威胁数据库 Rootkit Trojan.Rootkit.Agent.XC

Trojan.Rootkit.Agent.XC

Trojan.Rootkit.Agent.XC是一个检测名称,用于识别属于 rootkit 威胁类别的恶意程序。Rootkit 是一种特别危险的恶意软件,因为它们旨在隐藏自身以及受感染计算机上其他恶意组件的存在。当检测到此名称下的威胁时,通常表明该程序正试图未经授权地以隐藏方式访问系统,同时避免被安全工具和用户检测到。

由于没有关于此特定检测的具体技术细节,以下描述基于与此检测相关的 rootkit-family 威胁的典型行为。

这种威胁会造成什么影响?

与其他rootkit恶意软件一样,Trojan.Rootkit.Agent.XC通常被设计成深度嵌入操作系统,从而能够以更高的权限运行,同时对用户保持隐蔽。Rootkit通常会修改或拦截系统进程,隐藏与其关联的文件、文件夹、正在运行的进程或注册表项,并可能禁用或干扰安全软件以避免被清除。许多rootkit会作为其他恶意软件的基础,使攻击者能够在用户不知情的情况下安装间谍软件、勒索软件或后门等其他威胁。一些rootkit还被用于赋予远程攻击者对受感染计算机的持久、未经授权的控制权。

它通常是如何进入电脑的

Rootkit 类型的感染通常通过常见的恶意软件传播方式扩散。这些方式包括从不可信或盗版软件来源捆绑下载、恶意电子邮件附件或链接、虚假软件更新、破解应用程序以及利用操作系统或已安装程序中未修补的安全漏洞的漏洞利用工具包。在许多情况下,用户会在不知情的情况下自行安装 Rootkit,例如从不可靠的网站下载免费软件或点击欺骗性广告和弹出窗口。

用户面临的风险

由于rootkit的设计初衷是隐蔽运行,因此这类感染可能带来严重风险。攻击者可以利用隐藏的访问权限窃取敏感的个人或财务信息、记录键盘输入、截取屏幕截图或监控在线活动。受感染的系统也可能被用作发起进一步攻击的跳板,例如散布垃圾邮件、参与僵尸网络或下载其他恶意程序。由于rootkit会主动规避检测,因此感染可能持续很长时间,用户却察觉不到任何明显的异常,从而随着时间的推移不断扩大潜在的危害。

感染迹象

Rootkit感染的设计初衷就是为了便于通过常规观察来检测。然而,用户可能会注意到一些Rootkit活动常见的警告信号,例如系统异常变慢、意外崩溃或死机、安全软件停止正常工作或无法更新、系统设置被未经用户更改,以及可能表明与远程服务器存在未经授权通信的异常网络活动。在某些情况下,可能完全没有任何可见症状,而这正是此类威胁如此危险的原因之一。

如何做好防护

为了降低rootkit感染的风险,用户应保持操作系统和所有已安装软件的更新,因为攻击者经常利用未修补的漏洞。避免从非官方或不可信的来源下载软件,并对来自未知发件人的电子邮件附件和链接保持警惕。使用信誉良好且最新的安全软件并定期进行系统扫描,有助于在rootkit感染之前检测并阻止其扩散。由于rootkit一旦安装就难以清除,因此养成安全的浏览习惯和谨慎下载是普通计算机用户最有效的防御措施之一。

分析报告

一般信息

姓: Trojan.Rootkit.Agent.XC
签名状态: No Signature

已知样本

MD5: e80503abeed95309ab805f06de28491c
SHA1: 968c8a8b0d475654c905dcfeb4ba611e39891a79
SHA256: 336300B3AE0EB565AD0A96E7ED018CBA3C4E45C4BA42F0498E1179221DE651B6
文件大小: 1.53 MB,1525248字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
显示更多
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件图标

Windows PE 版本信息

姓名 价值
Company Name GBTGAME
File Description GBTGAME Launcher v3.0.10
File Version 3.0.10.0
Internal Name GBTGAME-Launcher-v3
Legal Copyright GBTGAME.ME
Original Filename GBTGAME-Launcher-v3.exe
Product Name GBTGAME Launcher v3.0.10
Product Version 3.0.10.0

文件特征

  • 2+ executable sections
  • No Version Info
  • x64

区块信息

总区块数: 1,773
潜在恶意块: 18
白名单区块: 1,458
未知区块: 297

可视化地图

0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 0 0 ? ? 0 ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 1 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? ? ? 0 ? 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 x ? ? ? ? ? ? x 0 ? ? ? 0 ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? 0 ? ? x 0 ? 0 x ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 1 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? 0 0 0 0 0 0 0 ? ? 0 x 0 x x x 0 0 0 2 0 ? ? ? 0
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

文件已修改

文件 属性
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\local\mojo.5304.9080.10448436914773022828 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\gbt_ui_trace_5304.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\gbt_ui_trace_5304.log Generic Write,Read Attributes
c:\users\user\downloads\.gbtgame-v3-runtime\launcher.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\.gbtgame-v3-runtime\launcher.log Generic Write,Read Attributes

注册表修改

键::值 数据 API名称
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 춀ꛤ䳡ǝ RegNtPreCreateKey

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
显示更多
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemEnvironmentValueEx
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpReceiveResponse
  • WinHttpSendRequest
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell命令执行

C:\Windows\System32\manage-bde.exe "C:\Windows\System32\manage-bde.exe" -status