本帖最后由 驭龙 于 2025-5-8 00:50 编辑
我明天开老爷机在sandboxie外运行,看看,理论上我这边另一台实机也正常触发了DPH检测机制
刚刚翻一下日志,报的行为是: inject_to_process, drop_executable, modify_executable
id: 343959, timestamp: 07.05.2025 00:26:12.0849, type: PsDelete (17), flags: 1 (wait: 1)
sid: S-1-5-7, cid: 4136/6952:\Device\HarddiskVolume6\VIRUS\MM56\1111\1111.exe
context: start addr: 0x000000000021CFE0, image: 0x0000000000170000:\Device\HarddiskVolume6\VIRUS\MM56\1111\1111.exe
unique id: 4136-133910223549336324-1507328
behaviour: inject_to_process, drop_executable, modify_executable
terminated process: \Device\HarddiskVolume6\VIRUS\MM56\1111\1111.exe:4136
fileinfo: size: 147674239, easize: 220, attr: 0x20, buildtime: 29.04.2025 21:53:59.0000, ctime: 07.05.2025 00:24:24.0186, atime: 07.05.2025 00:25:49.0624, mtime: 30.06.2024 14:32:57.0000, descr: 368380 , ver: 10.450.238.751 , company: , oname: 368380
file sha1: b01f165b1800386cc1f3df896db86f6e3e88880c
file sha256: ced0f9f9470165dc989655a9790db067212c17eed251c0ac05ce354d4fcd930b
status: unsigned, pe32, new_pe, dfc / unsigned / unknown / unknown / unknown / unknown
id: 343959 ==> undefined [1], time: 0.279900 ms
|