{"id":"a18c0d2d31da3b0d474fbde83cab5bb4","title":"Process Injection Tool — Process Injection Tool · 木马/恶意软件 · PE64","md5":"a18c0d2d31da3b0d474fbde83cab5bb4","sha256":"02a8f08e3340b89c987dfbf1a961487cdac104d988b8f98c036eeb226c25c9e4","family":"Process Injection Tool","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C#","file_format":"PE64","compiler":".NET Native AOT","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本是 .NET Native AOT (CoreRT) 编译的 64 位 Windows 可执行文件。DIE 工具误将其识别为 Rust 编译（.NET AOT 编译产生类似的 native 代码结构），但通过 .NET 运行时字符串（mscorlib、System.Runtime、ReadyToRunSectionType）确认真实身份。 核心恶意能力： 进程注入链：VirtualAlloc → VirtualProtect → QueueUserAPC → SetThreadContext — 完整的 APC 注入流程 令牌操作：OpenProcessToken + AdjustTokenPrivileges — 权限提升 进程访问：OpenProcess — 打开目标进程句柄 反检测：GetTickCount64 + QueryPerformanceCounter — 沙箱/调试器时间检测 持久化：CommonStartup/CommonDesktopDirectory 启动文件夹 + Microsoft.Win32.Registry 注册表 反射加载：AssemblyBinder + ReflectionDomainSetup — 动态程序集加载 编译环境：.NET 8.0 Native AOT，使用 Microsoft.Extensions.DependencyInjection 依赖注入框架，ReadyToRun 格式。","url":"https://zseceye.com/report/a18c0d2d31da3b0d474fbde83cab5bb4","json_url":"https://zseceye.com/report/a18c0d2d31da3b0d474fbde83cab5bb4.json","html_url":"https://zseceye.com/report/a18c0d2d31da3b0d474fbde83cab5bb4","hash_urls":{"md5":"https://zseceye.com/hash/a18c0d2d31da3b0d474fbde83cab5bb4","sha256":"https://zseceye.com/hash/02a8f08e3340b89c987dfbf1a961487cdac104d988b8f98c036eeb226c25c9e4"},"search_urls":{"md5":"https://zseceye.com/?q=a18c0d2d31da3b0d474fbde83cab5bb4","sha256":"https://zseceye.com/?q=02a8f08e3340b89c987dfbf1a961487cdac104d988b8f98c036eeb226c25c9e4"},"sample_download_url":"https://zseceye.com/report/a18c0d2d31da3b0d474fbde83cab5bb4/sample","sample_filename":"02a8f08e3340b89c.zip","iocs":[],"ips":[]}