Informational: Possibly employs anti-virtualization techniques
Informational: Detect SMTP ability in RAW
Warning: Look for RijnDael AES
Critical: A non-Windows executable contains win32 API functions names
行为分析
互斥量(Mutexes)
- Local\ZoneAttributeCacheCounterMutex
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
- Local\MSCTF.Asm.MutexDefault1
执行的命令
- "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\test\AppData\Local\Temp\java
- C:\Users\test\AppData\Local\Temp\java
- C:\Windows\system32\svchost.exe -k netsvcs
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
- C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
- C:\Windows\system32\sppsvc.exe
创建的服务
无信息
进程
cmd.exe PID: 2612, 上一级进程 PID: 2272
services.exe PID: 424, 上一级进程 PID: 328
svchost.exe PID: 2124, 上一级进程 PID: 424
rundll32.exe PID: 2460, 上一级进程 PID: 2612
mscorsvw.exe PID: 2584, 上一级进程 PID: 424
mscorsvw.exe PID: 216, 上一级进程 PID: 424
读取的文件
- \Device\KsecDD
- C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
- C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000052.db
- C:\Users\test\Desktop\desktop.ini
- C:\
- C:\Users\desktop.ini
- C:\Users
- C:\Users\test
- C:\Users\test\Searches\desktop.ini
- C:\Users\test\Videos\desktop.ini
- C:\Users\test\Pictures\desktop.ini
- C:\Users\test\Contacts\desktop.ini
- C:\Users\test\Favorites\desktop.ini
- C:\Users\test\Music\desktop.ini
- C:\Users\test\Downloads\desktop.ini
- C:\Users\test\Documents\desktop.ini
- C:\Users\test\Links\desktop.ini
- C:\Users\test\Saved Games\desktop.ini
- C:\Windows\System32\shdocvw.dll
- C:\Windows\AppPatch\sysmain.sdb
- C:\Windows\System32\
- C:\Windows\System32\rundll32.exe
- C:\Windows\SysWOW64\cmd.exe
- C:\Windows\sysnative\LogFiles\Scm\da41de71-8431-42fb-9db0-eb64a961dead
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\appmgmt\S-1-5-21-2280033686-3172497658-3481507381-1000\AppMgmt.ini
- C:\Windows\System32\shell32.dll
- C:\Windows\System32\shell32.dll.123.Manifest
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\System32\EhStorShell.dll
- C:\Windows\System32\zh-CN\EhStorShell.dll.mui
- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
- C:\Program Files (x86)\Microsoft Office\Office14\
- C:\Program Files (x86)\Microsoft Office\Office14\2052\GrooveIntlResource.dll
- C:\Windows\System32\ntshrui.dll
- C:\Windows\System32\imageres.dll
- C:\Windows\System32\zh-CN\imageres.dll.mui
- C:\Windows\sysnative\zh-CN\imageres.dll.mui
- C:\Windows\System32\zh-Hans\imageres.dll.mui
- C:\Windows\System32\zh\imageres.dll.mui
- C:\Windows\System32\en-US\imageres.dll.mui
- C:\Program Files (x86)\desktop.ini
- C:\Program Files (x86)
- C:\Program Files (x86)\Adobe
- C:\Program Files (x86)\Adobe\Reader 11.0
- C:\Program Files (x86)\Adobe\Reader 11.0\Reader
- C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
- C:\Windows
- C:\Windows\ehome
- C:\Windows\ehome\ehshell.exe
- C:\Program Files (x86)\Internet Explorer
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- C:\Windows\System32
- C:\Windows\System32\mspaint.exe
- C:\Windows\System32\notepad.exe
- C:\Program Files (x86)\Microsoft Office
- C:\Program Files (x86)\Microsoft Office\Office14
- C:\Program Files (x86)\Microsoft Office\Office14\OIS.EXE
- C:\Program Files (x86)\Windows Photo Viewer
- C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll
- C:\Program Files (x86)\Windows Photo Viewer\zh-CN\PhotoViewer.dll.mui
- C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
- C:\Program Files (x86)\Windows Media Player
- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
- C:\Program Files (x86)\Windows NT
- C:\Program Files (x86)\Windows NT\Accessories
- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
- C:\program files (x86)\windows photo viewer\photoviewer.dll
- C:\program files (x86)\windows photo viewer\zh-CN\photoviewer.dll.mui
- C:\program files (x86)\Adobe\reader 11.0\Reader\AcroRd32.exe
修改的文件
- C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat
删除的文件
无信息
修改的注册表键
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE
删除的注册表键
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName