投放出一个二进制文件并执行它
binary: C:\Users\test\AppData\Local\Temp\zip-tmp\csrss.exe
魔盾安全Yara规则检测结果 - 安全告警
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
运行截图
投放文件
csrss.exe
文件名 |
csrss.exe |
相关文件 |
- C:\Users\test\AppData\Local\Temp\zip-tmp\csrss.exe
|
文件大小 |
7958528 bytes |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 |
3629f91e99639d11d0ba60ebf93053fc |
SHA1 |
c297e7b981ab98eda10ea43388ee950e3f753cee |
SHA256 |
536d64acfdf57d9456de9265ff5f6b5eb167d0f25cc193b3440d9d6b784d691a |
SHA512 |
b8dd507fcd4a2a537a3f1d13f96002502da369eb1e72ec291de5414c9e86d8d0252ed5e5740aa107601ffec5b5255ca813571af2a270b0b0f14419f2a2ae92fc |
Ssdeep |
98304:WlnuhTg6K+vqUyXHIPfneCnD74WtltJtz3UkwW1t79IzqhcFOU0gdU+bMIGaFmIy:WF7+iZX4neCH4OSkdBvU5d9pTy |
VirusTotal |
搜索相关分析 |