魔盾安全Yara检测结果 - 普通
Warning: Detected UPX. Commonly used by RAT!
二进制文件可能包含加密或压缩数据
section: name: UPX1, entropy: 7.91, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00011a00, virtual_size: 0x00012000
可执行文件被使用UPX压缩
section: name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0001f000
通过进程尝试长时间延迟分析任务
Process: peview.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds
网络分析
TCP连接
IP地址 |
端口 |
23.223.199.177 |
80 |
HTTP请求
URL |
HTTP数据 |
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip |
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache
|
静态分析
版本信息
LegalCopyright: |
Licensed under the GNU GPL, v3. |
InternalName: |
peview |
FileVersion: |
2.35.0.5898 |
CompanyName: |
wj32 |
ProductName: |
Process Hacker |
ProductVersion: |
2.35.0.5898 |
FileDescription: |
PE Viewer |
OriginalFilename: |
peview.exe |
Translation: |
0x0804 0x04b0 |
PE数据组成
名称 |
虚拟地址 |
虚拟大小 |
原始数据大小 |
特征 |
熵(Entropy) |
UPX0 |
0x00001000 |
0x0001f000 |
0x00000000 |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
0.00 |
UPX1 |
0x00020000 |
0x00012000 |
0x00011a00 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
7.91 |
.rsrc |
0x00032000 |
0x00002000 |
0x00001600 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
4.43 |
覆盖
偏移量: |
0x00013400 |
大小: |
0x00001f58 |
导入
库 COMCTL32.dll:
• 0x4332a8 - PropertySheetW
库 COMDLG32.dll:
• 0x4332b0 - GetOpenFileNameW
库 GDI32.dll:
• 0x4332b8 - SelectObject
库 KERNEL32.DLL:
• 0x4332c0 - LoadLibraryA
• 0x4332c4 - ExitProcess
• 0x4332c8 - GetProcAddress
• 0x4332cc - VirtualProtect
库 ntdll.dll:
• 0x4332d4 - NtClose
库 ole32.dll:
• 0x4332dc - CoTaskMemFree
库 SHELL32.dll:
• 0x4332e4 - SHGetFileInfoW
库 USER32.dll:
• 0x4332ec - GetPropW
库 VERSION.dll:
• 0x4332f4 - VerQueryValueW
行为分析
互斥量(Mutexes)
- Local\MSCTF.Asm.MutexDefault1
- DefaultTabtip-MainUI
- Local\Shell.CMruPidlList
- Local\SHResolveLibrary:C:/Users/test/AppData/Roaming/Microsoft/Windows/Libraries/Documents.library-ms
执行的命令
无信息
创建的服务
无信息
启动的服务
无信息
进程
peview.exe PID: 2512, 上一级进程 PID: 2212
读取的文件
- \Device\KsecDD
- C:\Windows\SysWOW64\comdlg32.dll
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\System32\explorerframe.dll
- C:\Windows\System32\EhStorShell.dll
- C:\Windows\AppPatch\sysmain.sdb
- C:\Windows\System32\
- C:\Windows\System32\zh-CN\EhStorShell.dll.mui
- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
- C:\Program Files (x86)\Microsoft Office\Office14\
- C:\Program Files (x86)\Microsoft Office\Office14\2052\GrooveIntlResource.dll
- C:\Windows\System32\ntshrui.dll
- C:\Windows\System32\imageres.dll
- C:\Windows\System32\zh-CN\imageres.dll.mui
- C:\Windows\sysnative\zh-CN\imageres.dll.mui
- C:\Windows\System32\zh-Hans\imageres.dll.mui
- C:\Windows\System32\zh\imageres.dll.mui
- C:\Windows\System32\en-US\imageres.dll.mui
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\System32\ShellStyle.dll
- C:\Windows\win.ini
- C:\
- C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
- C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000052.db
- C:\Users\desktop.ini
- C:\Users
- C:\Users\test
- C:\Users\test\AppData
- C:\Users\test\AppData\Roaming
- C:\Users\test\AppData\Roaming\Microsoft\desktop.ini
- C:\Users\test\AppData\Roaming\Microsoft
- C:\Users\test\AppData\Roaming\Microsoft\Windows
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Libraries
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
- C:\Users\test\Documents\desktop.ini
- C:\Users\Public\desktop.ini
- C:\Users\Public
- C:\Users\Public\Documents\desktop.ini
- C:\Users\test\Desktop\desktop.ini
- C:\Windows\SysWOW64\shlwapi.dll
- C:\Windows\System32\mssvp.dll
- C:\Windows\System32\zh-CN\mssvp.dll.mui
- C:\Users\test\Documents
- C:\Users\test\Documents\My Music\desktop.ini
- C:\Users\test\Documents\My Pictures\desktop.ini
- C:\Users\test\Documents\My Videos\desktop.ini
- C:\Users\Public\Documents
- C:\Users\Public\Documents\My Music\desktop.ini
- C:\Users\Public\Documents\My Pictures\desktop.ini
- C:\Users\Public\Documents\My Videos\desktop.ini
- C:\Windows\System32\shell32.dll
- C:\Users\test\Links\desktop.ini
- C:\Users\test\Links
- C:\Users\test\Desktop
- C:\Users\Public\Desktop\desktop.ini
- C:\Users\Public\Desktop
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
- C:\Users\test\Music\desktop.ini
- C:\Users\Public\Music\desktop.ini
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
- C:\Users\test\Videos\desktop.ini
- C:\Users\Public\Videos\desktop.ini
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
- C:\Users\test\Pictures\desktop.ini
- C:\Users\Public\Pictures\desktop.ini
- C:\Users\test\Favorites\desktop.ini
- C:\Windows\System32\NetworkExplorer.dll
- C:\Windows\System32\networkexplorer.dll
- C:\Windows\System32\tzres.dll
- C:\Users\test\Links\Downloads.lnk
- C:\Users\test\Downloads\desktop.ini
- C:\Users\test\Links\Desktop.lnk
- C:\Users\test\Links\RecentPlaces.lnk
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
- \??\PIPE\wkssvc
- \??\PIPE\DAV RPC SERVICE
- C:\Windows\System32\wpdshext.dll
- C:\Windows\System32\audiodev.dll
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Network Shortcuts\desktop.ini
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Network Shortcuts
修改的文件
- \??\PIPE\wkssvc
- \??\PIPE\DAV RPC SERVICE
删除的文件
无信息
修改的注册表键
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\NodeSlots
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\MRUListEx
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\ComDlg\TV_FolderType
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\ComDlg\TV_TopViewID
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\ComDlg\TV_TopViewVersion
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\LanguageList
删除的注册表键
无信息