{"id":"5fb882846518a38b42b74348bb3a838b","title":"Autorun Pro (可疑Dropper) — Autorun Pro (可疑Dropper) · 下载器/投放器 · PE32","md5":"5fb882846518a38b42b74348bb3a838b","sha256":"ddf42fa0c0c9f5e7c33dfe7cc6743f812b796b53c759e6e19ec18daa6b98364e","family":"Autorun Pro (可疑Dropper)","apt":null,"verdict":null,"sample_type":"下载器/投放器","lang":"Delphi","file_format":"PE32","compiler":"Delphi 7","published_at":"2020-02-24T16:00:00.000Z","summary":"该样本是一个 Delphi 7 编译的 Autorun Pro Enterprise II 安装器，大小 634.5 KB。 Autorun Pro Enterprise II 是一款合法的 CD/DVD 自动运行菜单制作工具。然而，该样本出现在恶意软件包中 (与 RevengeRAT、NjRAT、AsyncRAT 等同包)，且时间戳为 1992年 (明显伪造)。 评估: 该安装器可能被用作恶意软件投放器，伪装为合法软件安装程序来绕过检测。 导入大量 GUI/COM/OLE 函数 (200+ API)，符合合法安装器特征，但也可能捆绑了恶意载荷在资源段。 建议: 提取资源段检查是否有额外的 PE 载荷。 SHA256: ddf42fa0c0c9f5e7c33dfe7cc6743f81...","url":"https://zseceye.com/report/5fb882846518a38b42b74348bb3a838b","json_url":"https://zseceye.com/report/5fb882846518a38b42b74348bb3a838b.json","html_url":"https://zseceye.com/report/5fb882846518a38b42b74348bb3a838b","hash_urls":{"md5":"https://zseceye.com/hash/5fb882846518a38b42b74348bb3a838b","sha256":"https://zseceye.com/hash/ddf42fa0c0c9f5e7c33dfe7cc6743f812b796b53c759e6e19ec18daa6b98364e"},"search_urls":{"md5":"https://zseceye.com/?q=5fb882846518a38b42b74348bb3a838b","sha256":"https://zseceye.com/?q=ddf42fa0c0c9f5e7c33dfe7cc6743f812b796b53c759e6e19ec18daa6b98364e"},"sample_download_url":"https://zseceye.com/report/5fb882846518a38b42b74348bb3a838b/sample","sample_filename":"ddf42fa0.zip","iocs":[],"ips":[]}