self_read: process: FD0EFF5D.exe, pid: 2808, offset: 0x00000000, length: 0x000a1000
get_no_useragent: HTTP traffic contains a GET request with no user-agent header
suspicious_request: http://www.suyx.net/war3/download/getupdate.ashx?l=1
suspicious_request: http://www.suyx.net/war3/download/README.md
样本投放可执行文件到临时目录然后抹除
Anomaly: C:\Users\test\AppData\Local\Temp\SuWar3Tools.exe deleted
魔盾安全Yara规则检测结果 - 高危
Warning: Detected code injection function with CreateRemoteThread in a remote process
已存在的系统二进制文件可能被病毒感染
file: c:\users\test\appdata\local\temp\suwar3tools.exe
运行截图
网络分析
访问主机记录
直接访问 |
IP地址 |
国家名 |
否 |
119.28.77.158 |
China |
否 |
139.129.143.197 |
China |
否 |
20.205.243.166 |
United States |
域名解析
域名 |
响应 |
www.suyx.net |
A 139.129.143.197
|
github.com |
A 20.205.243.166
|
visitor-badge.laobi.icu |
A 119.28.77.158
|
TCP连接
IP地址 |
端口 |
119.28.77.158 |
443 |
139.129.143.197 |
80 |
20.205.243.166 |
443 |
23.67.75.120 |
80 |
UDP连接
IP地址 |
端口 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
HTTP请求
URL |
HTTP数据 |
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip |
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache
|
http://www.suyx.net/war3/download/getupdate.ashx?l=1 |
GET /war3/download/getupdate.ashx?l=1 HTTP/1.1
Host: www.suyx.net
Connection: Keep-Alive
|
http://www.suyx.net/war3/download/README.md |
GET /war3/download/README.md HTTP/1.1
Host: www.suyx.net
|
静态分析
版本信息
Translation: |
0x0000 0x04b0 |
LegalCopyright: |
Copyright \xc2 2022 |
Assembly Version: |
1.0.0.0 |
InternalName: |
SuWar3Tools.exe |
FileVersion: |
1.0.0.0 |
CompanyName: |
|
LegalTrademarks: |
|
Comments: |
|
ProductName: |
|
ProductVersion: |
1.0.0.0 |
FileDescription: |
|
OriginalFilename: |
SuWar3Tools.exe |
PE数据组成
名称 |
虚拟地址 |
虚拟大小 |
原始数据大小 |
特征 |
熵(Entropy) |
.text |
0x00002000 |
0x0009b774 |
0x0009b800 |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ |
6.08 |
.rsrc |
0x0009e000 |
0x0000535c |
0x00005400 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ |
6.11 |
.reloc |
0x000a4000 |
0x0000000c |
0x00000200 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ |
0.10 |
资源
名称 |
偏移量 |
大小 |
语言 |
子语言 |
熵(Entropy) |
文件类型 |
RT_ICON |
0x0009e100 |
0x00004228 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.86 |
dBase III DBT, version number 0, next free block index 40 |
RT_GROUP_ICON |
0x000a2338 |
0x00000014 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
1.92 |
MS Windows icon resource - 1 icon, 64x64 |
RT_VERSION |
0x000a235c |
0x00000304 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.25 |
data |
RT_MANIFEST |
0x000a2670 |
0x00000ce8 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.90 |
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
导入
库 mscoree.dll:
• 0x402000 - _CorExeMain
行为分析
互斥量(Mutexes)
- 84C97AE0
- Local\MSCTF.Asm.MutexDefault1
执行的命令
- C:\Users\test\AppData\Local\Temp\FD0EFF5D.exe "renamed" "SuWar3Tools.exe"
创建的服务
无信息
启动的服务
无信息
进程
SuWar3Tools.exe PID: 2644, 上一级进程 PID: 2316
FD0EFF5D.exe PID: 2808, 上一级进程 PID: 2644
读取的文件
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
- C:\Users\test\AppData\Local\Temp\SuWar3Tools.exe.config
- C:\Users\test\AppData\Local\Temp\SuWar3Tools.exe
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
- C:\Windows\System32\MSVCR120_CLR0400.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dll
- \Device\KsecDD
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
- C:\Windows\assembly\pubpol49.dat
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\fb06ad4bc55b9c3ca68a3f9259d826cd\System.Windows.Forms.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\1be7a15b1f33bf22e4f53aaf45518c77\System.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\1be7a15b1f33bf22e4f53aaf45518c77\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\1d52bd4ac5e0a6422058a5d62c9f6d9d\System.Drawing.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\1d52bd4ac5e0a6422058a5d62c9f6d9d\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\fb06ad4bc55b9c3ca68a3f9259d826cd\System.Windows.Forms.ni.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
- C:\Windows\System32\tzres.dll
- C:\Users\test\AppData\Local\Temp\FD0EFF5D.exe
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\eb4cca4f06a15158c3f7e2c56516729b\System.Core.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\eb4cca4f06a15158c3f7e2c56516729b\System.Core.ni.dll
- C:\Users\test\AppData\Local\Temp\FD0EFF5D.exe.config
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\mscorlib.resources.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
- C:\Users\test\AppData\Local\GDIPFONTCACHEV1.DAT
- C:\Windows\Fonts\simsun.ttc
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.Windows.Forms.resources.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\fe4b221b4109f0c78f57a792500699b5\System.Configuration.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\fe4b221b4109f0c78f57a792500699b5\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\4fbda26d781323081b45526da6e87b35\System.Xml.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\4fbda26d781323081b45526da6e87b35\System.Xml.ni.dll
- C:\Windows\Fonts\msyh.ttf
- C:\Windows\Fonts\msyhbd.ttf
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\6e322d1b2e3358fa90494bffbe32cbf2\System.Data.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\6e322d1b2e3358fa90494bffbe32cbf2\System.Data.ni.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll.config
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\d3d95e1e349be37505587e7fee918881\System.Numerics.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\d3d95e1e349be37505587e7fee918881\System.Numerics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\9b0d0cb232dec8e57df49678532cb923\System.Runtime.Serialization.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\9b0d0cb232dec8e57df49678532cb923\System.Runtime.Serialization.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\cde471ea4f02c36c73581ed5681e463e\SMDiagnostics.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\cde471ea4f02c36c73581ed5681e463e\SMDiagnostics.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\1348a5d04b41c614e48fe5fdb88d1cfa\System.ServiceModel.Internals.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\1348a5d04b41c614e48fe5fdb88d1cfa\System.ServiceModel.Internals.ni.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.Xml.resources.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.Runtime.Serialization.resources.dll
- C:\Users\test\AppData\Local\Temp\SuWar3Tools.cfg
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\zh-Hans\mscorrc.dll
- C:\Windows\System32\zh-CN\tzres.dll.mui
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\5faf546a8e018d89b1c277e0be243e4b\System.Net.Http.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\5faf546a8e018d89b1c277e0be243e4b\System.Net.Http.ni.dll
- C:\Windows\SysWOW64\zh-CN\KERNELBASE.dll.mui
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.resources.dll
修改的文件
- C:\Users\test\AppData\Local\Temp\FD0EFF5D.exe
- C:\Users\test\AppData\Local\GDIPFONTCACHEV1.DAT
- C:\Users\test\AppData\Local\Temp\SuWar3Tools.cfg
删除的文件
- C:\Users\test\AppData\Local\Temp\SuWar3Tools.exe
修改的注册表键
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FD0EFF5D_RASAPI32
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FD0EFF5D_RASAPI32\EnableFileTracing
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FD0EFF5D_RASAPI32\EnableConsoleTracing
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FD0EFF5D_RASAPI32\FileTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FD0EFF5D_RASAPI32\ConsoleTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FD0EFF5D_RASAPI32\MaxFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FD0EFF5D_RASAPI32\FileDirectory
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\LanguageList
删除的注册表键
无信息