Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\az7aa\ImagePath
data: \??\C:\Users\test\AppData\Local\Temp\zip-tmp\az7aa.sys
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\j9ksAzlR\ImagePath
data: \??\C:\Users\test\AppData\Local\Temp\zip-tmp\j9ksAzlR.sys
运行截图
网络分析
访问主机记录
直接访问 |
IP地址 |
国家名 |
否 |
14.215.158.24 |
China |
否 |
183.3.226.29 |
China |
域名解析
域名 |
响应 |
jq.qq.com |
A 14.215.158.24
|
qm.qq.com |
A 183.3.226.29
|
TCP连接
IP地址 |
端口 |
14.215.158.24 |
443 |
183.3.226.29 |
80 |
183.3.226.29 |
443 |
23.192.228.27 |
80 |
UDP连接
IP地址 |
端口 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
HTTP请求
URL |
HTTP数据 |
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip |
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache
|
http://qm.qq.com/cgi-bin/qm/qr?k=qRqrj51RAQpEfB6pXUQZRR1uQcU3AA78&authKey=909NLTBUx6DbRGE9z3GfjPaTMyeEjQnLlQ%2FVshKGGyAgWFOJa5o79p%2BUTobm6edd&noverify=0&group_code=537071796 |
GET /cgi-bin/qm/qr?k=qRqrj51RAQpEfB6pXUQZRR1uQcU3AA78&authKey=909NLTBUx6DbRGE9z3GfjPaTMyeEjQnLlQ%2FVshKGGyAgWFOJa5o79p%2BUTobm6edd&noverify=0&group_code=537071796 HTTP/1.1
Accept: */*
Accept-Language: zh-cn
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Accept-Encoding: gzip, deflate
Host: qm.qq.com
Connection: Keep-Alive
|
投放文件
Apex.exe
文件名 |
Apex.exe |
相关文件 |
- C:\Users\test\AppData\Local\Temp\zip-tmp\Apex.exe
|
文件大小 |
2088960 bytes |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 |
4488289b0f0e5c20fdf2ab040b97dde2 |
SHA1 |
499e0ad7ea584f71dc1bc093980f23a2bef1270c |
SHA256 |
e20db1d26d825f515e54c0dc250da8ff4af05625edc64da66d63e22181b2d5ce |
SHA512 |
f9884e6e5aa4dc88c52781d23931acf0afda13fe8ed1271e931577c55f9b61442adb07c7c2e873f9de3a4884e59738b531cde2f9271a6f9721399212b1a634a3 |
Ssdeep |
24576:81b2Xh3BXV4WBsZJ1zXsRxPOJzjurq2uXlz7hdUnKwYVUh3oXBrniGq7pztiG:8opBXzsZoRUJfgUVz7Mn0a3oXB0 |
VirusTotal |
搜索相关分析 |