行为分析
互斥量(Mutexes)
- Local\MSCTF.Asm.MutexDefault1
执行的命令
- C:\Windows\system32\svchost.exe -k netsvcs
- C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
创建的服务
无信息
启动的服务
无信息
进程
cmd.exe PID: 2308, 上一级进程 PID: 3008
services.exe PID: 456, 上一级进程 PID: 356
svchost.exe PID: 2860, 上一级进程 PID: 456
rundll32.exe PID: 1388, 上一级进程 PID: 2308
访问的文件
- C:\Windows\Temp
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
- C:\Windows\
- C:\Windows\ServiceProfiles
- C:\Windows\ServiceProfiles\
- C:\Windows\ServiceProfiles\LocalService
- C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
- C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
- C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
- C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
- C:\Windows\sysnative\LogFiles\Scm\5140dec0-8eab-4098-9657-106470a96f02
- C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
- C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
- C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
- C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
- C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
- C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
- C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
- C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
- C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
- \Device\KsecDD
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\appmgmt\S-1-5-21-2280033686-3172497658-3481507381-1000\AppMgmt.ini
- C:\Windows\System32\shell32.dll
- C:\Windows\System32\shell32.dll.manifest
- C:\Windows\System32\shell32.dll.123.Manifest
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Fonts\staticcache.dat
读取的文件
- C:\Windows\
- C:\Windows\ServiceProfiles\
- C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
- C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
- C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
- C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
- C:\Windows\sysnative\LogFiles\Scm\5140dec0-8eab-4098-9657-106470a96f02
- C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
- C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
- C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
- C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
- C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
- C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
- C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
- C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
- C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
- \Device\KsecDD
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\appmgmt\S-1-5-21-2280033686-3172497658-3481507381-1000\AppMgmt.ini
- C:\Windows\System32\shell32.dll
- C:\Windows\System32\shell32.dll.123.Manifest
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Fonts\staticcache.dat
修改的文件
无信息
删除的文件
无信息
修改的注册表键
无信息
删除的注册表键
无信息
API解析
- sspicli.dll.LogonUserExExW
- ole32.dll.CoInitializeEx
- cryptbase.dll.SystemFunction036
- ole32.dll.CoInitializeSecurity
- sechost.dll.LookupAccountNameLocalW
- advapi32.dll.LookupAccountSidW
- sechost.dll.LookupAccountSidLocalW
- ole32.dll.CoCreateInstance
- kernel32.dll.SortGetHandle
- kernel32.dll.SortCloseHandle
- appmgmts.dll.ServiceMain
- rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
- shell32.dll.OpenAs_RunDLLW
- uxtheme.dll.ThemeInitApiHook
- user32.dll.IsProcessDPIAware
- dwmapi.dll.DwmIsCompositionEnabled
- shell32.dll.#102
- propsys.dll.#430
- advapi32.dll.RegOpenKeyExW
- advapi32.dll.RegGetValueW
- advapi32.dll.RegCloseKey
- ole32.dll.CoTaskMemFree
- advapi32.dll.OpenThreadToken
- ole32.dll.CoTaskMemAlloc
- comctl32.dll.InitCommonControlsEx
- uxtheme.dll.EnableThemeDialogTexture
- uxtheme.dll.OpenThemeData
- uxtheme.dll.GetThemeBool
- gdi32.dll.GetLayout
- gdi32.dll.GdiRealizationInfo
- gdi32.dll.FontIsLinked
- advapi32.dll.RegQueryInfoKeyW
- gdi32.dll.GetTextFaceAliasW
- advapi32.dll.RegEnumValueW
- advapi32.dll.RegQueryValueExW
- advapi32.dll.RegQueryValueExA
- advapi32.dll.RegEnumKeyExW
- gdi32.dll.GdiIsMetaPrintDC
- ole32.dll.CoUninitialize
- ole32.dll.CoRegisterInitializeSpy
- ole32.dll.CoRevokeInitializeSpy
- gdi32.dll.GetTextExtentExPointWPri
- uxtheme.dll.BufferedPaintInit
- uxtheme.dll.BufferedPaintRenderAnimation
- uxtheme.dll.BeginBufferedAnimation
- uxtheme.dll.IsThemeBackgroundPartiallyTransparent
- uxtheme.dll.DrawThemeParentBackground
- uxtheme.dll.GetThemePartSize
- uxtheme.dll.DrawThemeBackground
- uxtheme.dll.GetThemeBackgroundContentRect
- uxtheme.dll.DrawThemeText
- uxtheme.dll.EndBufferedAnimation
- uxtheme.dll.GetThemeTransitionDuration
- oleaut32.dll.SysAllocString
- oleaut32.dll.SysStringLen
- oleaut32.dll.SysFreeString