self_read: process: _______________001.exe, pid: 2580, offset: 0x00000000, length: 0x00001000
self_read: process: _______________001.exe, pid: 2580, offset: 0x00000080, length: 0x00000200
self_read: process: _______________001.exe, pid: 2580, offset: 0x00000178, length: 0x00000200
self_read: process: _______________001.exe, pid: 2580, offset: 0x00032be0, length: 0x00000200
尝试通过安装目录检测已安装的反病毒软件
file: C:\Program Files (x86)\Avira\
file: C:\Program Files (x86)\Avira
file: C:\Program Files (x86)\Avira\Avira.exe
运行截图
网络分析
访问主机记录
直接访问 |
IP地址 |
国家名 |
否 |
183.66.100.32 |
China |
域名解析
域名 |
响应 |
jkjkdll3-1323575486.cos.ap-chengdu.myqcloud.com |
A 183.66.100.32
CNAME cd.file.myqcloud.com
A 183.66.100.19
|
TCP连接
IP地址 |
端口 |
183.66.100.32 |
443 |
23.15.196.139 |
80 |
UDP连接
IP地址 |
端口 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
HTTP请求
URL |
HTTP数据 |
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip |
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache
|
静态分析
版本信息
Translation: |
0x0000 0x04b0 |
LegalCopyright: |
TKReview |
Assembly Version: |
6.0.0.0 |
InternalName: |
APP.exe |
FileVersion: |
6.0.0.0 |
CompanyName: |
TKReview |
LegalTrademarks: |
TKReview |
Comments: |
TKReview |
ProductName: |
TKReview |
ProductVersion: |
6.0.0.0 |
FileDescription: |
TKReview |
OriginalFilename: |
APP.exe |
PE数据组成
名称 |
虚拟地址 |
虚拟大小 |
原始数据大小 |
特征 |
熵(Entropy) |
.text |
0x00002000 |
0x00032a54 |
0x00032c00 |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ |
2.78 |
.rsrc |
0x00036000 |
0x00070858 |
0x00070a00 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ |
5.69 |
.reloc |
0x000a8000 |
0x0000000c |
0x00000200 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ |
0.10 |
资源
名称 |
偏移量 |
大小 |
语言 |
子语言 |
熵(Entropy) |
文件类型 |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x000a5e18 |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.77 |
GLS_BINARY_LSB_FIRST |
RT_GROUP_ICON |
0x000a6290 |
0x00000092 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.10 |
MS Windows icon resource - 10 icons, 256x256 |
RT_VERSION |
0x000a6334 |
0x00000324 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.27 |
data |
RT_MANIFEST |
0x000a6668 |
0x000001ea |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.00 |
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
导入
库 mscoree.dll:
• 0x402000 - _CorExeMain
行为分析
互斥量(Mutexes)
- Local\MSCTF.Asm.MutexDefault1
执行的命令
无信息
创建的服务
无信息
启动的服务
无信息
进程
_______________001.exe PID: 2580, 上一级进程 PID: 2256
读取的文件
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
- C:\Users\test\AppData\Local\Temp\_______________001.exe.config
- C:\Users\test\AppData\Local\Temp\_______________001.exe
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
- C:\Windows\sysnative\MSVCR120_CLR0400.dll
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\f89061884b75dab0e3967d7221e5290d\mscorlib.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\f89061884b75dab0e3967d7221e5290d\mscorlib.ni.dll
- \Device\KsecDD
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
- C:\Windows\assembly\pubpol49.dat
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\37004ddc6f466d807c52ca3b7f9f9827\System.Windows.Forms.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\60b77585c8aa9cfd1b30a64092c81041\System.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System\60b77585c8aa9cfd1b30a64092c81041\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\43de4a177616225e9b6262468e1c3b53\System.Drawing.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\43de4a177616225e9b6262468e1c3b53\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\37004ddc6f466d807c52ca3b7f9f9827\System.Windows.Forms.ni.dll
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SortDefault.nlp
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\2fe311002b76e58f2f89f897a32b62a2\System.Configuration.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\d1da4b8a843ec63bb8be25f8202bedc1\System.Core.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\d1da4b8a843ec63bb8be25f8202bedc1\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\2fe311002b76e58f2f89f897a32b62a2\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\c2f35cb9621b8ca33a05759bbb0683c1\System.Xml.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\c2f35cb9621b8ca33a05759bbb0683c1\System.Xml.ni.dll
- C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_2b24536c71ed437a\GdiPlus.dll
- C:\Users\test\AppData\Local\GDIPFONTCACHEV1.DAT
- C:\Windows\Fonts\simsun.ttc
- C:\Windows\sysnative\zh-CN\KERNELBASE.dll.mui
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\mscorlib.resources.dll
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\zh-Hans\mscorrc.dll
- C:\Windows\sysnative\tzres.dll
- C:\Windows\sysnative\zh-CN\tzres.dll.mui
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.resources.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.Windows.Forms.resources.dll
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb
- C:\Windows\symbols\dll\System.pdb
- C:\Windows\dll\System.pdb
- C:\Windows\System.pdb
- C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb
- C:\Windows\symbols\dll\mscorlib.pdb
- C:\Windows\dll\mscorlib.pdb
- C:\Windows\mscorlib.pdb
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.pdb
- C:\Windows\symbols\dll\System.Windows.Forms.pdb
- C:\Windows\dll\System.Windows.Forms.pdb
- C:\Windows\System.Windows.Forms.pdb
- C:\Windows\Fonts\staticcache.dat
修改的文件
- C:\Users\test\AppData\Local\GDIPFONTCACHEV1.DAT
- C:\Program Files (x86)\Avira\Avira.exe
删除的文件
- C:\Program Files (x86)\Avira\Avira.exe
修改的注册表键
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\_______________001_RASAPI32
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\_______________001_RASAPI32\EnableFileTracing
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\_______________001_RASAPI32\EnableConsoleTracing
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\_______________001_RASAPI32\FileTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\_______________001_RASAPI32\ConsoleTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\_______________001_RASAPI32\MaxFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\_______________001_RASAPI32\FileDirectory
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\LanguageList
删除的注册表键
无信息