Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Nov. 12, 2021, 11:03 a.m. | Nov. 12, 2021, 11:06 a.m. |
-
-
bcdedit.exe C:\windows\sysnative\bcdedit.exe
2528 -
bcdedit.exe C:\windows\sysnative\bcdedit.exe /enum {BBA53588-9FEC-4BE1-9FF8-51BF7E088918}
2588 -
MiniTPFw.exe "C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\MiniTPFw.exe"
2840-
ThunderFW.exe "C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\ThunderFW.exe" MiniThunderPlatform2021-11-1217:23:59 "C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\MiniThunderPlatform.exe"
2992
-
-
MiniThunderPlatform.exe "C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\MiniThunderPlatform.exe" -StartTP
2912 -
update.exe "C:\Users\test22\Documents\YunQiShiUSBDrive\update.exe" 4FB7D25268E0F658802D8CA493C76FC9B24AC78C469520FCCD2BF6CB7E35B270BED50E2600463B6EE69C35FA2008A41EAF0EAB8968667939D3ED1E6EC3C3D5C27A2C97F8B0DB381B9A9A2CD6C994C848F7E57C82CF93E05E21B2B7729FDD26E29806D5D8B67BD066EA41908218A47771E3EEADEB3C33EEEA8198C76F309C79EB59CB7011D6CA67820901496CD331EC7241162DA82D773F6B8B37B799C286A46CF86761CDDB2754E2B549FE965F43FE893766A51AB4788DA3811517F9C4E477E308BA8BB78C7C740CF3196DA35496895E5C438F16EC4A8FF5647E22013C053EA2D9D97401BDF0CDA8
2224 -
bcdedit.exe C:\windows\sysnative\bcdedit.exe
2532 -
bcdedit.exe C:\windows\sysnative\bcdedit.exe /enum {BBA53588-9FEC-4BE1-9FF8-51BF7E088918}
2644
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
IP Address | Status | Action |
---|---|---|
116.132.219.184 | Active | Moloch |
120.76.246.204 | Active | Moloch |
140.206.225.232 | Active | Moloch |
157.255.225.49 | Active | Moloch |
164.124.101.2 | Active | Moloch |
39.100.9.39 | Active | Moloch |
47.115.157.13 | Active | Moloch |
47.92.195.246 | Active | Moloch |
47.92.99.221 | Active | Moloch |
47.97.7.140 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .vmp0 |
resource name | FILE |
resource name | GIF |
resource name | PNG |
resource name | STYLE_XML |
resource name | None |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://47.97.7.140:80/ | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://116.132.219.184:80/ | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://47.92.195.246:80/ | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://140.206.225.232:80/ |
request | POST http://47.97.7.140:80/ |
request | POST http://116.132.219.184:80/ |
request | POST http://47.92.195.246:80/ |
request | POST http://140.206.225.232:80/ |
request | POST http://47.97.7.140:80/ |
request | POST http://116.132.219.184:80/ |
request | POST http://47.92.195.246:80/ |
request | POST http://140.206.225.232:80/ |
ip | 120.76.246.204 |
ip | 47.115.157.13 |
ip | 157.255.225.49 |
ip | 39.100.9.39 |
ip | 47.92.99.221 |
description | uqiwang.exe tried to sleep 365 seconds, actually delayed analysis time by 365 seconds |
name | FILE | language | LANG_CHINESE | filetype | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x004c0c28 | size | 0x01128400 | ||||||||||||||||||
name | GIF | language | LANG_CHINESE | filetype | GIF image data, version 89a, 200 x 170 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x015e9028 | size | 0x0001b0f3 | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb | ||||||||||||||||||
name | PNG | language | LANG_CHINESE | filetype | PNG image data, 16 x 16, 8-bit/color RGBA, interlaced | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x01727c9c | size | 0x000003fb |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\bootice\BOOTICE.EXE |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\qemu\SDL.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\uninstall.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\qemu\libpdcurses.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\pe\PECmd.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\dos\bootsect.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\oscdimg\etfsboot.com |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Dependency\InsNet.dll |
file | C:\Users\Public\Desktop\云骑士装机大师(U盘版).lnk |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\XLBugHandler.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\atl71.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\MiniTPFw.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\qemu\myqemu.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\cpio\libiconv2.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\msvcp71.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\xldl.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\fnt\mkblfont.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\fbinst\fbinst.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\zlib1.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\dos\bcdedit.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Dependency\Zlib.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\minizip.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\MiniThunderPlatform.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\gdisk32\gdisk32.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\cpio\cpio.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\dos\bcdboot.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\fnt\freetype6.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\ConfigRes.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\qemu\libz-1.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\dl_peer_id.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\ThunderFW.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\download_engine.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\qemu\libssp-0.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\cpio\libintl3.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\oscdimg\oscdimg.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\msvcr71.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\fnt\libiconv2.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\fnt\zlib1.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Dependency\Propsys.dll |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\XLBugReport.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\update.exe |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\云骑士装机大师(U盘版)\卸载.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\云骑士装机大师(U盘版)\云骑士装机大师(U盘版).lnk |
file | C:\Users\Public\Desktop\云骑士装机大师(U盘版).lnk |
file | C:\Users\test22\Desktop\云骑士装机大师(U盘版).lnk |
cmdline | C:\windows\sysnative\bcdedit.exe /enum {BBA53588-9FEC-4BE1-9FF8-51BF7E088918} |
cmdline | C:\windows\sysnative\bcdedit.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\MiniTPFw.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\update.exe |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\Work\Tools\download\download\ThunderFW.exe |
wmi | select * from Win32_VideoController |
wmi | select * from Win32_OperatingSystem |
wmi | select * from Win32_PhysicalMemory |
wmi | select * from Win32_ComputerSystem |
wmi | select * from Win32_SystemEnclosure |
wmi | select * from win32_DiskDrive |
wmi | select * from Win32_DesktopMonitor |
wmi | select * from win32_baseboard |
wmi | select * from Win32_NetworkAdapter WHERE NetConnectionID != null |
section | {u'size_of_data': u'0x012d8e00', u'virtual_address': u'0x004ac000', u'entropy': 7.971870441736988, u'name': u'.rsrc', u'virtual_size': u'0x012d8c18'} | entropy | 7.97187044174 | description | A section with a high entropy has been found | |||||||||
entropy | 0.803325771608 | description | Overall entropy of this PE file is high |
description | Communications over RAW Socket | rule | Network_TCP_Socket | ||||||
description | Run a KeyLogger | rule | KeyLogger | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | Take ScreenShot | rule | ScreenShot | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Affect hook table | rule | win_hook | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
section | .vmp0 | description | Section name indicates VMProtect |
wmi | select * from Win32_ComputerSystem |
wmi | select * from Win32_PhysicalMemory |
file | C:\Users\test22\Documents\YunQiShiUSBDrive\update.exe |