威胁数据库 病毒 病毒.Wapomi.B

病毒.Wapomi.B

Virus.Wapomi.B 被识别为恶意软件中的病毒类别成员。与该类别中的许多威胁一样,它旨在感染计算机上的文件并传播到其他系统,通常是在用户不知情或未经用户同意的情况下进行的。由于尚未确认有关此特定变种的详细技术细节,以下描述反映了此类文件感染病毒和蠕虫类威胁的典型行为,而 Virus.Wapomi.B 也被认为具有这些行为特征。

这种威胁会造成什么影响?

被归类为病毒的威胁,例如 Virus.Wapomi.B,通常通过将恶意代码附加到存储在受感染计算机上的可执行文件或其他合法程序上来运作。一旦文件被感染,运行该文件就会触发病毒激活,使其在系统中进一步传播,并可能感染其他连接的设备或驱动器。此类病毒通常会尝试自我复制,感染尽可能多的文件,因此感染持续时间越长,彻底清除就越困难。

在许多情况下,此类威胁也被用作传播其他恶意程序的手段。这可能包括在受感染的计算机上下载或安装其他不需要的或有害的程序,从而扩大损害范围,超出最初的感染范围。

它通常是如何进入电脑的

此类病毒通常通过受感染的移动存储介质传播,例如U盘、外置硬盘或共享网络驱动器。它们也可能通过盗版软件、破解程序安装程序或点对点网络共享的文件传播。电子邮件附件、从不可信网站下载的恶意文件以及与其他软件捆绑传播也可能是此类威胁的常见感染途径。由于尚未确认 Virus.Wapomi.B 的具体传播方式,用户应警惕所有这些常见的感染途径。

用户面临的风险

此类感染可能对受感染的计算机及其用户构成多种风险。这些风险包括系统性能下降、不稳定或因文件损坏导致的系统崩溃。由于此类病毒通常会传播到其他文件和驱动器,因此如果不及时处理,可能会对整个系统或网络造成大范围损害。此外,由于此类威胁可能被用于植入其他恶意软件,用户可能面临数据被盗、未经授权的访问或病毒传播的有效载荷导致的其他感染等次生风险。

感染迹象

如果用户的计算机感染了此类病毒,他们可能会注意到一些警告信号。这些信号包括:系统运行速度异常变慢、程序无法打开或意外崩溃、系统中出现陌生文件,或者磁盘或网络活动无故增加。安全软件也可能将可疑文件标记为已感染或自动隔离。任何无法解释的系统行为变化都应被视为感染的潜在迹象。

如何做好防护

为了降低感染 Virus.Wapomi.B 及类似威胁的风险,用户应避免从不可信或非官方来源下载软件,并谨慎使用来源不明的移动存储介质。保持操作系统和已安装软件的更新有助于堵住恶意软件可能利用的安全漏洞。定期使用更新的安全工具扫描系统、避免打开可疑的电子邮件附件以及备份重要文件,都能进一步降低潜在感染的影响,并在感染发生时帮助用户更快地恢复系统。

分析报告

一般信息

姓: Virus.Wapomi.B
包装工队: ASPack v2.12
签名状态: No Signature

已知样本

MD5: 1aa4c64363b68622c9426ce96c4186f2
SHA1: 6d30a08e63beec01478959d96a792d43bf03fb23
SHA256: 7936DEB5E6A236E8DCE91352D0617E3DB3BBE0FBAEBA5FB08BBEAC7590338C4D
文件大小: 89.60 KB,89600字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件特征

  • .adata
  • .aspack
  • 2+ executable sections
  • ASPack v2.12
  • HighEntropy
  • No Version Info
  • packed
  • upx
  • x86

区块信息

总区块数: 388
潜在恶意块: 134
白名单区块: 45
未知区块: 209

可视化地图

? x x x x x 0 x x x x x ? x x 0 x x ? ? x x x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? x x ? x x x ? 0 ? x x x ? x ? ? x ? 0 x ? ? x ? ? x ? ? ? ? ? ? ? 0 x x 0 x x ? x ? x ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? ? 0 ? ? ? x ? x ? ? x x 0 x x x ? ? ? ? ? ? ? ? ? ? ? x x x x x x x x ? x x 0 x ? ? x x x x 0 x x ? 0 x ? 0 ? x ? x x x x x x x ? ? x x x x x ? x x ? ? ? x 0 x ? ? 0 ? ? ? 0 0 x ? 0 ? ? 0 0 x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? x ? x x ? x x x x x x ? ? x ? x 0 x x ? ? 0 x x x 0 0 x x x ? x ? ? x ? x ? x x x x x ? x x x x x x x x x 0 x 0 ? x ? x 0 0 x 0 x x x x x 0 ? ? ? ? ? x x 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? x ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? 0 ? ? ? ? ? ? 0 ? ?
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

文件已修改

文件 属性
\device\namedpipe\{d952f2d0-0bce-4b2b-8fff-2317f120fcc3} Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\infotmp.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\2dec7a46.log Generic Write,Read Attributes
c:\windows\syswow64\2dec12c8.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\appmgmt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\bits.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\certpropsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\fastuserswitchingcompatibility.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\gpsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\helpsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
显示更多
c:\windows\syswow64\ias.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\iphlpsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\irmon.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\lanmanserver.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\logonhours.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\msiscsi.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\nla.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\ntmssvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\nwcworkstation.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\nwsapagent.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\pcaudit.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\rasauto.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\rasman.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\remoteaccess.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\schedule.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\scpolicysvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\sens.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\sessionenv.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\sharedaccess.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\shellhwdetection.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\srservice.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\tapisrv.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\tokenbroker.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\uploadmgr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\usermanager.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\winmgmt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\wmdmpmsp.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\wmi.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\wuauserv.dll Generic Read,Write Data,Write Attributes,Write extended,Append data

注册表修改

键::值 数据 API名称
HKLM\system\controlset001\control\keyboard layouts\e0010409::layout file KBDUS.DLL RegNtPreCreateKey
HKLM\system\controlset001\control\keyboard layouts\e0010409::layout text +�Y� RegNtPreCreateKey
HKLM\system\controlset001\services\certpropsvc\parameters::servicedll C:\WINDOWS\system32\CertPropSvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\scpolicysvc\parameters::servicedll C:\WINDOWS\system32\SCPolicySvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\lanmanserver\parameters::servicedll C:\WINDOWS\system32\lanmanserver.dll RegNtPreCreateKey
HKLM\system\controlset001\services\gpsvc\parameters::servicedll C:\WINDOWS\system32\gpsvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\iphlpsvc\parameters::servicedll C:\WINDOWS\system32\iphlpsvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\msiscsi\parameters::servicedll C:\WINDOWS\system32\msiscsi.dll RegNtPreCreateKey
HKLM\system\controlset001\services\schedule\parameters::servicedll C:\WINDOWS\system32\schedule.dll RegNtPreCreateKey
HKLM\system\controlset001\services\winmgmt\parameters::servicedll C:\WINDOWS\system32\winmgmt.dll RegNtPreCreateKey
显示更多
HKLM\system\controlset001\services\sessionenv\parameters::servicedll C:\WINDOWS\system32\SessionEnv.dll RegNtPreCreateKey
HKLM\system\controlset001\services\tokenbroker\parameters::servicedll C:\WINDOWS\system32\TokenBroker.dll RegNtPreCreateKey
HKLM\system\controlset001\services\usermanager\parameters::servicedll C:\WINDOWS\system32\UserManager.dll RegNtPreCreateKey
HKLM\system\controlset001\services\rasauto\parameters::servicedll C:\WINDOWS\system32\Rasauto.dll RegNtPreCreateKey
HKLM\system\controlset001\services\rasman\parameters::servicedll C:\WINDOWS\system32\Rasman.dll RegNtPreCreateKey
HKLM\system\controlset001\services\remoteaccess\parameters::servicedll C:\WINDOWS\system32\Remoteaccess.dll RegNtPreCreateKey
HKLM\system\controlset001\services\sens\parameters::servicedll C:\WINDOWS\system32\SENS.dll RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters::servicedll C:\WINDOWS\system32\Sharedaccess.dll RegNtPreCreateKey
HKLM\system\controlset001\services\tapisrv\parameters::servicedll C:\WINDOWS\system32\Tapisrv.dll RegNtPreCreateKey
HKLM\system\controlset001\services\wuauserv\parameters::servicedll C:\WINDOWS\system32\wuauserv.dll RegNtPreCreateKey
HKLM\system\controlset001\services\bits\parameters::servicedll C:\WINDOWS\system32\BITS.dll RegNtPreCreateKey
HKLM\system\controlset001\services\shellhwdetection\parameters::servicedll C:\WINDOWS\system32\ShellHWDetection.dll RegNtPreCreateKey
HKLM\system\controlset001\services\appmgmt\parameters::servicedll C:\WINDOWS\system32\AppMgmt.dll RegNtPreCreateKey

Windows API 使用情况

类别 API
Service Control
  • OpenSCManager
  • StartService