[13312] 2018-10-17_负载恶意软件HawkEye的VBInject样本分析

文档创建者:s7ckTeam
浏览次数:2
最后更新:2025-01-18
2018-10-17_负载恶意软件HawkEye的VBInject样本分析 H a w k E y e V B   I n j e c t M a c c   F r e e B u f   2 0 1 8 - 1 0 - 1 7 0 x 0 1   H a w k E y e o f f i c e H a w k E y e V B   I n j e c t V B V i r u s T o t a l V B K r y p t V B I n j e c t 0 x 0 2  
C : U s e r u s e r A p p D a t a R o m a i n g W i n d o w s U p d a t e . e x e C : U s e r u s e r A p p D a t a R o m a i n g p i d . t x t , C : U s e r u s e r A p p D a t a R o m a i n g p i d l o c . t x t W i n d o w s U p d a t e . e x e w i r e s h a r k 访 h t t p : / / w h a t i s m y i p a d d r e s s . c o m / y a n d e x 0 x 0 3   V B V B   d e c o m p i l e c a l l 0 x 4 0 1 2 A 1 c a l l m s v b v m 6 0
V B   d e c o m p i l e 0 x 4 A 0 7 D 6 0 x 4 A 0 B C 8 F o r m L o a d F o r m P a i n t c a l l D l l F u n c t i o n C a l l R t l M o v e M e m o r y F 4 c a l l ( c a l l _ _ v b a x x x ) c a l l D l l F u n c i t o n C a l l
E n u m W i n d o w s B O O L   E n u m W i n d o w s (   W N D E N U M P R O C   l p E n u m F u n c ,   L P A R A M   l P a r a m   ) l p E n u m F u n c l P a r a m 0 x 1 2 F 4 D 8 F 8 - > j m p c a l l   e d x
0 x 4 8 E A 9 2 0 x 4 8 E A 9 3 c a l l a d c 1 0 x 4 8 E A 9 3 n o p [ e b x + 2 ] f s : e s i ( T E B ) 3 B e i n g D e b u g g e d ,   0 x 0 1 n o p 0 x 0 4   0 x 4 8 E A 9 2
c a l l c a l l D l l F u n c t i o n C a l l E n u m W i n d o w s V i r t u a l A l l o c D l l F u n c t i o n C a l l V i r t u a l A l l o c
1 T E B P E B   B e i n g D e b u g g e d V i r t u a l A l l o c 2 P E B 访 0 x 6 8 0 x 6 8
P E B N t G l o b a l F l a g 0 x 6 8 N t G l o b a l F l a g 0 x 0 0 x 7 0 0 x 7 0 j e D l l F u n c i t o n C a l l A P I S h e l l E x e c u t e W , W r i t e F i l e , C r e a t e F i l e , V i r t u a l P r o t e c t , C r e a t e P r o c e s s 3 0 x 3 4 3 0 0 0 0
P E M Z G e t C o m m a n d L i n e W Z w A l l o c a t e V i r t u a l M e m o r y 0 x 5 A 0 x 3 4 3 6 0 0 P E M
Z w W r i t e V i r t u a l M e m o r y 0 x 3 4 3 6 0 0 P E 0 x 0 5   C : U s e r u s e r A p p D a t a R o m a i n g p i d . t x t p i d l o c . t x t W i n d o w s U p d a t e . e x e P E V B P E E x e i n f o P E . N E T   R e a c t o r d e 4 d o t - m o d 5 2 8 K B 6 5 5 1 2 K B P E I D m s c o r e e . d l l _ C o r e E x e M a i n
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则