Skip to content

Commit

Permalink
删图
Browse files Browse the repository at this point in the history
  • Loading branch information
W1ndys committed Oct 8, 2024
1 parent 4718382 commit b3731cf
Show file tree
Hide file tree
Showing 4 changed files with 3 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ SHA1:6fed7732f7cb6f59743795b2ab154a3676f4c822

1. 打开任务管理器,观察进程情况。

![打开任务管理器](../img/CyberSecurity/5-cat/image.png)
![img](https://pica.zhimg.com/80/v2-070de21e15f36fab6472ab224bac1f37_720w.png?source=d16d100b)

2. 运行病毒样本,观察进程情况。

Expand All @@ -43,13 +43,13 @@ SHA1:6fed7732f7cb6f59743795b2ab154a3676f4c822

1. 查一下文件信息

![文件信息](../img/CyberSecurity/5-cat/image-1.png)
![img](https://pica.zhimg.com/80/v2-618531a8b718a7d8e0cbfb8d534f57b8_720w.png?source=d16d100b)

2. 打开 IDA Pro,导入病毒样本。

3. 定位到 start 函数,查看伪代码。

![伪代码](../img/CyberSecurity/5-cat/image-2.png)
![img](https://pic1.zhimg.com/80/v2-b00bb81f8e8ab65414f8a5aa0b568be7_720w.png?source=d16d100b)

#### start 函数分析

Expand Down
Binary file removed source/img/CyberSecurity/5-cat/image-1.png
Binary file not shown.
Binary file removed source/img/CyberSecurity/5-cat/image-2.png
Binary file not shown.
Binary file removed source/img/CyberSecurity/5-cat/image.png
Binary file not shown.

0 comments on commit b3731cf

Please sign in to comment.