^259 #17,17
- 16 C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\tr.lproj\Error.strings.5B9euTOJdoGAmjdOfX9zfW6PCeouR80jgziJy7TsSBs.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\CoreFoundation.resources\tr.lproj\Error.strings)
- Opened L8032, Read T8192|100% H8032|^508045, Write T8192|100% H8032|^235 #18,18
- 87*C:\Program Files\Common Files\Apple\Mobile Device Support\AirTrafficHost.dll.5B9euTOJdoGAmjdOfX9zfWhg6mCDzId9b8G5JqgI_wA.hive (C:\Program Files\Common Files\Apple\Mobile Device Support\AirTrafficHost.dll)
- Opened L313144, Read T100864|32% H11528|^60796, Write T100864|32% H11528|^263 #96,96
- Dropped Files
- 1 C:\5B9euTOJdoGAmjdOfX9zfQ.key.hive
- Dropped by \Device\HarddiskVolume2\$aa\1\Hive\Hive.exe [3780]
- 2 D:\5B9euTOJdoGAmjdOfX9zfQ.key.hive
- Dropped by \Device\HarddiskVolume2\$aa\1\Hive\Hive.exe [3780]
- 3 D:\$aa\1\Hive\hive.bat
- Dropped by \Device\HarddiskVolume2\$aa\1\Hive\Hive.exe [3780]
- 4 D:\$aa\1\Hive\shadow.bat
- Dropped by \Device\HarddiskVolume2\$aa\1\Hive\Hive.exe [3780]
- 5 C:\HOW_TO_DECRYPT.txt
- Dropped by \Device\HarddiskVolume2\$aa\1\Hive\Hive.exe [3780]
- 6 D:\HOW_TO_DECRYPT.txt
- Dropped by \Device\HarddiskVolume2\$aa\1\Hive\Hive.exe [3780]
- Thumbprints
- 5867c60d5c95a00fdd4c85331835e869ad2ac503bdf15b32060a5a63365d9e07 (FLD1)
- 33eec0d678abdd37caced822278c662c3496b683287aee887b92f932995e2676 (FLD2)
- a0db0f7f9745cf549bc85b8999b9ddb50aa534ad9bfc2768388f601ff611f92f (SIG)
- 0a89bb174ad410f8c1acc87bb576b0ce80159ca0436cd8394a87ae107daf2df8
复制代码 |