Other behavior |
Behavior description: | 创建互斥体 |
details: | CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
| CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
| CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
| CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
| CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
| CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1645522239-1417001333-500MUTEX.DefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
| MSCTF.Shared.MUTEX.AEH |
| MSCTF.Shared.MUTEX.IPJ |
Behavior description: | 枚举窗口 |
details: | N/A |
Behavior description: | 查找指定窗口 |
details: | NtUserFindWindowEx: [Class,Window] = [CurrPorts,] |
| NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,] |
| NtUserFindWindowEx: [Class,Window] = [NirSoft_IPNetInfo,] |
| NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,] |
Behavior description: | 窗口信息 |
details: | Pid = 2548, Hwnd=0x10350, Text = 11 Total Ports, No Remote Connections, 1 Selected, ClassName = msctls_statusbar32. |
| Pid = 2548, Hwnd=0x1034c, Text = CurrPorts, ClassName = CurrPorts. |
Behavior description: | 获取系统权限 |
details: | SE_DEBUG_PRIVILEGE |