在 start 处 sub_140014EB5 ();
可疑
有挺多的反调试:
.text:00007FF7CD3342B5 mov rcx, [rbp+810h+hObject] ; hObject
.text:00007FF7CD3342BC call cs:CloseHandle ; Check Invalid Close->Exception
ida patch 一下
sub_14001458C((_DWORD)Buffer, 64614, v12, v26, 0);
解密
chacha20加密
看位数判断是哪个参数
&( $sHellid[1] + $ShElLid[13] + 'X')( ( [RuntIme.INteroPsErviCEs.maRSHal]::PTrtostriNGAUTo( [rUNtIme.inteRopServIces.MarshAl]::seCuREsTrinGtobStr( $('76492d1116743f0423413b16050a5345MgB8AG8ARwBQAGMAeQBnAFIAUgBXACsAcAB6AFYALwBFADgAZwA5AGIASwA3AFEAPQA9AHwAYQBkADIAYwAzADYAYwA5ADAAZgA1AGQANwNAAwAGUAZAAwADEAZgBkADQAZQA1ADMANwBjADMANQAwADYAMwA2AGYAZAA0ADQANABlADYAOQBkAGYAZAA3AGQAMwBiADYAMwA2AGYANwA3ADcANQ.....A4AGEAZABhADQANwA4ADQANAA4ADQAOQBmADUANwAwAGUAOABmAGEAOABkADQAOABkADUAMwAwADUAZAA4AGQAYwA5ADcANQAxADUAZAA2AGIAMwA1AGQAMQAwAGQANAA=' | conveRTTo-SECureSTrinG -K (94..117)) ) )))
iex hook 一下
三层套娃展开
RC4加密