威胁数据库 后门 后门.Orcus.RA

后门.Orcus.RA

通过CagedTech在 后门
发布时间:
最后更新:

威胁评分卡

人气排名: 26,433
威胁级别: 60 % (中等的)
受感染的计算机: 2
初见: July 22, 2026
最后一次露面: October 4, 2026
受影响的操作系统: Windows

Backdoor.Orcus.RA是一种后门威胁,旨在让攻击者能够隐蔽地、未经授权地远程访问受感染的 Windows 计算机。与其他后门程序一样,它会在后台静默运行,允许远程操作者在受害者不知情或未经同意的情况下控制计算机、监视用户并篡改数据。它的存在对个人隐私和系统安全都构成了严重威胁。

Backdoor.Orcus.RA 的作用

一旦在系统中激活,Backdoor.Orcus.RA 就会在受感染的计算机和远程攻击者之间建立一条隐藏的通信通道。通过这种连接,网络犯罪分子通常可以向受感染的计算机发出指令,从而浏览和传输文件、安装其他恶意软件、截取屏幕截图、记录键盘输入或实时监控用户活动。许多此类后门程序还能够修改系统设置、禁用安全功能,并保持持久性,即使计算机重启后,恶意程序也能继续运行。

由于后门程序旨在隐蔽运行,Backdoor.Orcus.RA 的设计理念是通过与合法系统进程融合、隐藏其文件以及限制任何可能提醒用户其存在的可见症状来避免被检测到。

它通常是如何进入电脑的

这类后门威胁很少由受害者直接安装。相反,它们通常通过欺骗手段传播,例如恶意电子邮件附件、捆绑软件下载、破解或盗版应用程序、虚假软件更新或指向被入侵网站的链接。在许多情况下,后门是由其他恶意软件(例如木马、蠕虫或恶意下载器)植入系统的,这些恶意软件首先入侵计算机,然后静默安装后门组件。从非官方来源下载软件或点击未经请求的链接和附件的用户更容易遭遇此类感染。

用户面临的风险

计算机上存在 Backdoor.Orcus.RA 可能导致严重后果。由于攻击者能够有效地远程控制计算机,密码、银行信息、个人文件和浏览历史记录等敏感信息可能会被窃取或泄露。该后门还可以作为发起进一步攻击的跳板,包括安装其他恶意软件、加入僵尸网络或部署勒索软件。在某些情况下,受感染的系统可能被用于攻击其他计算机或网络,使受害者在不知情的情况下成为更大规模网络犯罪活动的参与者。

感染迹象

由于后门程序旨在隐蔽运行,因此感染可能难以察觉。然而,用户可能会观察到一些警告信号,例如异常的网络活动、系统性能无故下降、程序在未经用户操作的情况下自动打开或关闭、后台运行着陌生的进程、安全软件意外禁用或数据使用量增加。任何这些症状,尤其是同时出现时,都可能表明存在类似 Backdoor.Orcus.RA 这样的隐藏威胁。

如何做好防护

为了降低后门感染的风险,用户应避免从不可信或非官方来源下载软件,不要打开来自未知发件人的电子邮件附件或链接,并及时更新操作系统和已安装的应用程序,安装最新的安全补丁。使用信誉良好的反恶意软件工具定期扫描系统、启用防火墙以及谨慎浏览不熟悉的网站,也有助于防止 Backdoor.Orcus.RA 等后门程序入侵计算机。

分析报告

一般信息

姓: Backdoor.Orcus.RA
签名状态: No Signature

已知样本

MD5: f5620301a852f67580b5619de61b22c3
SHA1: b8fdbe22dc5469e8fb3ade4e67a1b6f868085f83
SHA256: 3607E07B19E169EA6DBAAEA3EB94081DDE52EE81ABBA98D6C33F2648506F9341
文件大小: 197.63 KB,197632字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
显示更多
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件图标

Windows PE 版本信息

姓名 价值
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name Yoga Shooting Beta.exe
Original Filename Yoga Shooting Beta.exe
Product Version 0.0.0.0

文件特征

  • .NET
  • HighEntropy
  • x64

区块信息

总区块数: 233
潜在恶意块: 7
白名单区块: 45
未知区块: 181

可视化地图

? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? x ? 0 ? ? x 0 ? x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
显示更多
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent