```
进程行为
行为描述: 创建本地线程
详情信息:
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2452, ThreadID = 2468, StartAddress = 77DC845A, Parameter = 00000000
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2452, ThreadID = 2600, StartAddress = 77C0A341, Parameter = 003F72A0
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2452, ThreadID = 2604, StartAddress = 77C0A341, Parameter = 003F72A0
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2452, ThreadID = 2624, StartAddress = 77C0A341, Parameter = 003F7330
TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2452, ThreadID = 2848, StartAddress = 77C0A341, Parameter = 003F73C0
行为描述: 枚举进程
详情信息:
N/A
文件行为
行为描述: 重命名文件
详情信息:
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe ---> C:\Program Files\Common Files\3B0BDBEB.exe
网络行为
行为描述: 打开指定 IE 网页
详情信息:
tg://setlanguage?lang=classic-zh-cn
行为描述: 建立到一个指定的套接字连接
详情信息:
URL: da****om, IP: **.216.117.**:8000, SOCKET = 0x00000114
行为描述: 按名称获取主机地址
详情信息:
gethostbyname: da****om
注册表行为
行为描述: 修改注册表
详情信息:
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Software\Wxyabc Efghijkl Nop\MarkTime
\REGISTRY\USER\S-*\Software\Microsoft\ActiveMovie\devenum\Version
复制代码
Address 185.216.117.5
Hostname
noc.ayidc.comISP Cloudie Limited
IP Organization Cloudie Limited
ASN AS55933
ASN Organization Cloudie Limited
Location 香港
```