Other behavior |
Behavior description: | 直接调用系统关键API |
details: | Index = 0x0000009A, Name: NtQueryInformationProcess, Instruction Address = 0x01054F87 |
| Index = 0x000000E5, Name: NtSetInformationThread, Instruction Address = 0x01054F87 |
Behavior description: | 检测自身是否被调试 |
details: | IsDebuggerPresent |
Behavior description: | 创建互斥体 |
details: | RasPbFile |
| CTF.LBES.MutexDefaultS-* |
| CTF.Compart.MutexDefaultS-* |
| CTF.Asm.MutexDefaultS-* |
| CTF.Layouts.MutexDefaultS-* |
| CTF.TMD.MutexDefaultS-* |
| CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-* |
| MSCTF.Shared.MUTEX.IOH |
Behavior description: | 创建事件对象 |
details: | EventName = DINPUTWINMM
|
Behavior description: | 直接获取CPU时钟 |
details: | EAX = 0x1bfea6df, EDX = 0x000000b7 |
| EAX = 0x1bfea72b, EDX = 0x000000b7 |
| EAX = 0x1e8676b4, EDX = 0x000000b7 |
| EAX = 0x1e867700, EDX = 0x000000b7 |
| EAX = 0x1e86774c, EDX = 0x000000b7 |
| EAX = 0x1e867798, EDX = 0x000000b7 |
| EAX = 0x1e8677e4, EDX = 0x000000b7 |
| EAX = 0x1e867830, EDX = 0x000000b7 |
| EAX = 0x1e86787c, EDX = 0x000000b7 |
| EAX = 0x1e8678c8, EDX = 0x000000b7 |
Behavior description: | 查找指定窗口 |
details: | NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,] |
Behavior description: | 打开事件 |
details: | HookSwitchHookEnabledEvent |
| CTF.ThreadMIConnectionEvent.000007E8.00000000.00000010 |
| CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.00000010 |
| MSCTF.SendReceiveConection.Event.IOH.IC |
| MSCTF.SendReceive.Event.IOH.IC |
Behavior description: | 窗口信息 |
details: | Pid = 2660, Hwnd=0x103a4, Text = 请勿更改默认文件名, ClassName = Afx:400000:b:10011:1900015:0.
|
Behavior description: | 隐藏指定窗口 |
details: | [Window,Class] = [,tooltips_class32] |
| [Window,Class] = [,Afx:400000:8] |
| [Window,Class] = [,_EL_Timer] |
Behavior description: | 打开互斥体 |
details: | RasPbFile |
| ShimCacheMutex |