Informational: Possibly employs anti-virtualization techniques
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
Informational: Detected Overlay signature
Informational: Detected Taggant Signature
尝试断开连接或更改沙箱进程监控的Windows功能
unhook: function_name: SetWindowLongA, type: modification
unhook: function_name: SetWindowLongW, type: modification
运行截图
投放文件
\xc8\xab\xcf\xb5\xcd\xb3Rez\xcd\xa8\xd3\xc3\xd6\xc6\xd7\xf7_se.exe
文件名 |
\xc8\xab\xcf\xb5\xcd\xb3Rez\xcd\xa8\xd3\xc3\xd6\xc6\xd7\xf7_se.exe |
相关文件 |
- C:\Users\test\AppData\Local\Temp\zip-tmp\\xe5\x85\xa8\xe7\xb3\xbb\xe7\xbb\x9fRez\xe9\x80\x9a\xe7\x94\xa8\xe5\x88\xb6\xe4\xbd\x9c_se.exe
|
文件大小 |
3796992 bytes |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 |
49a9dc4633b670d5fab902ef83be6394 |
SHA1 |
b0aa4a230fcaf553671181145d1d0bd4c6d07995 |
SHA256 |
47507f348c0ef1cf6aa47929936b1b0d7dd2acdefb7ccf41c98e9924eda0bba3 |
SHA512 |
3fd0398228e05067d395ba3b28aa9990712eed65cbe786a0420bc564eccd10f4d0b9d2b699517dbe7a41551645c6c7c7bda212b576e3c28f1b95f16754a63f6b |
Ssdeep |
98304:GZ8rvh9l0iQeYrcliqtpQQ3ID6sh523h4KpC2c81KuHedpvPOOp:YUecliqttItXW7M8DHedpHOOp |
VirusTotal |
搜索相关分析 |