行为分析
互斥量(Mutexes)
- Local\MSCTF.Asm.MutexDefault1
执行的命令
- C:\Windows\system32\svchost.exe -k netsvcs
创建的服务
无信息
启动的服务
无信息
进程
cmd.exe PID: 1396, 上一级进程 PID: 1468
services.exe PID: 452, 上一级进程 PID: 356
svchost.exe PID: 1484, 上一级进程 PID: 452
rundll32.exe PID: 1048, 上一级进程 PID: 1396
访问的文件
- C:\Windows\Temp
- \Device\KsecDD
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\appmgmt\S-1-5-21-2280033686-3172497658-3481507381-1000\AppMgmt.ini
- C:\Windows\System32\shell32.dll
- C:\Windows\System32\shell32.dll.manifest
- C:\Windows\System32\shell32.dll.123.Manifest
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Fonts\staticcache.dat
读取的文件
- \Device\KsecDD
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\appmgmt\S-1-5-21-2280033686-3172497658-3481507381-1000\AppMgmt.ini
- C:\Windows\System32\shell32.dll
- C:\Windows\System32\shell32.dll.123.Manifest
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Fonts\staticcache.dat
修改的文件
无信息
删除的文件
无信息
修改的注册表键
无信息
删除的注册表键
无信息
API解析
- ole32.dll.CoInitializeEx
- cryptbase.dll.SystemFunction036
- ole32.dll.CoInitializeSecurity
- sechost.dll.LookupAccountNameLocalW
- advapi32.dll.LookupAccountSidW
- sechost.dll.LookupAccountSidLocalW
- ole32.dll.CoCreateInstance
- kernel32.dll.SortGetHandle
- kernel32.dll.SortCloseHandle
- appmgmts.dll.ServiceMain
- rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
- shell32.dll.OpenAs_RunDLLW
- uxtheme.dll.ThemeInitApiHook
- user32.dll.IsProcessDPIAware
- dwmapi.dll.DwmIsCompositionEnabled
- shell32.dll.#102
- propsys.dll.#430
- advapi32.dll.RegOpenKeyExW
- advapi32.dll.RegGetValueW
- advapi32.dll.RegCloseKey
- ole32.dll.CoTaskMemFree
- advapi32.dll.OpenThreadToken
- ole32.dll.CoTaskMemAlloc
- comctl32.dll.InitCommonControlsEx
- uxtheme.dll.EnableThemeDialogTexture
- uxtheme.dll.OpenThemeData
- uxtheme.dll.GetThemeBool
- gdi32.dll.GetLayout
- gdi32.dll.GdiRealizationInfo
- gdi32.dll.FontIsLinked
- advapi32.dll.RegQueryInfoKeyW
- gdi32.dll.GetTextFaceAliasW
- advapi32.dll.RegEnumValueW
- advapi32.dll.RegQueryValueExW
- advapi32.dll.RegQueryValueExA
- advapi32.dll.RegEnumKeyExW
- gdi32.dll.GdiIsMetaPrintDC
- ole32.dll.CoUninitialize
- ole32.dll.CoRegisterInitializeSpy
- ole32.dll.CoRevokeInitializeSpy
- gdi32.dll.GetTextExtentExPointWPri
- uxtheme.dll.BufferedPaintInit
- uxtheme.dll.BufferedPaintRenderAnimation
- uxtheme.dll.BeginBufferedAnimation
- uxtheme.dll.IsThemeBackgroundPartiallyTransparent
- uxtheme.dll.DrawThemeParentBackground
- uxtheme.dll.GetThemePartSize
- uxtheme.dll.DrawThemeBackground
- uxtheme.dll.GetThemeBackgroundContentRect
- uxtheme.dll.DrawThemeText
- uxtheme.dll.EndBufferedAnimation
- uxtheme.dll.GetThemeTransitionDuration
- oleaut32.dll.SysAllocString
- oleaut32.dll.SysStringLen
- oleaut32.dll.SysFreeString